A massive collection of driver’s license scans belonging to people in the United States and Canada has appeared for sale on the dark web, raising serious concerns about identity theft and personal data security.
The illegal service, known as Nexus, claimed to have more than 153 million driver’s license records from the two countries. The collection reportedly also included millions of other identification documents, such as ID cards, travel documents and hundreds of thousands of medical cards.
However, the 153 million figure has not yet been independently confirmed as the number of unique people affected. The FBI has confirmed that it is investigating the incident but has not publicly established the full size of the breach or exactly where all of the stolen information came from.
Some of the available records reportedly contained detailed digital images of the front and back of driver’s licenses. Certain records also included infrared and ultraviolet versions of the documents, which are normally used by identity verification systems to check whether an ID is genuine. Timestamps attached to some files also appeared to match occasions when people had their identities checked.
The investigation has focused attention on a Louisiana-based identity verification provider after evidence suggested that scanned identity documents may have been connected to its systems. However, investigators have not conclusively confirmed the company as the source of the entire dataset, and the exact cause of the suspected breach remains under investigation.
The scale of the exposed information could create major problems for affected users. Driver’s licenses contain valuable personal details that criminals can potentially use for identity theft, financial fraud, fake account creation and attempts to bypass identity verification checks.
Another worrying sign was that the number of documents listed by Nexus appeared to be increasing. At one point, the number of driver’s license records grew by nearly 400,000 within about 24 hours, suggesting the operators may have been receiving new information from an active or recently active source.
The dark-web service later disappeared shortly after information about the operation became public. Its disappearance, however, does not mean that copies of the data have been removed from criminal networks or that previously accessed information cannot be misused.
For people in the US and Canada, the incident is another reminder of the risks created when highly sensitive identity documents are scanned and stored by third-party services. Users should remain alert for suspicious credit activity, unexpected account changes, phishing messages or attempts to open accounts in their name.
The investigation is still ongoing, and authorities have not yet published a confirmed list of affected individuals. More details about the size of the breach, its original source and how the data was obtained could emerge as investigators continue examining the case.