153 million driver's licenses sold on the dark web: the IDScan case
> TL;DR: A dark-web service named "Nexus" was selling access to 153 million US and Canadian driver's licenses and 3 million travel documents. Krebs on Security verified the licenses were genuine and linked the breach to identity-verification service IDScan. The FBI is investigating. The database alone covers roughly 63% of all US licenses.
The numbers
According to Krebs on Security, the "Nexus" service offered:
Krebs verified the licenses were genuine, including his own and those of nine friends and family members. The Secretary of Defense, an FBI assistant director and other senior officials were among the records. The service disappeared from the dark web shortly after the story ran.
Why a license is a goldmine
A license is not just a way to steal an identity. It is a join key: the license number appears in other databases, and linking it to an address and a photo turns an anonymous record into a usable profile.
History is full of examples:
If a small investigative outfit assembles leaked Russian data, imagine what Chinese services do with leaking American data.
The identity-provider breach pipeline
Breaches at identity-verification providers keep repeating:
These services are necessary to catch fraud, but they concentrate a critical mass of identity data. That is the classic profile of a high-value target — and a point of concentration.
What to check right now
The takeaway
An identity database is not an asset. It is a point of concentration. The more complete it is, the more valuable it is to an attacker. The question is not "can it leak?" but "what does an attacker do with 153 million licenses and 400,000 new ones a day?"
Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
ANTS / France Titres 2026: a basic IDOR flaw exposes 11.7 million accounts
France's vehicle registration and ID portal ants.gouv.fr was compromised through an elementary IDOR vulnerability: changing an identifier in an API request was enough to access other users' data. Official tally: 11.7 million accounts exposed, with the attacker claiming up to 19 million.
South Korea: data-breach fines jump to 10% of revenue
South Korea raises data-breach fines to 10% of total revenue (from 3%) for leaks of 10 million or more people. Coupang's $466M fine could reach the trillions of won under the new rule.
DGFiP Breached by ZeroBytes: Inside France's Biggest Tax Data Leak of 2026
France's tax authority (DGFiP) confirmed unauthorized access to its information system: impersonated agent credentials, no blanket MFA, and over 2 million people potentially exposed through the cadastral records server.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant ActionShield audits.