Most "millions of records leaked" claims on cybercrime forums don't hold up to scrutiny. This one did.
In late August 2026, a dark web marketplace called Nexus surfaced advertising 153+ million U.S. and Canadian driver's license scans — front, back, plus the infrared and ultraviolet captures identity-verification systems use to detect counterfeits. A blank search (no query terms) reportedly returned ~11.5 million pages of results at ~15 records per page, lining up with the claimed total.
The verification methodology is what's interesting from a SOC/OSINT angle: researchers cross-referenced leaked record timestamps against real-world events. One researcher's own license matched a dispensary visit in Las Vegas during DEF CON. Another matched a Hertz rental. Records reportedly tied to a sitting U.S. Defense Secretary were also found searchable.
The suspected source is IDScan.net, an identity-verification vendor processing 21M+ checks monthly across car rental, retail, hospitality, and cannabis clients. No confirmed breach yet — but the FBI's New Orleans field office has opened a formal investigation.
The operator's claim of "continuously exfiltrating new data for over a year" is the real detection-failure story here — this wasn't a smash-and-grab, it was a sustained pipeline nobody caught.
Full writeup covers the verification process, an exiftool-based metadata check investigators use for this kind of validation, and concrete detection/response steps for both individuals and security teams:
https://www.xpert4cyber.com/2026/09/153-million-drivers-license-leak-dark-web.html
Top comments (0)