Excerpt from Reuters, Published on September 3, 2026
The FBI is investigating a reported driver’s license data breach after a dark-web service advertised access to millions of identity documents belonging to people in the United States and Canada.
The service, known as Nexus, claimed to hold more than 153 million driver’s license scans, along with millions of other identification and travel documents. Cybersecurity journalist Brian Krebs reported that he found his own driver’s license among the records and verified several other samples. Some records reportedly contained front and back images, as well as additional scans.
The source of the dataset remains under investigation. Reporting has linked some records to an identity verification provider, but Reuters said it could not independently establish where the data originated. The provider has also said it is investigating. The FBI’s New Orleans field office is handling the inquiry.
The reported driver’s license data breach highlights a broader risk for organizations that rely on external identity verification services. Government-issued IDs contain information that can support identity theft, fraud, account takeover, and social engineering. Unlike passwords, many identity attributes cannot simply be changed after exposure.
For businesses, the incident raises questions about third-party risk management and how identity data moves through verification platforms, applications, cloud environments, and downstream vendors. Security programs should account for access controls, data minimization, retention practices, monitoring, incident response, and vendor oversight.
The driver’s license data breach also shows why organizations need visibility beyond their own production systems. A trusted third-party provider can become part of an organization’s overall data security exposure, particularly when it processes highly sensitive identity information.
For additional information, visit Reuters.




