Over 153 Million Driver’s License Scans Found for Sale on Dark Web

A massive trove of highly sensitive data—more than 153 million driver’s license scans—was discovered on a dark web marketplace, underscoring the growing threat posed by stolen identity documents. Alongside U.S. licenses, the haul includes over 10 million ID cards, 3 million international and travel documents, and 579,000+ medical cards. Canadian licenses are also among the compromised IDs.

The breach was flagged on August 31 when a platform called Nexus was found openly selling this data. The numbers were confirmed through blank-search results totaling 11.5 million pages, each showing 15 listings. Researchers verified their own documents, as well as family members’—some entries had ties to commercial driver’s licenses (CDLs) and government access cards.

How the Leak Happened & Key Players

The data is believed to have been collected over more than a year from a major identity-verification service. While the exact source hasn’t been legally confirmed, one leading theory points to IDScan.net, a firm that handles both physical hardware for scanning IDs and SDKs for mobile app integrations. Several consumers were identified after renting cars from Hertz, suggesting breaches coincided with such transactions.

No public admission of a breach has come from IDScan.net. As of now, an FBI investigation is under way to determine the scope, source, and accountability behind the leak.

Digital IDs Could Help, but Not Yet

States are gradually enabling digital driver’s licenses via platforms like Apple Wallet, which allow selective data sharing—say, just your birthdate rather than your full address or license number. Yet fewer than 20 U.S. states currently support adding your driver’s license to Apple Wallet, and even in those where it’s possible, acceptance remains limited. Physical IDs are still required in many everyday situations like airport security.

The transition to digital IDs faces challenges. Regulations differ by state. Physical verification devices must be upgraded. And many businesses still don’t accept digital formats. It’s worth noting that even widespread digital ID adoption wouldn’t necessarily have prevented this breach, since the vulnerability seems rooted in how external verification services store and handle physical scan data.

What’s hidden is that a lot of the data now floating on Nexus is alleged to match the infrastructure of companies like IDScan.net, which supplies hardware to scan drivers’ licenses in person—but also SDKs used by apps that ask users to photograph their IDs. Some such integrations have been used by online gambling platforms, e-signing services, and others. The FBI’s probe aims to confirm whether such integrations or hardware were misused, and whether data was exfiltrated via them.

This leak stresses that having your ID scanned during a rental car booking or app registration isn’t just benign—it might expose your biometric or identifying data to significant risk.

What the Numbers Mean: Over 150 million U.S. license scans, including CALs like CDLs; 1M+ Canadian IDs; millions of medical cards. Nexus listings often align in time with rental bookings at Hertz.

Despite the potential of digital ID systems to reduce the data collected and stored, adoption hurdles and design decisions currently limit their ability to avert such leaks.

What to Do: Review past ID submissions when possible; monitor your credit reports; consider freezing credit where feasible; stay updated on state-level digital ID options.

What’s Next: Ongoing FBI investigation; potential accountability for identity verification firms; review of digital ID acceptance.

Analytical Note: This incident reveals that data vulnerability isn’t just about hackers breaking in—it’s often about how much data companies collect and how long they keep it. Digital IDs promise selective sharing, but the underlying systems and third-party vendors must enforce data minimization and strong security. What to watch for: changes in regulation around ID storage, legal liability for verification providers, and whether customers demand transparency about how their physical ID data is processed and discarded.