Identity Verification Breach: 153M Driver's License Scans Sold
A dark web listing offered 153 million stolen driver's license scans, UV and IR images included. Here's why that points to an ID verification vendor.

On 30 August 2026, at 15:09 UTC, our collection picked up a new advert from a seller calling themselves inordinate. The title was "160M+ USA DL/ID Scans + Data". Nobody was talking about it yet.
The seller wasn't offering a one-off dump. They'd built a searchable web app, branded it NEXUS, and let anyone register and search for free. You paid per record, and before paying you could preview a redacted version with the person's photo visible.
According to the listing, the database held:
153 million US and Canadian driver's licences
10 million ID cards
3 million travel documents and international IDs
579,000 medical cards, including cannabis dispensary cards
Around 500,000 new documents added every day

Image: Sinon dark web intel collector flagging the activity on 30th August
The seller made no secret of the source. They claimed persistent access to "a major identity verification company and its customers, which include multiple Fortune-500 companies," and said they'd been pulling data continuously "for over a year."
Why the UV and IR scans point to an ID verification vendor
The 153 million figure is what made headlines. For us, the more telling part was a line further down. It said records could include front and back scans "under regular light, UV light, and IR light."
Nobody has infrared images of their own driving licence. Those come from document-authentication scanners, the kind a bar, car rental desk or bank uses to check a card's hidden security features. So this data almost certainly didn't come from a DMV, a state records system or a consumer app breach. It came from somewhere that physically scans ID cards to check them.
That changes what's actually been exposed. A DMV breach leaks records about you. A verification vendor breach leaks images of the card you handed over, along with the transaction it was tied to. That means where you were, and whether you were buying something, renting something or opening an account.

Image: Screenshot of the NEXUS web page that was built to browser breached data
What's been confirmed so far
After our capture, the story broke and a federal investigation was opened. The ID verification provider reported as the likely source has said publicly that it received information suggesting some data may have been accessed without authorisation. It also said an unauthorised third party may have accessed or copied customer information in its cloud environment. It hasn't confirmed the scope or the 153 million figure, and says its investigation is ongoing.
Several class actions were filed within 72 hours. Every one names the vendor. None name the businesses whose customers were scanned through it. The NEXUS service went offline soon after the coverage started.
To be clear about what we're claiming, our evidence is the listing: what it contained and when it appeared. The link to a specific vendor came from other reporting, and the vendor hasn't confirmed it.
Why identity verification vendors keep getting breached
We've seen this before. By our count, it's the third time in three years that a company whose job is checking who you are has leaked identity documents at scale.
The closest precedent is the 2024 exposure at an identity verification firm used by X, TikTok, LinkedIn, Coinbase, PayPal and Uber. Admin credentials sat exposed for about eighteen months. They circulated in criminal channels for over a year before anyone acted.
The same two problems show up in both cases, and we don't think either is bad luck.
The first is how long attackers go unnoticed. The seller here claims a year of continuous extraction, and the 2024 exposure ran for eighteen months. Part of the reason is that reading huge volumes of identity documents is a normal day's work for a verification vendor. A monitoring tool has no spike to catch, because the attacker's traffic looks just like the vendor's own.
The second is concentration. Businesses hire a verification vendor so they don't have to handle ID scans themselves. The result is that thousands of companies send the same kind of sensitive document to one place. That's the service they're paying for, and it's also why one intrusion yields 153 million records instead of a few thousand. We've seen the same thing in other shared-platform compromises, where the victims have nothing in common except a supplier.
Managing third-party ID verification risk
Individuals caught up in this can't do much. You can change a password in a minute, but you can't change your date of birth or your face. In most US states, a replacement licence also keeps the same number. High-resolution scans of a card under three kinds of light will stay useful to fraudsters for decades.
So most of the work falls on organisations.
Find out which of your vendors scan IDs. Most security teams can list their cloud providers but couldn't tell you who handles their ID checks. If you run age verification, rental checks, KYC onboarding or visitor sign-in, someone is holding images of your customers' documents. Those images were collected at your counter, under your name.
Ask what happens to the scan after the check. Verifying an ID doesn't require keeping the image forever. Plenty of deployments keep scans anyway, because storage is cheap and nobody wrote a data retention policy. Ask your vendor what their default is and whether you can change it.
Plan for slow disclosure. This listing was live for days before anyone reported on it, and the access behind it had reportedly been running for a year before that. A quarterly vendor review won't catch something on that timeline. Don't count on the vendor's own monitoring to catch it either.