Hackers Leak 153 Million U.S. Driver's Licenses, FBI Launches Probe
PUBLISHED Sep 2, 2026, 3:54 PM ET
Read, Watch or Listen
Federal authorities are investigating a massive data breach involving over 153 million driver license scans and identification documents offered for sale on a dark web marketplace named Nexus. Security researchers confirmed that the cache includes standard driver licenses, commercial permits, and military Common Access Cards, allegedly originating from third-party identity verification provider IDScan.net. The compromised dataset features records belonging to citizens across the United States and Canada, alongside credentials tied to high-profile figures such as Secretary of Defense Pete Hegseth. The breach has raised significant concerns regarding corporate data retention practices and national security risks associated with third-party identity verification services. Cybersecurity analysts report that the threat actors claim ongoing access to underlying systems, uploading hundreds of thousands of new document scans daily. The Federal Bureau of Investigation field office in New Orleans has initiated formal inquiries to trace the origin of the leak and identify the perpetrators responsible.
By Michael Grant | JQJO News
Timeline of Events
- On August 31, 2026, dark service Nexus launched offering millions of credential scans.
- On September 1, 2026, security researchers verified the scale of the exposed document repository.
- On September 2, 2026, reports identified verification provider IDScan.net as the source.
- On September 2, 2026, the Federal Bureau of Investigation launched an official emergency probe.
- On September 2, 2026, media outlets confirmed military credentials among the leaked files.
- On September 2, 2026, investigators reported attackers adding hundreds of thousands daily updates.
- On September 3, 2026, corporate clients initiated independent audits of verification security protocols.
- On September 3, 2026, privacy advocates criticized mandatory physical document collection by private firms.
- On September 3, 2026, federal lawmakers demanded stricter oversight on identity verification vendors.
- On September 3, 2026, cybersecurity firms deployed enhanced monitoring tools for affected individuals.
News Intelligence
- Immediate US impact: Millions face immediate identity theft and targeted phishing threat risks.
- Possible long-term US impact: Stricter federal regulations will govern third-party data collection practices.
- Most affected groups: U.S. citizens, Canadian residents, federal agencies, and identity verification vendors.
- Reader priority: Monitor credit reports closely across trusted financial and cybersecurity outlets.
Left: Emphasizes corporate regulatory failures and inadequate consumer privacy protections. Center: Reports factual details regarding the FBI investigation and technical scope. Right: Focuses on national security vulnerabilities and high-profile government credential risks.
KrebsOnSecurity published initial investigation into the Nexus dark web leak. https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Coverage of Story:
From Center
Hackers Leak 153 Million U.S. Driver's Licenses, FBI Launches Probe
JQJO KrebsOnSecurity Tom's Hardware PCMag Malwarebytes AI Weekly BigGo News AppleInsider Dark Reading Forbes Bloomberg Reuters Wall Street Journal The Verge Washington Post New York TimesFrom Right
No right-leaning sources found for this story.
Comments