Home>Articles>A Startling Report Just Revealed Millions of Driver’s Licenses Were ‘For Sale’ on the Dark Web

Real ID, California DMV. (Photo: dmv.ca.gov)

A Startling Report Just Revealed Millions of Driver’s Licenses Were ‘For Sale’ on the Dark Web

Hackers, thieves, and other criminals—including those operating overseas—are constantly looking for new information they can exploit to their advantage

By Michael Letts, September 3, 2026 11:45 am

It’s scary how easily certain information about you and your family can be found on the “dark web.” What’s worse is how quickly that information can potentially be used against you—for illicit charges, spam emails, identity theft, and who knows what else.

A new report revealed that a site on the dark web known as Nexus was recently offering citizens’ driver’s licenses for purchase, with more than 150 million records reportedly available. 150 million.

That’s absolutely terrifying. In fact, this could easily be considered one of the largest exposures of personal identification information I’ve seen yet. Imagine how much sensitive information could potentially be accessed from these records.

The information was first shared by independent journalist Brian Krebs, who discovered the service being advertised on a Russian cybercrime forum. For good measure, the site also allegedly included his actual Virginia driver’s license as a free sample.

“The record that features my driver’s license includes six image files – three pairs of photos of the license’s front and back, a basic image scan, as well as infrared and ultraviolet versions of the same images,” he noted. “A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the Midwest United States to attend a family funeral.”

This is deeply concerning. Nexus initially noted on its website that the license scans came from a “major identity verification company,” which was later identified as IDscan, according to researcher Zach Edwards. But questions remain about exactly where and how the information may have been exposed. Could it have occurred at airport security, at driver’s license offices, or somewhere else entirely?

The FBI has already taken note of the report and is currently investigating the matter. The website, perhaps unsurprisingly, went offline following the publication of Krebs’ report.

“The FBI can confirm that it is looking into the incident.”

Sadly, that’s just the world we live in these days. Hackers, thieves, and other criminals—including those operating overseas—are constantly looking for new information they can exploit to their advantage. Credit cards can be compromised and charged thousands of dollars, leaving victims high and dry when their funds are locked up. Worse yet, identities can be stolen, leaving people scrambling to reclaim whatever parts of their lives they can.

If the reported scale of this incident proves accurate, it could mark one of the largest known exposures of government-issued identity documents. And it serves as a wake-up call: Even if you think your information is safe, there is always a chance that it may not be.

“Based on all the details in the article and how Brian was literally able to dox me (and the timing of the screenshot of my license being added into the system aligning to my trip), all the signs point to IDscan having a hellacious ongoing real-time breach of their data,” Edwards noted on social media. “This is a massive vendor.”

IDscan has already confirmed that it is assisting the FBI with the investigation.

So, what can you do to protect yourself? My best advice is to monitor your accounts closely. Keep a close eye on your bank accounts and credit activity, and consider additional protection through identity theft protection services, such as LifeLock or Aura. These days, you can never be too careful.

If you see even a hint of suspicious activity on your bank account—even something as small as an unfamiliar $1 charge—contact your bank immediately. Freeze or cancel the affected card and ask the bank to issue a new one if necessary. You may have to wait a little while for a replacement card to arrive, but that inconvenience can provide peace of mind and potentially prevent far greater losses later.

I’m sure this will serve as a serious wake-up call for the FBI and law enforcement more broadly about the dangers of the dark web and how easily personal information can wind up there. We definitely need to continue strengthening cyber enforcement and cybersecurity efforts, lest we be left exposed to horrendous financial and personal damage from leaked information.

Take care of yourselves, your family, and your friends, folks. The thieves are out there, and they’re looking for every bit of digital information they can exploit.

Print Friendly, PDF & Email
Spread the news:

 RELATED ARTICLES

Leave a Reply

Your email address will not be published. Required fields are marked *