FBI Probes Breach of 160 Million American Driver's License Scans

Source: X | @realdefender45

EXECUTIVE SUMMARY

The Federal Bureau of Investigation (FBI) opened a formal investigation after criminals began selling scans of more than 160 million North American driver's licenses on a Russian-language cybercrime forum. The stolen data traces to idscan.net, a New Orleans-based identity verification company. A cybersecurity researcher whose own license appeared in the stolen set confirmed the breach is an ongoing, real-time intrusion.

ANALYSIS

The Nexus service appeared on the Russian-language cybercrime forum Exploit on September 1, 2026, advertising searchable access to more than 153 million scanned driver's licenses belonging to people in the United States and Canada. The sellers claimed the data came from "a major identity verification company and its customers, which includes multiple Fortune-500 companies." Journalist Brian Krebs traced the source to idscan.net, a New Orleans company whose clients include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and financial services firm Jack Henry. Krebs confirmed the authenticity of the stolen data with nine individuals whose licenses appeared in the set.

The stolen set is larger than driver's licenses alone. The same advertisement offered access to more than 10 million additional documents, including residency cards, medical identification cards, and international identity documents. The seller told Krebs that exfiltration had been running continuously for over a year, and that in a 24-hour window the license count grew by approximately 400,000 records. That growth rate indicates the attacker is positioned on or near the live processing pipeline, capturing documents as they are submitted, not working from a static copy of a database.

The FBI's New Orleans field office opened a formal investigation on September 1. A bureau spokesperson confirmed: "The FBI can confirm that it is looking into the incident. Due to the ongoing nature of the investigation, we decline to comment further." The Nexus service went offline after the investigation became public. That does not mean the stolen data was recovered or the intrusion terminated.

Cybersecurity researcher Zach Edwards of Infoblox, whose own identification appeared in the data, assessed the breach as a real-time, ongoing intrusion. Edwards stated the attack created "legitimate national security risks for high-profile individuals." Defense Secretary Pete Hegseth's driver's license is among the exposed records, confirming senior government officials are included in the stolen set. No disclosure has been made to affected individuals by idscan.net.

SOURCES

Previous
Previous

Whistleblower Who Exposed Corrupt FBI Chief Found Dead in Florida Apartment

Next
Next

Downtown Minneapolis Mass Shooting Kills Two and Wounds Three Officers