
The FBI is investigating a possible data breach that may have exposed more than 153 million driver’s licenses in the U.S. and Canada.
Independent journalist Brian Krebs on Tuesday reported a dark web site that claimed to be selling digital scans of driver’s licenses. The FBI confirmed to TIME that the bureau is “looking into the incident,” but declined to comment “due to the ongoing nature of the investigation.”
The IDs that the service, which is now offline, advertised for sale reportedly included that of Defense Secretary Pete Hegseth.
If the service’s reported claims are true, the breach could be one of the most extensive single leaks of driver’s license data, says James E. Lee, President of the Identity Theft Resource Center, which has tracked breaches since 2005.
“This data set will continue to have massive value to the cybercriminal community for many years, and we are likely to see this service or one very similar appear again on the darknet,” Krebs tells TIME.
Experts also warn that this incident illustrates the risks of companies retaining ID scans and biometric data for age and identity verification.
Here’s what to know about the possible breach and what it could mean for your data.
Krebs, who runs an independent cybersecurity news site “KrebsOnSecurity,” said he was alerted to the site on Monday. The site had been advertised on a Russian cybercrime forum as a service selling digital scans of identity documents belonging to more than 170 million people in North America, according to Krebs. Krebs said his own driver’s license had been offered as a free sample by the service.
“It doesn’t bother me seeing my data out there because I’m used to that,” Krebs tells TIME. “But it’s more aggravating to see this information available on friends and family members.”
The service, called “Nexus,” claimed to have more than 153 million driver’s licenses belonging to people in the U.S. and Canada, more than 10 million identification cards, and more than three million travel documents or international IDs, Krebs reported. It also claimed to have hundreds of thousands of medical cards.
Krebs said he was able to confirm nine of the leaked documents. TIME has not independently verified the service’s reported claims.
Soon after his report was published, Krebs said in an update that the “Nexus” site appeared to have vanished.
It is not yet clear what the source of the breach is.
According to Krebs, Nexus claimed in its forum post that it obtained the documents through a live breach at a “major identity verification company,” and that it had been “exfiltrating new data for over a year into our private database.”
A spokesperson for IDScan.net, an identity verification provider based in New Orleans, told Krebs that the service was investigating the incident. The company works with marijuana dispensaries across the U.S. to validate IDs, as well as other businesses requiring ID verification spanning retail, transportation, finance, and other services.
TIME has reached out to IDScan.net for comment.
There have been confirmed breaches with larger reported victim or record counts. For example, in 2013, Yahoo suffered a breach affecting all three billion user accounts at the time, and in 2018, the global hotel chain Marriott disclosed a breach of its Starwood reservation database that affected hundreds of millions of guest records.
But the potential Nexus breach could be one of the largest involving government IDs. It is also notable as the service reportedly claimed to provide a searchable trove of ID scans, including both front and back images, and infrared and ultraviolet scans of the IDs.
Other recent breaches have exposed driver’s license information on a smaller scale.
In June, the Texas Parks and Wildlife Department said an unauthorized actor may have obtained information belonging to more than 3 million hunting and fishing license customers through a third-party vendor. The potentially compromised data included drivers’ license information, passport numbers, and phone numbers, but did not include Social Security numbers. The department said it strengthened access controls and was working with the vendor on other safeguards. Officials have not publicly identified the vendor or announced an enforcement action.
In 2023, hackers exploited a vulnerability in a file-transfer system, MOVEit, used by Louisiana’s Office of Motor Vehicles. The breach affected roughly 6 million records in the state. Officials said Clop, a cybercriminal extortion group, had claimed responsibility for the breach, and that authorities were monitoring dark web activity associated with the group. The state said the vulnerability was since patched and that additional safeguards were added.
The following year, background-check company National Public Data confirmed that hackers had accessed records containing personal information, including Social Security numbers, of millions of people.
“Unfortunately, breaches of this size are now all too common,” Lee says.
A breach involving ID images carries “significantly worse” security risks than a breach that involves ordinary personal data or ID numbers, Edgar Whitley, a Professor of Information Systems in the Department of Management at LSE, tells TIME.
A high-quality image of a government-issued ID like a driver’s license makes it a lot easier for identity thieves to impersonate the license-holder, according to Lee. A copy of an ID can be used in opening new lines of credit, or it can be combined with information from other breaches in targeted phishing attempts or to hack accounts. Whitley says such images can also be used to make AI deepfakes.
Biometric characteristics, unlike passwords or identification numbers, also cannot easily be changed, Whitley adds. “You can reissue a new password but not a new face.”
It’s difficult for individuals to limit their exposure, according to experts.
“There is no way to ‘protect’ yourself from someone else using a digital scan of your license if the company collecting the scans is relieved of them by hackers, apart from choosing not to have your ID scanned by anything or anyone,” Krebs tells TIME.
“What we can do,” says Lee, “is make our information … less useful and harder to impersonate.”
If you believe your personal information has been compromised, Krebs recommends freezing your credit with the three big consumer credit bureaus: Equifax, Experian, and TransUnion. Doing so makes it harder for an identity thief to open new credit accounts in your name. FrozenPii.com, an ITRC website, helps customers freeze their credit and other identity-related processes.
You can also place a fraud alert and report identity theft at IdentityTheft.gov.
The risks of a breach are likely to increase as more and more businesses and agencies require identity or age verification to provide a service, especially when that information is shared with third-party providers, experts say. “Robust identity verification is no longer a luxury or optional for businesses of all sizes,” Lee says.
Responsibility for keeping consumers’ data safe rests with the organizations that collect and store that data, Whitley says. The National Institute of Standards and Technology, a federal agency that develops technology standards, recommends that identity-verification providers collect only information necessary for the transaction and limit its retention of consumers’ personal data. Consumers can also ask about how their information will be used and stored, and whether presenting a physical identity document is sufficient.