The FBI has opened an investigation into the appearance of scanned identity documents belonging to more than 153 million people in the United States and Canada on a Russian-language cybercrime forum, in what would rank among the largest exposures of government-issued ID ever offered for sale. The listing surfaced on the forum Exploit on August 31 under the name Nexus, advertised as a searchable database of North American identity documents, and the case is being handled by the bureau’s New Orleans field office.

What makes this breach different from the credit card dumps and password lists that circulate on the same forums is what a driver’s license scan actually contains: a photograph, a full legal name, a home address, a date of birth and a document number, all in a single image that a bank, a landlord or a lender will accept as proof that you are who you say you are.
What is in the database
The advertised set goes well beyond licenses. Alongside the 153 million driver’s licenses sit roughly 10 million state ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579,000 medical cards, 429,000 common access cards – the smart cards carried by US military personnel and defense contractors – 91,000 residence cards, 77,000 employment authorization records and about 5 million miscellaneous documents.
The seller claimed access to material from roughly 170 million people. Security journalist Brian Krebs found the listing after coming across his own driver’s license posted as a free sample, then located a document belonging to Defense Secretary Pete Hegseth in the same data. That detail is what moved the story out of the security trade press and into national coverage, reported by NBC News and others.
The trail points at an ID-checking vendor
Nobody handed over 153 million licenses at once. A collection that size comes from the layer of the economy most people never think about: the identity-verification vendors whose scanners sit at car rental counters, dispensary doors, bar entrances and bank branches, capturing an image of the document every time somebody proves their age or identity.
Investigators and reporters have pointed at IDScan.net, a widely used identity-verification company based in Louisiana, as the suspected source. Its clients include the rental company Hertz and the Planet13 chain of marijuana dispensaries. The evidence is circumstantial but specific: timestamps attached to leaked documents match the moments when victims used their identification at those businesses. The company has not confirmed a breach. Asked about the findings, IDScan told Krebs: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome” to its investigation team.
The location of the FBI office handling the case – New Orleans, rather than Washington or a field office near a victim – is itself a signal about where the bureau believes the exposure originated.
Why a license scan is worse than a leaked password
A password can be changed in ten seconds. A driver’s license number, a birth date and a face cannot. The practical uses of a stolen ID image are well established in fraud markets:
- Account takeover. Many banks and crypto exchanges accept a selfie plus a document scan as identity proof. A leaked scan supplies half of that check, and generative tools increasingly supply the other half.
- Synthetic identity fraud. Real document numbers get blended with fabricated details to open credit lines that no single victim notices until a collections notice arrives.
- Tax and benefit fraud. Name, address and date of birth are enough to file a fraudulent return or claim a benefit in someone else’s name.
- Physical-world use. Common access cards and residence documents have value to anyone trying to fabricate credentials rather than open an account.
The FBI cited two categories of victim in particular: survivors of domestic violence, whose current addresses are a safety matter rather than a privacy preference, and participants in witness protection. For those people, a leaked address is not an inconvenience. NarwhalTV has covered the widening pattern of identity-layer breaches in its report on the federal cyber intrusion disclosed this year.
What people can actually do
There is no recall process for a driver’s license the way there is for a payment card, and no US state currently reissues license numbers on request after a third-party breach. That leaves a short list of defensive steps: freeze credit files at all three bureaus, which costs nothing and blocks most new-account fraud; request an identity protection PIN from the IRS before somebody else files a return in your name; and treat any inbound call or message referencing your license details as hostile, because the caller now holds the same information a legitimate institution would use to establish trust.
The structural problem
The Nexus listing has since disappeared from Exploit, which means little – data offered once is copied, resold and re-listed. The deeper issue is that a decade of age-verification and know-your-customer rules pushed a scan of nearly everybody’s identity documents into the hands of intermediaries that most customers have never heard of, cannot choose between, and have no contractual relationship with.
Every one of those scans was captured for a legitimate purpose. The aggregation is what created a target worth attacking, and the people whose documents are now for sale never had a say in where the images were stored.