Back to blog
data breachidentityKYCdark websovereignty

153 million driver's licenses sold on the dark web: the IDScan case

Published on 2026-09-165 min readActionShield

> TL;DR: A dark-web service named "Nexus" was selling access to 153 million US and Canadian driver's licenses and 3 million travel documents. Krebs on Security verified the licenses were genuine and linked the breach to identity-verification service IDScan. The FBI is investigating. The database alone covers roughly 63% of all US licenses.

The numbers

According to Krebs on Security, the "Nexus" service offered:

  • 153 million driver's licenses (US and Canada).
  • 3 million travel documents.
  • A continuously growing database: nearly 400,000 licenses added in a single day, a sign of regular ingestion of fresh data.
  • Krebs verified the licenses were genuine, including his own and those of nine friends and family members. The Secretary of Defense, an FBI assistant director and other senior officials were among the records. The service disappeared from the dark web shortly after the story ran.

    Why a license is a goldmine

    A license is not just a way to steal an identity. It is a join key: the license number appears in other databases, and linking it to an address and a photo turns an anonymous record into a usable profile.

    History is full of examples:

  • The breaches at Anthem, Equifax, Marriott, United Airlines and the Office of Personnel Management fed Chinese espionage, used to counter US intelligence efforts.
  • Bellingcat identified a deep-cover GRU agent in Naples, then the suspects in the Skripal poisoning, using leaked databases.
  • If a small investigative outfit assembles leaked Russian data, imagine what Chinese services do with leaking American data.

    The identity-provider breach pipeline

    Breaches at identity-verification providers keep repeating:

  • AU10TIX (licenses and official documents).
  • 5CA, Discord's age-verification provider.
  • National Public Data.
  • These services are necessary to catch fraud, but they concentrate a critical mass of identity data. That is the classic profile of a high-value target — and a point of concentration.

    What to check right now

  • If you integrate an identity-verification provider, ask for evidence of their data scoping: which data, how much, where, for how long.
  • Your customers' identity data (licenses, passports, KYC) is a priority target. Encrypt it, limit its lifetime, and log access.
  • Any data that acts as a join key (license number, social security number, account number) multiplies the impact of a breach.
  • Your subcontractors that touch identity must be audited to the same standard as your own application.
  • The takeaway

    An identity database is not an asset. It is a point of concentration. The more complete it is, the more valuable it is to an attacker. The question is not "can it leak?" but "what does an attacker do with 153 million licenses and 400,000 new ones a day?"

    Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Want to know what your AI agent can do?

    Tell us about your agent, its tools, and client context. We will come back with the right review scope.

    Discuss your audit