The FBI is investigating a possible breach of an identity verification company after criminals advertised access to scans and data tied to more than 160 mn North American driver’s licenses. A bureau spokesperson confirmed that the agency is examining the incident but declined further comment because the investigation remains active.
The data appeared for sale through a new service called Nexus on Exploit, a Russian-language cybercrime forum. An advertisement for the service referenced more than 160 mn US driver’s license and identification scans alongside associated personal data.
The sellers described the material as a proprietary database of breached identity documents. They also claimed persistent access to a major identity verification company and its customers, including several Fortune 500 businesses.
Authorities haven’t identified the source of the records publicly, and the claims made by the sellers remain under investigation. The scale of the advertised database would make the incident unusually large if investigators confirm the figures and origin.
The group also offered access to more than 10 mn additional identity documents. Those records included residency cards, medical cards and identification documents issued outside the US.
Cyber threat researcher Zach Edwards said his own identification appeared among the documents advertised for sale. Edwards works for cybersecurity company Infoblox and described the operators as technically capable and financially motivated.
If confirmed at the advertised scale, the incident would rank among the largest exposures of US government-issued identity documents. Driver’s license scans contain information useful for identity verification, making widespread access valuable to criminals attempting fraud or account takeover.
Independent cybersecurity journalist Brian Krebs previously reported on the service. Krebs said he verified the authenticity of driver’s license records with nine people whose documents appeared in the database.
Nexus disappeared shortly after confirmation that the FBI had opened an investigation. It isn’t clear whether the service’s disappearance ended access to the underlying data or whether copies remain available elsewhere.
Edwards said evidence pointed to the possibility of an active breach rather than a static archive assembled from older incidents. He said newly submitted credentials appeared to be reaching the attackers while customers continued using the affected verification provider.
Such access would create a different risk profile from a one-time database theft. New identity documents submitted for verification could continue entering the attackers’ possession until the access path is removed.
Edwards also warned about exposure involving high-profile individuals. A continuing stream of government-issued identification documents would provide criminals with current information that might support impersonation or other targeted activity.
The FBI hasn’t disclosed which identity verification company it is examining or how many people might ultimately be affected. Investigators also haven’t confirmed the advertised totals of more than 160 mn driver’s license records and 10 mn additional documents.









