Skip to main content
AI Everywhere: See and Control the Risk with Adaptive AI Governance, September 23
Blog

153 Million IDs, One FBI Investigation, and the Case for a Second Verification Layer

SEPTEMBER 9, 20265 MIN READ
Marshall BennettMarshall Bennett
153 Million IDs, One FBI Investigation, and the Case for a Second Verification Layer

Key takeaways

  • A dark web service called Nexus offered searchable access to more than 153 million U.S. and Canadian driver’s licenses and other IDs, including front, back, infrared, and ultraviolet scans; TechCrunch and Gizmodo traced the data to Louisiana-based IDScan, whose technology is used by car rental counters, hotels, dispensaries, and financial institutions.
  • The leak is especially dangerous because infrared and ultraviolet images reveal anti-counterfeiting features used to distinguish genuine licenses from fakes; LSE professor Edgar Whitley said high-quality government ID images create significantly worse risks than ordinary personal-data breaches because they make impersonation much easier.
  • The FBI’s New Orleans field office opened an investigation, IDScan said it was looking into the reports, and lawsuits were filed in Louisiana, but the core cause remains unknown; TechCrunch and CyberInsider reported new records were still appearing at 400,000 to 500,000 per day until the listing disappeared, suggesting ongoing access rather than a one-time theft.
  • The article argues the bigger industry problem is third-party ID storage: researcher Zach Edwards warned that sensitive data is flowing into more vendors without enough oversight, while Bruce Schneier’s view is that stored data becomes a liability the longer it sits; Experian’s analysis of FTC data put U.S. identity theft and fraud losses above $15.8 billion in 2025.
  • Security teams are urged to treat identity verification vendors like other regulated data handlers by requiring a current SOC 2 report or equivalent independent audit and by putting retention limits, breach notification timelines, and deletion requirements directly into contracts.
  • The practical control recommendation is to minimize retention of scanned IDs and add a second verification layer—such as a one-time code, a callback to a known number, or a live check—so a leaked document alone is not enough to impersonate someone; James E. Lee of the Identity Theft Resource Center warned the data set will likely retain value for cybercriminals for years.

In early September, a dark web listing called Nexus surfaced on a Russian cybercrime forum, offering searchable access to more than 153 million U.S. and Canadian driver’s licenses and other identity documents. Buyers could preview a record before paying, and each one came with front, back, infrared, and ultraviolet scan images. TechCrunch and Gizmodo traced the data back to IDScan, a Louisiana-based identity verification company whose scanning technology runs at car rental counters, hotels, dispensaries, and financial institutions across the country.

Those infrared and ultraviolet scans are the details worth pausing on. They capture the anti-counterfeiting features printed into the document itself, the same features a bouncer's scanner or a rental car clerk's device checks to tell a genuine license from a fake one. Edgar Whitley, a professor of information systems at the London School of Economics, has explained why that makes this leak different from an ordinary breach. “A breach involving ID images carries significantly worse security risks than a breach that involves ordinary personal data or ID numbers.” Whitley said. “A high-quality image of a government-issued ID like a driver's license makes it a lot easier for identity thieves to impersonate the license-holder.” The 153 million leaked scans expose who someone is. Beyond that, they hand a forger a blueprint for reproducing the security markers meant to catch a fake in the first place.

What We Know, and What Remains Unanswered

The FBI’s New Orleans field office opened an investigation. IDScan’s chief operating officer, Jillian Kossman, said the company was looking into the reports. Multiple lawsuits have since been filed in Louisiana. Within days of the story becoming public, the Nexus listing disappeared from the dark web.

What has not been disclosed is how the underlying access happened. Reporting from TechCrunch and CyberInsider both note that new documents kept appearing in the listing at a rate of 400,000 to 500,000 a day, right up until it went offline, which points to some kind of ongoing access rather than a single one-time theft. Neither outlet has confirmed whether that access came through an exposed API, a compromised credential, a misconfigured database, or another route entirely. Nor is it yet known how long that access existed before anyone noticed.

That gap matters more than the takedown itself. A fast public response is good news. It is not the same thing as knowing how the door was left open, or for how long.

Why This Reaches Beyond One Company

Scanning a government-issued ID has become part of ordinary business in dozens of industries. That convenience comes with a tradeoff: a single driver’s license now lives inside far more third-party systems than most people realize, and each one of those systems is a separate place the same document can leak from.

Zach Edwards, a security and privacy researcher who reviewed the Nexus listing, described the pattern directly. “These systems are putting sensitive data into more and more third-party vendors, and we don't have nearly the oversight to ensure they are safe,” Edwards said. That is a call for stronger oversight, and it applies to every company in this industry, not only the one named in this incident.

Bruce Schneier, a fellow and lecturer at Harvard’s Kennedy School, has made a related argument about stored data generally. “Saving it is dangerous because it’s hard for companies to secure,” Schneier has written, arguing that a sufficiently skilled and motivated attacker will eventually get past any single layer of defense. His broader point is that data sitting in storage behaves like a liability on a balance sheet, valuable to have, expensive to protect, and riskier the longer it sits unused.

Applied to identity documents, that argument points to a specific, practical fix. The less time a scanned document sits in storage, and the fewer places it sits, the smaller the target it becomes. U.S. identity theft and fraud losses topped 15.8 billion dollars in 2025, according to Experian’s analysis of FTC data, which is exactly why getting this right benefits every party in the transaction, the business collecting the ID included.

What Public Disclosure Did, and Did Not, Fix

Independent researchers and journalists identified the Nexus listing, confirmed the data was genuine, and published their findings quickly. That disclosure removed the ability to buy from Nexus within days of the story breaking. It is a good outcome, and it happened because people with visibility into the dark web spoke up in public rather than staying quiet.

It did not answer the harder questions. How long was the access point open? How many of the 153 million documents were pulled before anyone noticed? Those answers, once they come, will matter more to the industry’s next steps than how quickly the listing went dark.

The lawsuits filed in the aftermath serve a useful function regardless of how those questions resolve. They create a direct financial incentive for every company handling ID documents, not just the one named here, to treat stored identity data with more care and to be able to prove it.

What Security Teams Can Do Right Now

This is where the vendor relationship becomes the actual lever. Security teams already treat payment processors and cloud providers as regulated data handlers, requiring independent audit evidence and contractual data handling terms before signing. Identity verification vendors deserve the same treatment.

  • Ask for a current SOC 2 report or equivalent independent audit, not a marketing claim about security. Put data retention limits, breach notification timelines, and deletion requirements directly into the contract, rather than trusting a vendor's default policy.
  • Retention is a lever every organization controls directly. A scanned ID kept for years after a transaction closes is pure liability with no ongoing benefit. Setting a firm deletion schedule closes off exactly the kind of exposure Nexus took advantage of.
  • A second verification layer matters just as much. A one-time code, a callback to a known number, or a live check alongside a document scan means one exposed record stops being enough on its own to impersonate someone.
  • Individuals have a role too. Anyone can check whether a driver’s license has surfaced in a known leak through a breach monitoring service, and place a fraud alert or credit freeze if it has. It is also fair to ask any business that scans an ID how long that scan is kept and what happens to it afterward. A well-run business will have a clear answer ready.

A Shared Responsibility, Still in Progress

Security researchers, law enforcement, the businesses that rely on identity verification, and the people whose documents get scanned every day all have a stake in closing the gap this incident exposed. The fast takedown of Nexus is a genuine result. The unanswered questions behind it are the more important work still ahead.

James E. Lee, president of the Identity Theft Resource Center, has a clear-eyed read on why that work does not end with one takedown. "This data set will continue to have massive value to the cybercriminal community for many years, and we are likely to see this service or one very similar appear again on the darknet," Lee said. That is exactly why building strong verification practices into daily operations matters more than responding well to any single incident.

The businesses that come out ahead will treat every scanned document with the same discipline as a password, hold their vendors to the same audit standard they'd apply to any other regulated data handler, and add a second way to confirm someone is who they say they are.

Get started with Adaptive Security

Human and agent security for the AI era.