153M Licenses For Sale—FBI Scrambles

A massive trove of 153 million driver’s license scans is being shopped on a Russian crime forum, and federal agents are now on the case.

Story Highlights

  • Report says 153 million U.S. and Canadian driver’s license scans are for sale on a dark‑web service called Nexus.
  • Federal Bureau of Investigation (FBI) launched an inquiry through its New Orleans field office.
  • Media describe high‑resolution front and back scans consistent with identity‑verification systems.
  • The seller’s count is a claim, not a confirmed tally of unique people affected.

FBI Opens Probe After Marketplace Claims of 153 Million Licenses

Reuters reported that the Federal Bureau of Investigation (FBI) is investigating a report that tens of millions of U.S. and Canadian driver’s licenses are being sold on the dark web. Independent journalist Brian Krebs said a service named Nexus advertised more than 153 million licenses and other identity records. Krebs also reported that the FBI’s New Orleans field office opened a formal inquiry into the source of the images. That level of response signals a serious federal focus, even as the exact source remains under review.

Time and TechCrunch echoed the description of Nexus and its scale claims, citing high numbers and a mix of document types. Reuters summarized that the listings included digital scans consistent with identity checks done by many businesses. Krebs said the images included front and back scans and verification photos, which suggests an identity‑verification pipeline was compromised rather than a simple list of numbers. That difference matters because high‑resolution images can enable more damaging fraud than a leaked number alone.

What Kind of Data Is Allegedly in the Trove—and Why It Matters

Reports say the advertised data contains high‑quality scans of licenses plus extra images used to verify identity during rentals or purchases. Those are the kinds of records stored by vendors that help retail, rental car, and travel companies check customers. Such scans can be reused by criminals to open accounts, pass remote checks, or fool weak facial comparison tools. Time warned that, if true, the breach could be one of the largest exposures of government ID documents in North America. That risk puts families and seniors in the crosshairs of identity theft.

Several outlets noted that Nexus went offline or displayed a shutdown message soon after coverage increased, which often happens when an illicit market gets heat. That disappearance can make verification harder for the public, but it does not erase the risk that copies are already in criminal hands. Reuters stressed that the FBI investigation is underway, but has not released technical findings to the public. Until those findings land, consumers should assume bad actors may try to use these scans in scams and credit fraud.

Source Theories, Unconfirmed Attribution, and What We Actually Know

Krebs tied the style and timestamps of the scans to identity‑verification workflows and said the FBI in New Orleans opened an inquiry on the same day he published. Some coverage pointed to a Louisiana‑based provider as a potential source, but none of the cited reports published a formal forensic report proving the upstream breach. Hall Attorneys also emphasized that the marketplace’s 153 million figure is a seller’s claim, not a verified count of unique victims. Those guardrails matter for accuracy, even as the security risk remains real.

Local reporting quoted a statement that the company at issue received information suggesting data may have been accessed without authorization and brought in third‑party specialists to assess scope. That is standard incident response language. It confirms concern and action, but it does not resolve how much was taken or from where. Conservatives value clear accountability. That starts with facts: what systems stored these scans, why retention was so broad, and whether customers were told the truth about how long their IDs would be kept.

Practical Steps for Families and What Washington Should Do Next

Consumers can act now. Place a credit freeze at all three major bureaus. Set fraud alerts with your bank and card issuers. Watch benefits accounts and your mail for surprise bills or approvals you did not request. Demand retailers and rental firms delete stored license scans once a transaction ends. Ask state motor vehicle agencies about free monitoring after breaches. These are simple moves that block criminals who try to use your license to open lines of credit or pass remote checks.

Washington must tighten data‑retention rules for license scans gathered by private vendors. President Trump’s administration should press agencies to set firm delete‑by‑default standards and tough penalties when companies hoard sensitive images with weak security. The FBI is doing its job by investigating. Congress should back it up by making sure identity‑verification vendors use strict access controls, log every view and copy, and notify the public fast. Protecting citizens’ identity is not red or blue. It is basic security and limited government done right.

Sources:

zerohedge.com, reuters.com, krebsonsecurity.com, breachhistory.com, techcrunch.com, techjacksolutions.com