Security1 distinct publisher3 min readPublished
Every company that outsourced KYC document capture now owns an exposure it never inventoried, because the images being sold appear to come from the verifier rather than from any of its customers. The FBI opened the file in New Orleans.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The six image files behind each record are the useful evidence. The entry for Krebs holds three front-and-back pairs: a plain scan, an infrared version and an ultraviolet version, with a date and time appended to each file [8]. Infrared and ultraviolet passes are how a reader inspects the security features printed into a licence. That points at capture hardware standing at a counter, inside a verification workflow, rather than at a copied DMV table.
The collection points do not resolve to one venue. No passports appear in the set, which is what ended the airport theory [9]. One person found in the index had not flown recently and had a Hertz rental running for several months around the date of their timestamp [10]. The index also carries marijuana dispensary cards [11] and records tagged "CDL" or "CAC", the second of which may mean Common Access Cards [12]. A rental counter and a dispensary have little in common on the surface, but both could plausibly route their identity checks through the same verification supplier.
The size claim holds up on arithmetic. A blank search returns roughly 11.5 million pages at about 15 results per page [13], which lands near 172 million indexed documents and puts the 170 million figure in the sales thread inside the range rather than above it [14]. Canada supplies about 1.1 million of the licences, under one percent of the total, with Ontario the largest single concentration at 473,673 records [20][24]. Listings grew by nearly 400,000 licences in 24 hours [15]. At that rate, 153 million licences take about 383 days to pile up [17], which sits close to the "over a year" of continuous exfiltration the sellers advertise [16]. The numbers are consistent with each other, but consistency is not the same as corroboration.
There is no CVE here and nothing to patch. The exposure sits with every firm that moved document capture to a supplier and never wrote down where the raw frames went afterward. The questions are which supplier performs the capture, whether it keeps the infrared and ultraviolet frames after the check passes, for how long, and whether the contract obliges it to notify you when its own image store is the thing that leaks. Krebs has not named the Louisiana company [25], so procurement records are the only place a buyer can look. The Bureau opening this out of New Orleans is at least consistent with a vendor sitting in Louisiana [26].
The shop lets a buyer preview a record with pertinent fields redacted and displays the customer photo where it has one [21]. The workflow is built to confirm a named target is in stock before the buyer spends money, which functions less like a data dump and more like a fraud pipeline.
Ranked by verification strength, evidence, and original report placement.
A new identity theft service launched on the dark web is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.
The New Orleans field office of the FBI launched an official inquiry into the source of the images on the day of the report.
On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America.
The proprietor of the service offered the Virginia drivers license of KrebsOnSecurity's author as a free sample in the initial sales thread on Exploit.
The service, dubbed Nexus, claims more than 153 million drivers licenses for people in the US and Canada, more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards.
The people behind Nexus claim the license images come from an active breach at "a major identity verification company" whose customers include multiple Fortune 500 companies.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A free graph of ads.txt now shows which data brokers your own site authorised1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
security
Hired for depth, scored on growth: why the CISO seat keeps turning over1 distinct publisher
product
Apple's iOS 27 Wallet beta turns Apple Card into a subscription calendar1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-hand and verifiable, but only one set of hands
The proof here is unusually personal: the reporter's own license was the advertisement's free sample, and nine friends and relatives found in the index each confirmed travelling on or near their stamped date. That establishes the data is real and points hard at a rental counter. What it does not establish is the vendor — never named, never asked on the record in anything published, with Hertz silent and the FBI inquiry described rather than quoted.
A live market and an open file, no visible response
Three things are demonstrably in motion: a storefront running on Exploit, an index that grew by roughly 400,000 license records in a day and already returns more pages than the sellers advertise, and a field-office inquiry opened within hours. Absent from the record is anything on the other side — no vendor acknowledgement, no customer notifications, no takedown, nothing telling the people in the index that they are in it.
Numbers borrowed from the seller, origin still inferred
Modestly overstated, and mostly by construction. The 153 million and the 'over a year of exfiltration' are the criminals' own sales copy; the page-math check keeps them from being fantasy but does not confirm what the images are or where they came from. The bigger stretch is the framing that every company outsourcing document capture now carries this exposure — that follows only if the verifier really is the breach point, which nine rental-counter anecdotes suggest rather than settle.
Three interested parties, one of them the reporter
Follow who gains. The sellers need the number big and the breach sounding active, and they supplied both figures. The verifier gains from staying anonymous, and so far has. And the reporter's own license was the bait in the sales thread — which is simultaneously why this story exists at all and why its central verification step was available to him and to almost nobody else.
Solid on the storefront, thin on the source
Split the story in two and confidence splits with it. That a marketplace exists, holds genuine license imagery in triple-exposure sets, and is still being fed — that much is close to settled by direct observation. Who was breached, how far it reaches, and which businesses routed captures through the affected pipeline remain a single reporter's working hypothesis awaiting a name.