Bad news. If you are in the US or Canada, you might be among 153 million people who had their drivers license hacked and pop up on the dark web:
A threat actor this week started offering on the dark web digital scans of over 153 million US and Canadian driver’s licenses.
The driver’s licenses emerged on an identity theft service called Nexus. Simultaneously, a threat actor started promoting the service on a Russian cybercrime forum, claiming the possession of the IDs of over 170 million individuals.
On Nexus, visitors could find over 153 million driver’s licenses, more than 10 million identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards.
According to investigative journalist Brian Krebs, a blank search on Nexus appeared to return approximately 153 million results. Only around 1.1 million driver’s licenses were from Canada.
The threat actor behind Nexus alleged that the documents were exfiltrated from an active breach at an identity verification firm that serves multiple Fortune 500 companies, Krebs reports.
Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)
“A license contains the owner’s date of birth, address, physical descriptors, and a government-issued ID number. This is enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable. The harder problem is that unlike a compromised password, none of those fields can be changed, so every person in this dataset will carry this exposure with them for life. It’s good that this isn’t being taken lightly, but it may be time to raise the standard for ID verification checks.”
Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)
“This looks less like someone stole a database once and more like someone had persistent access to trusted systems or identities. If an attacker gets in as an employee, administrator, contractor or service account, database encryption does not save you because the system treats them as authorized. We do not yet know whether compromised credentials or legacy MFA were the entry point, but that seems likely.
“For access to hundreds of millions of identity records, organizations should require fingerprint based biometric assured identity on dedicated hardware. And companies need to rethink how much identity data they retain in the first place.”
Donald McFarlane, Advisory Board Member, Xcape, Inc. (https://www.linkedin.com/in/dmcfarlane)
“I am far less interested in how the threat actors gained access than in why all this data was sitting there waiting to be stolen.
“IDScan’s own documentation says their product defaults to “Collect all” and retaining all records, and even touts the resulting PII and demographic data for retail and marketing purposes. For some customers, IDScan provides retention choices; remarkably, its Basic plan appears to require collecting everything and provides no option to delete it. Checking my ID is one thing. Building a permanent dossier because I showed it to you once is quite another.
“As Americans increasingly push back on systems like Flock that aggregate data about ordinary people’s movements into permanent surveillance databases, businesses should expect the same scrutiny when they aggregate identity data for purposes far beyond the transaction that justified collecting it. Showing ID because a merchant requires it is not an invitation to monetize your identity.
“Data minimization is a fundamental security control. If a verification result will suffice, don’t keep the underlying document. If a derived biometric template will suffice, don’t keep the image. If you don’t need the data at all, don’t keep it in the first place. Executives who choose to hoard data they do not need should expect to answer for the consequences. Blaming the hackers does not excuse the business decision that created the target.”
John Strand, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“It feels like a broken record whenever we start talking about technology, unregulated industries, and the impact they can have on people.
“When you look at data brokers and the sheer amount of information they collect, purchase, acquire, aggregate, and store over time, it’s absolutely staggering. And this particular breach appears to be staggering in its own right.
“I don’t know what the perfect answer is for dealing with data brokers. But I do think we need to start treating this type of data with protections similar to what we provide for protected health information. Maybe that means bringing some of it under HIPAA-like protections or creating a regulatory framework that treats large collections of personal data with the same seriousness.
“I know regulation isn’t going to be a 100% solution. Nothing is. But there has to be some accountability around how this information is collected, how much of it companies are allowed to retain, and what security controls they’re required to have in place to protect it.
“Right now, we’re allowing companies to accumulate staggering amounts of information about people while the protections around that data simply haven’t kept pace.”
Denis Calderone, Principal/CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“We’ve been seeing more of these lately. Texas Parks & Wildlife lost 3 million. AssuranceAmerica exposed nearly 7 million. Now an identity verification provider has reportedly been compromised to the tune of 153 million. The scale keeps multiplying because the data keeps concentrating. Hertz, Target, Caesars, FedEx, over a thousand marijuana dispensaries all outsource identity checks to the same vendor. One breach, and every customer of every client is potentially exposed.
“What makes this worse is the claim that data has been actively exfiltrating for over a year, and the database reportedly grew by 400,000 and this appears to be a live pipeline. The records aren’t just names and numbers and includes front, back, infrared, and ultraviolet scans of the physical license, which is enough to pass most identity checks that exist today. A compromised password gets reset in five minutes. A compromised driver’s license requires an in-person DMV visit, proof that fraud has already occurred, and a stack of paperwork; this is a lot of friction to the user/citizen. Meanwhile, age verification laws and know-your-customer mandates keep pushing more businesses to collect government-issued IDs through more third-party vendors. A recent analysis documented 88 identity verification breaches since 2011, and 42% of them occurred in just the last two and a half years.
“Businesses using identity verification vendors need to start asking harder questions about how long scans are retained after verification is complete, whether there’s a contractual data minimization obligation, and whether they have an audit right. Because right now there is no infrastructure analogous to a credit freeze that lets someone flag a compromised driver’s license number. The burden falls entirely on individual victims to place flags manually, state by state, and hope the fraud shows up somewhere they can see it. Every organization collecting and centralizing government-issued identity documents needs to treat those data stores with at least the same security posture they’d apply to payment card data, if not higher. You can get a new credit card number in 24 hours. You can’t get a new face.”
This hack is pretty bad. If I can get a source to have you check to see if you are affected, I will do so. But right now it is safe to assume that you are affected unless otherwise told.
153 Million Drivers Licenses Hacked And Exposed
Posted in Commentary with tags Hacked on September 3, 2026 by itnerdBad news. If you are in the US or Canada, you might be among 153 million people who had their drivers license hacked and pop up on the dark web:
A threat actor this week started offering on the dark web digital scans of over 153 million US and Canadian driver’s licenses.
The driver’s licenses emerged on an identity theft service called Nexus. Simultaneously, a threat actor started promoting the service on a Russian cybercrime forum, claiming the possession of the IDs of over 170 million individuals.
On Nexus, visitors could find over 153 million driver’s licenses, more than 10 million identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards.
According to investigative journalist Brian Krebs, a blank search on Nexus appeared to return approximately 153 million results. Only around 1.1 million driver’s licenses were from Canada.
The threat actor behind Nexus alleged that the documents were exfiltrated from an active breach at an identity verification firm that serves multiple Fortune 500 companies, Krebs reports.
Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)
“A license contains the owner’s date of birth, address, physical descriptors, and a government-issued ID number. This is enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable. The harder problem is that unlike a compromised password, none of those fields can be changed, so every person in this dataset will carry this exposure with them for life. It’s good that this isn’t being taken lightly, but it may be time to raise the standard for ID verification checks.”
Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)
“This looks less like someone stole a database once and more like someone had persistent access to trusted systems or identities. If an attacker gets in as an employee, administrator, contractor or service account, database encryption does not save you because the system treats them as authorized. We do not yet know whether compromised credentials or legacy MFA were the entry point, but that seems likely.
“For access to hundreds of millions of identity records, organizations should require fingerprint based biometric assured identity on dedicated hardware. And companies need to rethink how much identity data they retain in the first place.”
Donald McFarlane, Advisory Board Member, Xcape, Inc. (https://www.linkedin.com/in/dmcfarlane)
“I am far less interested in how the threat actors gained access than in why all this data was sitting there waiting to be stolen.
“IDScan’s own documentation says their product defaults to “Collect all” and retaining all records, and even touts the resulting PII and demographic data for retail and marketing purposes. For some customers, IDScan provides retention choices; remarkably, its Basic plan appears to require collecting everything and provides no option to delete it. Checking my ID is one thing. Building a permanent dossier because I showed it to you once is quite another.
“As Americans increasingly push back on systems like Flock that aggregate data about ordinary people’s movements into permanent surveillance databases, businesses should expect the same scrutiny when they aggregate identity data for purposes far beyond the transaction that justified collecting it. Showing ID because a merchant requires it is not an invitation to monetize your identity.
“Data minimization is a fundamental security control. If a verification result will suffice, don’t keep the underlying document. If a derived biometric template will suffice, don’t keep the image. If you don’t need the data at all, don’t keep it in the first place. Executives who choose to hoard data they do not need should expect to answer for the consequences. Blaming the hackers does not excuse the business decision that created the target.”
John Strand, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“It feels like a broken record whenever we start talking about technology, unregulated industries, and the impact they can have on people.
“When you look at data brokers and the sheer amount of information they collect, purchase, acquire, aggregate, and store over time, it’s absolutely staggering. And this particular breach appears to be staggering in its own right.
“I don’t know what the perfect answer is for dealing with data brokers. But I do think we need to start treating this type of data with protections similar to what we provide for protected health information. Maybe that means bringing some of it under HIPAA-like protections or creating a regulatory framework that treats large collections of personal data with the same seriousness.
“I know regulation isn’t going to be a 100% solution. Nothing is. But there has to be some accountability around how this information is collected, how much of it companies are allowed to retain, and what security controls they’re required to have in place to protect it.
“Right now, we’re allowing companies to accumulate staggering amounts of information about people while the protections around that data simply haven’t kept pace.”
Denis Calderone, Principal/CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“We’ve been seeing more of these lately. Texas Parks & Wildlife lost 3 million. AssuranceAmerica exposed nearly 7 million. Now an identity verification provider has reportedly been compromised to the tune of 153 million. The scale keeps multiplying because the data keeps concentrating. Hertz, Target, Caesars, FedEx, over a thousand marijuana dispensaries all outsource identity checks to the same vendor. One breach, and every customer of every client is potentially exposed.
“What makes this worse is the claim that data has been actively exfiltrating for over a year, and the database reportedly grew by 400,000 and this appears to be a live pipeline. The records aren’t just names and numbers and includes front, back, infrared, and ultraviolet scans of the physical license, which is enough to pass most identity checks that exist today. A compromised password gets reset in five minutes. A compromised driver’s license requires an in-person DMV visit, proof that fraud has already occurred, and a stack of paperwork; this is a lot of friction to the user/citizen. Meanwhile, age verification laws and know-your-customer mandates keep pushing more businesses to collect government-issued IDs through more third-party vendors. A recent analysis documented 88 identity verification breaches since 2011, and 42% of them occurred in just the last two and a half years.
“Businesses using identity verification vendors need to start asking harder questions about how long scans are retained after verification is complete, whether there’s a contractual data minimization obligation, and whether they have an audit right. Because right now there is no infrastructure analogous to a credit freeze that lets someone flag a compromised driver’s license number. The burden falls entirely on individual victims to place flags manually, state by state, and hope the fraud shows up somewhere they can see it. Every organization collecting and centralizing government-issued identity documents needs to treat those data stores with at least the same security posture they’d apply to payment card data, if not higher. You can get a new credit card number in 24 hours. You can’t get a new face.”
This hack is pretty bad. If I can get a source to have you check to see if you are affected, I will do so. But right now it is safe to assume that you are affected unless otherwise told.
Leave a comment »