# Dark Web Service Nexus Sells 153M+ Driver Licenses

> A new dark web service, Nexus, is selling over 153 million drivers' licenses from North America, likely sourced from an identity verification company.

- Published: 2026-09-02T01:59:46.000Z
- Severity: high
- Category: Data Breach
- Tags: Dark Web, Identity Theft, Data Breach, Nexus, Exploit Forum
- Author: Runtime Rebel Intel
- Primary source: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
- Canonical: https://runtimerebel.com/blog/dark-web-service-nexus-sells-153m-driver-licenses

## Key points

- Millions of North American drivers' licenses are for sale on the dark web, risking widespread identity theft.
- Data likely stolen from an unnamed, widely used identity verification company, impacting individuals and officials.
- Defenders must monitor for fraudulent activity and review the security of third-party identity verification vendors.

A new [dark web](/glossary#dark-web) marketplace named Nexus has emerged, actively selling digital scans of over 153 million drivers' licenses belonging to individuals in the United States and Canada. This significant [data breach](/glossary#data-breach), first reported by [KrebsOnSecurity](https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/), has prompted an official inquiry by the New Orleans field office of the Federal Bureau of Investigation (FBI).

The scale of this operation is alarming, affecting a broad spectrum of individuals, including high-ranking U.S. government officials. The source of these sensitive images appears to be an ongoing compromise at a widely utilized identity verification company based in Louisiana, which serves numerous Fortune 500 clients.

## The Nexus Dark Web Service: Anatomy of a Massive Data Breach

Launched on the Russian cybercrime forum [Exploit](/glossary#exploit), Nexus boasts an extensive database beyond just drivers' licenses. It claims to offer more than 10 million identification cards, over three million travel and international [IDs](/glossary#ids), and at least 579,000 medical cards. A blank search on the Nexus platform reportedly returned approximately 11.5 million pages of results, underscoring the vastness of the compromised data. While it includes documents from both Canada and the U.S., the majority of records are American, with Canada accounting for about 1.1 million results, heavily concentrated in Ontario.

Adding to the concern, some records include unusual document types such as marijuana dispensary cards, and cryptic source notations like "CDL" (presumably commercial drivers license) and "CAC" (potentially Common Access Cards, government-issued identity cards).

The operators behind Nexus claim to have been "continuously exfiltrating new data for over a year," feeding it into their private database. This claim is supported by observed increases of nearly 400,000 drivers' license records within a 24-hour period, indicating an active and ongoing data harvest. This active exfiltration highlights the persistent **impact of dark web data sales on identity verification** systems, as freshly stolen data continually replenishes the illicit market.

### Tracing the Data's Origin: Identity Verification Company Implicated

KrebsOnSecurity's investigation points strongly towards an identity verification service. Evidence includes timestamps embedded in the image files matching dates when individuals known to have their licenses in Nexus traveled or rented cars. For instance, the article's author found his own Virginia drivers' license, complete with infrared and ultraviolet scans, timestamped to a day he flew for a funeral in June 2025. He remembered using his U.S. passport at airport security that day, but later rented a car from Hertz, suggesting the data was likely collected during a car rental verification process, or similar activity requiring ID verification by a third party.

Several other individuals confirmed their travel or car rental activities aligned with the timestamps on their compromised licenses, with Hertz frequently mentioned as the car rental agency. The absence of passports in the dataset also steered investigators away from airport security as the primary source. This granular detail regarding the presumed point of compromise is vital for understanding **mitigation strategies for compromised driver licenses**.

## Actionable Recommendations for Mitigating Data Breach Risks

The exposure of such a vast quantity of personal identification documents carries severe risks of identity theft, financial fraud, and targeted spear-[phishing](/glossary#phishing) campaigns. Organizations and individuals must take proactive steps to mitigate potential harm.

### Prioritizing Response and Detecting Identity Theft Post-Data Breach

*   **Review Third-Party Vendor Security:** Companies, especially those utilizing identity verification services, should immediately audit their third-party vendors' security practices, data handling, and breach notification protocols. Ensure that any service handling sensitive [PII](/glossary#personally-identifiable-information-pii) meets stringent security standards and has incident response plans in place.
*   **Enhanced Monitoring for Fraud:** Individuals and organizations should increase vigilance for suspicious activities. This includes monitoring credit reports, financial accounts, and unexplained communications seeking personal information. Implement multi-factor authentication ([MFA](/glossary#mfa)) across all critical accounts where possible.
*   **Employee Education:** Educate employees, especially those in positions of public trust, about the heightened risk of spear-phishing and [social engineering](/glossary#social-engineering) attempts. Emphasize caution regarding unsolicited requests for personal or official information.
*   **Identity Protection Services:** Individuals whose licenses may have been compromised should consider enrolling in identity theft protection services, which can provide alerts for fraudulent activities and assist in recovery efforts.

Understanding and preparing for **detecting identity theft post-data breach** is crucial. Proactive monitoring and swift response are the best defenses against the long-term impact of such extensive PII exposure.

**Related:** [Texas Data Breach Exposes 3M Driver's Licenses via Vendor](/blog/texas-data-breach-exposes-3m-driver-s-licenses-via-vendor), [WFP Palestine Breach: 600,000 Gaza Households' Data Exposed](/blog/wfp-palestine-breach-600000-gaza-households-data-exposed)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/dark-web-service-nexus-sells-153m-driver-licenses
