[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxdH7IFMwkykhUV5kK8zaYpO5CoKktpjfp9M3-A05e-M":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"d80550dd-ddfa-4522-b44a-d72a224415f4","153 Million Driver License Images Offered on Dark Web","153-million-driver-license-images-offered-on-dark-web-fda462","Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek.","A threat actor is offering digital scans of over 153 million US and Canadian driver's licenses on the dark web, allegedly stolen from identity verification firm IDScan.net. The stolen data, which also includes other identification and medical cards, was found on a service called Nexus. The FBI has reportedly launched an investigation into the potential breach.","153 million US and Canadian driver's licenses offered on dark web, likely from IDScan.net.","A threat actor this week started offering on the dark web digital scans of over 153 million US and Canadian driver’s licenses. The driver’s licenses emerged on an identity theft service called Nexus. Simultaneously, a threat actor started promoting the service on a Russian cybercrime forum, claiming the possession of the IDs of over 170 million individuals. On Nexus, visitors could find over 153 million driver’s licenses, more than 10 million identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards. According to investigative journalist Brian Krebs, a blank search on Nexus appeared to return approximately 153 million results. Only around 1.1 million driver’s licenses were from Canada. The threat actor behind Nexus alleged that the documents were exfiltrated from an active breach at an identity verification firm that serves multiple Fortune 500 companies, Krebs reports. After verifying the presence of his own driver’s license on Nexus, as well as that of other individuals, Krebs concluded that the documents were likely siphoned from identity verification platform IDScan.net.Advertisement. Scroll to continue reading. The Louisiana-based firm provides ID fraud prevention, access management, and age verification services, along with an ID-activated door lock and mobile ID scanners. The company says it works with large brands across a dozen industries, including automotive, banking and fintech, gaming, education, transportation, hospitality, law enforcement, retail, and security, performing over 21 million verifications each month at more than 20,000 locations. SecurityWeek has emailed IDScan for a statement on the potential data breach and will update this article if the company responds. According to Krebs, the Nexus platform was shut down shortly after his article on the stolen IDs was published. However, the FBI apparently caught wind of the potential IDScan data breach and launched an official investigation into the matter. Some of the driver’s licenses the threat actor behind Nexus had exfiltrated apparently belong to FBI agents. “The first takeaway lesson is that organizations should design identity systems on the assumption that identity evidence may eventually be compromised. A genuine-looking document cannot remain sufficient proof of identity indefinitely. Organizations should inventory identity data and establish who collects it, why it is needed, where it flows, and when it is deleted,” NCC Group senior adviser and director Tim Rawlins said. “Contracts with identity providers should establish requirements for logging, data segregation, retention, incident notification, access to evidence, and independent assurance. Organizations should also monitor for abnormal bulk access and potential data exfiltration, including unusual activity involving service accounts, application programming interfaces, and administrative accounts,” Rawlins added. Individuals should avoid sharing copies of their driver’s licenses unless absolutely necessary and, when presenting an ID for verification, ask whether it can be checked without being scanned, photographed, or retained. Related: Ransomware Gang Claims Nutex Health Data Breach Related: 9.5 Million Impacted by Aesto Health Data Breach Related: McKesson Confirms Data Breach as Attacker Deadline Looms Related: Extortion Group Claims Manchester Airports Group Data Breach Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Malicious Virtualizor Update Served via BGP HijackingChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedHackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM JackpottingRansomware Gang Claims Nutex Health Data Breach9.5 Million Impacted by Aesto Health Data BreachWatchGuard Patches Critical Vulnerabilities Latest News AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 MillionOver 3 Million WordPress Sites Affected by Migration Plugin VulnerabilityCisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch VulnerabilitiesOpenLeash Adds a Human Check to Risky AI Agent ActionsUK Moves to Block High-Risk Tech Suppliers From Critical InfrastructureRockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsExploit Published for Fresh Cleo Harmony VulnerabilityAnthropic Details Response to Security Incidents, Unveils Enterprise Safeguards Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002F153-million-driver-license-images-offered-on-dark-web\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F07\u002Fdata-tracking-report.jpeg","2026-09-03T10:54:18+00:00","2026-09-03T12:00:11.429813+00:00",8,[18,21,24],{"name":19,"type":20},"Nexus","product",{"name":22,"type":23},"IDScan.net","vendor",{"name":25,"type":26},"Nexus threat actor","threat_actor","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":27,"icon":29,"name":30,"slug":31},null,"Breaches","breaches",[33,38,40,45],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":39},{"id":27,"icon":29,"name":30,"slug":31},{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51],{"type":52,"value":53,"context":54},"domain","idscan.net","Likely source of stolen driver's license images."]