Cybersecurity3 mins read

153 Million Driver’s Licenses Reportedly Exposed on Dark Web Platform Nexus

Gizmodo reports that a dark web service called Nexus offered searchable access to more than 153 million scanned U.S. and Canadian driver’s licenses, prompting an FBI inquiry.

What Happened With Nexus

Driver Licence
Image credits:Pixel-Shot - Shutterstock.com

Gizmodo reports that a dark web platform called Nexus surfaced on September 1, offering searchable access to more than 153 million scanned U.S. and Canadian driver’s licenses. The FBI opened an investigation the same day, according to the article.

The report says investigative journalist Brian Krebs was alerted to a listing on the Russian cybercrime forum Exploit, where a user claimed to be selling searchable access to identity documents for more than 170 million people across North America. Nexus reportedly went dark shortly after Krebs published his findings, though the article notes the underlying data may still circulate on other criminal marketplaces.

Why Driver’s License Data Is Hard to Contain

The core risk is that a driver’s license cannot be reset like a password or reissued as easily as a credit card. A license scan can connect a person’s face, name, date of birth, home address, and license number in one document.

That makes the information useful for identity verification attempts across banks, government services, cell carriers, and consumer platforms. If a scanned license is searchable in criminal markets, the exposure can remain relevant long after the original platform disappears.

What the Report Says Was in the Dataset

According to the Gizmodo article, each license entry reportedly included six image files: front and back scans, plus infrared and ultraviolet versions of the same document. Those versions matter because they can show security features used to validate modern IDs.

The platform also reportedly held more than 10 million ID cards, 3 million travel documents and international IDs, and roughly 579,000 medical cards, including marijuana dispensary cards. Some records were marked “CAC,” which the article says could refer to Common Access Cards if confirmed.

Practical Steps to Reduce Fraud Risk

There is no perfect fix for a leaked identity document, but consumers can still reduce risk. Gizmodo recommends starting with a credit freeze at Equifax, Experian, and TransUnion because a freeze can prevent new accounts from being opened in your name.

People who have handed over scanned IDs to businesses such as car rentals, hotels, retailers, or dispensaries should be alert for targeted phishing tied to identity theft protection, record verification, or investigation updates. The article also frames dark web monitoring and phishing protection as useful tools after this kind of exposure, while noting that such services could not have prevented a vendor-side breach.

Discover More

    Google Gemini logo with cybersecurity-themed illustration
    Gemini Test Breakout

    Gemini reportedly reached real company systems during a flawed security test.

    Google GeminiAI Security
    A macro close-up photograph shows the Google Gemini AI app icon
    Gemini’s AI Hacking Test

    Gemini accessed three companies’ protected systems during cybersecurity testing, according to TechCrunch.

    AICybersecurity
    U.S. Coast Guard troops scaling a ladder onto a vessel
    Hacked Tankers Boarded

    The FBI and Coast Guard investigated compromised tanker networks near the U.S. coast.

    CybersecurityShipping