Product2 distinct publishers2 min readPublished
A dark web service says its licence images come from a live breach at an identity verification company whose customers include Fortune 500 names, which makes an uploaded document a weaker check for everyone downstream.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The victims who confirmed their own records did it by reading a timestamp. Several told KrebsOnSecurity the date on the image matched the day they had handed a licence over while travelling or renting a car [14]. The capture point was a counter transaction, and the image stayed in a system long after the clerk waved them through.
Fidelity is what makes the set valuable to a buyer. Some records hold several images of the same licence, front and back, shot under infrared and ultraviolet light [13]. Those are the channels scanner hardware reads to check the security printing on a card, which means the stolen files arrive in the format an automated check is hoping to see.
The scale claim survives crude arithmetic. A blank search on the service returned about 11.5 million pages at roughly 15 records a page [11], which multiplies out to about 172.5 million records against the 170 million the seller advertised [18][2]. Roughly 1.1 million were Canadian, more than 473,000 of those from Ontario [12], and Krebs reported senior US officials in the set, including Defense Secretary Pete Hegseth [15]. The sellers also said the tap was still open, adding nearly 400,000 scans inside 24 hours [6]; at that pace the pile grows by around 12 million a month [19].
Teams assume a document check proves the person is who they claim to be. In practice it captures an image and keeps it, because the kept image is the audit artifact. The control was built for the compliance file, not for the user. That file is what turned into inventory.
For each flow in your product that asks a user for a document, ask two questions. Does the decision need the image after the decision has been written. And would the outcome change if you assumed the image were already public. Put those on axes and only one box of the four is dangerous: image retained, document match doing the work alone. A flow sitting in that box now has a control whose input a stranger can buy [1].
Getting out of that box means pairing the document with a signal the verification vendor never handled, and deleting the image once the decision is logged. The cost lands on the compliance side of the house. You give up the picture you would have shown a regulator or a card network, and you have to argue that a decision log plus a hash of the image is enough evidence of diligence. The argument is easier to make this week because the vendor named in the reporting isn't yours [7].
Ranked by verification strength, evidence, and original report placement.
A new identity theft service on the dark web, called Nexus, is selling digital scans of more than 153 million drivers licences belonging to people in the United States and Canada.
Nexus was advertised on the Russian cybercrime forum Exploit on August 31, and its operator claimed to hold identity documents belonging to more than 170 million people across North America.
The claimed inventory includes more than 153 million driving licences, 10 million other identification cards, three million travel documents or international IDs, and at least 579,000 medical cards.
The FBI's New Orleans field office launched an official inquiry into the source of the images, and had not released a public statement about the investigation.
IDScan.net confirmed it was investigating the claims but had not determined whether unauthorized access occurred or what information may have been exposed.
The people behind Nexus claim the licence images come from an active breach at a major identity verification company whose customers include multiple Fortune 500 companies.
Distinct publishers with included, body-backed reporting in this cluster.
9to5mac.com
1 article · September 2, 2026
dexerto.com
2 articles · September 2, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsroom's legwork, relayed three times
Strip away the attribution and every load in this story rests on KrebsOnSecurity: the forum listing, the page counts, the vendor trail, the FBI inquiry. What lifts it above rumour is concrete verification work — Krebs was shown a scan of his own licence, other victims confirmed theirs, and timestamps lined up with real rental and dispensary visits. What holds it back is that neither Dexerto nor 9to5Mac checked anything themselves, Dexerto says outright that the full scale is unconfirmed, and the two facts that would close the case sit with an FBI office that is silent and a vendor that says it does not yet know.
A live market that answered questions and then closed
There is more here than an advertisement. The service was listed on Exploit on 31 August, gained nearly 400,000 records in a single day, drew an FBI field-office inquiry and an internal review at the vendor, and then went dark within hours of publication. Those are five separate real-world movements in roughly two days. The ceiling is that all of them describe activity around the data rather than its scope: no company has notified customers, no regulator has spoken, and once the site vanished the one thing anyone could actually query disappeared with it.
The headline number is still the seller's
153 million is a criminal's inventory figure printed in a headline, and neither publisher pretends otherwise — yet both lead with it. The honest counterweight is that Krebs's spot check made it plausible: 11.5 million pages at fifteen records each works out near 172 million, in the same neighbourhood as the advertised total. So the overstatement is modest and specific rather than wholesale. It sits in two places: the leap from 'a Louisiana vendor fits the evidence' to a story shaped as a breach at that vendor, and 9to5Mac's silence on the site's disappearance, which leaves the danger sounding more current than the record shows.
The one party with numbers is the one selling
Follow the motives and they nearly all push the same way. Criminals running a paid service profit from a bigger catalogue and from insisting their access is still open; a vendor under suspicion gains from saying it cannot yet determine what happened; an FBI office mid-inquiry gains from saying nothing. Meanwhile the reporting is aggregated from a rival outlet by two consumer-tech publishers, one of which files it under entertainment and the other of which closes with a block of shopping links — attention economics, not a stake in the outcome, but not disinterested scrutiny either.
Firm on the shape, soft on the source
We can be fairly confident that a large collection of genuine North American licence scans was on sale, that at least some of it is authentic, and that both a federal inquiry and a vendor review are underway — those rest on verified samples and dated institutional responses. Confidence drops sharply on the two things readers most want: which company leaked, and how many people are actually in there. One publisher hedges the Hegseth detail and the other never names the vendor at all, which is a fair signal of how firm the underlying attribution really is.
Follow any of these and your For You feed starts watching them — no settings page required.
security
Twenty dollars a photo: the FBI's O'Hare affidavit is a fence-line problem, not a network one1 distinct publisher
invest
Tariff refunds are landing, and where the cash stops tells you who has pricing power1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 distinct publisher