CYBER DELTA FORCESearch

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

CDF News DeskKrebsOnSecurity2 Sept 2026, 4:10 am
CDF REPORT

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images. A record available at this identity theft service that includes the drivers license for U.S.

That’s notable because we both handed our licenses to the Hertz rental car representative at the same time. “This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. The record featuring my drivers license includes six image files: three pairs of photos of the license’s front and back, a basic image scan, as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral. Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames.

During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net. Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.

What changed

After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel.

Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division.

Who is affected

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.” Other records carry the source notation of “CAC,” which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms.

Customer photos are displayed if available.” Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me.

The “trust” page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, Target , Fedex , Motorola Solutions , the financial services giant Jack Henry , and Caesars Entertainment .

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

8: IDscan.net published a brief notice saying it has “determined that an unauthorized third party may have access and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers.” The statement said IDscan.net is notifying affected individuals and offering credit protection services.

Why this matters

That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.

“This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity.

Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

The technical picture

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit.

The record featuring my drivers license includes six image files: three pairs of photos of the license’s front and back, a basic image scan, as well as infrared and ultraviolet versions of the same images.

A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.

Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames.

Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service.

How organizations are responding

During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.

Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN CLOUD & IDENTITY

More cybersecurity reporting

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev ServersThe Hacker News · 15 Sept 2026, 4:42 pmChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEThe Hacker News · 15 Sept 2026, 11:01 amTwitch extension with 30K installs exposes users’ OAuth tokensBleepingComputer · 15 Sept 2026, 12:33 amUnmasking Cloud Identities: From Behavioral Clustering to Automated DetectionPalo Alto Unit 42 · 14 Sept 2026, 3:30 pm