I rented a car, and within hours, my driver’s license was for sale

by | Sep 28, 2026 | Technology

I rented a car, and within hours, my driver's license was for sale

The FBI is investigating a significant data breach involving the unauthorized sale of driver’s license scans on the dark web, according to reporting published earlier this week by security journalist Brian Krebs. The illicit marketplace, known as Nexus, offered more than 153 million driver’s licenses for purchase, including those belonging to Krebs himself, his family members, an FBI assistant director, and multiple cybersecurity researchers.

The stolen license scans included comprehensive image files capturing both front and back sides of identification documents in standard, infrared, and ultraviolet formats. Security experts suggest the inclusion of infrared and ultraviolet data could potentially enable the creation of counterfeit IDs capable of bypassing holographic security features. Beyond driver’s licenses, Nexus advertised access to various other identity documents, including commercial driver’s licenses, government access cards, and marijuana dispensary identification.

The timing of the breach indicates real-time or near-real-time access to a centralized data source. Stolen IDs became available for purchase within hours or days of individuals presenting them at businesses such as car rental agencies and dispensaries. During one 24-hour period tracked by Krebs, the inventory of available licenses grew by approximately 400,000, suggesting the breach remains ongoing with continuous additions to the stolen data.

Investigation by Krebs and other security professionals pointed to IDScan.net, a New Orleans-based ID scanning service, as a potential source. The company has publicly disclosed partnerships with several major businesses, including a car rental company and a multi-state cannabis dispensary chain. IDScan.net indicated its scanning technology captures infrared and ultraviolet spectra. Representatives from IDScan.net and the car rental company involved did not immediately respond to inquiries. The Nexus marketplace went offline within hours of the public disclosure of the breach.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI