FBI Investigates Dark Web Service Selling Over 153 Million Stolen Drivers Licenses

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

A new identity theft service has emerged on the dark web, offering digital scans of over 153 million drivers licenses from individuals in the United States and Canada. This service, identified as Nexus, appears to be sourcing images from a major identity verification company based in Louisiana. The New Orleans field office of the Federal Bureau of Investigation (FBI) has initiated an inquiry into the origins of these images, as reported by KrebsOnSecurity.

Details of the Nexus Service

Launched recently, Nexus claims to have amassed over 153 million drivers licenses, alongside more than 10 million identification cards, over three million travel documents, and at least 579,000 medical cards. A search within the Nexus database reveals approximately 11.5 million pages of results, predominantly featuring records from American citizens.

Potential Source of Data Breach

The operators of Nexus allege that the license images are being harvested from an ongoing breach at a prominent identity verification company, which serves several Fortune 500 clients. The service has reportedly been continuously exfiltrating data for over a year, with the number of available drivers license records increasing by nearly 400,000 in just 24 hours.

FBI Investigation and Implications

As the investigation unfolds, the FBI has confirmed that they are looking into the breach involving the identity verification company. Experts warn that the exposure of such sensitive data poses significant risks, particularly for individuals who rely on their drivers licenses for identity verification in various contexts, including financial transactions and travel.

In a recent update, the Nexus website has reportedly gone offline, displaying a message indicating that the service is no longer available. This development may suggest a response to the heightened scrutiny from law enforcement.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Attackers Exploit CVE-2026-82329 Flaw in JFrog Artifactory to Gain Admin Access Days After Patch

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to reporting by The Hacker...

Cloudflare’s H1 2026 DDoS Report Reveals 519% Surge in 1 Tbps Attacks Amid Geopolitical Tensions

Cloudflare's recently released DDoS Threat Report H1 2026 reveals a staggering 519% increase in Distributed Denial of Service (DDoS) attacks exceeding 1 Tbps, highlighting...

Check Point Research Unveils Static Deobfuscation Techniques for JSCeal Malware

Research by: hasherezade Check Point Research (CPR) has recently unveiled significant advancements in the static deobfuscation of JSCeal, a sophisticated malware targeting cryptocurrency applications. Since...

Red Hat Releases Important Kernel Security Update for RHEL 8.8 Services

Red Hat has announced an important kernel security update for its Red Hat Enterprise Linux (RHEL) 8.8 Update Services, specifically targeting SAP Solutions and...