Blog

Breached Once, Exposed Forever: 153 Million ID Documents Go Up for Sale

Jack Corbett5 min read

  • identity verification
  • data breach
  • impersonation

How many companies are holding a copy of your passport or driving licence right now, and how many of them could you name?

Government ID has become the default way to prove you are who you say you are. The result is that thousands of companies now collect and store identity documents. Only one of them needs to fail, and the document is exposed. Passwords can be changed, but it’s much harder to change government ID and impossible to change your face or date of birth.

The reflex response to impersonation, and particularly the fear of deepfakes, is pushing firms to demand government ID for more things, in more places, more often. We are building massive stores of identity evidence as a control. But that control just spilled 153 million driving licences.

The incident

In late August 2026, an identity theft service called Nexus launched on the Russian cybercrime forum Exploit, offering searchable, previewable identity documents in bulk. Brian Krebs broke the story on 2 September after finding his own driving licence in the database.

Krebs said the catalogue held:

153M

US and Canadian driving licences.

10M

Identity cards.

3M

Travel documents and international IDs.

579k

Medical cards, including dispensary cards.

Around 1.1 million of the licences are Canadian, so the exposure is overwhelmingly American. Set against roughly 241 million licensed drivers in the United States, records on that scale would cover well over half the country’s drivers, although how many of them are distinct people has not been verified. The seller claimed the data covered more than 170 million people. Crucially, these were not text records. They were image files: up to six per licence, including the front, back, infrared and ultraviolet scans, each with a date and timestamp appended.

We have been continuously exfiltrating new data for over a year into our private database. Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.

Krebs and researcher Zach Edwards traced the likely source to IDScan.net, a Louisiana-based identity verification firm. The document timestamps lined up with Hertz car rental pickups and visits to Planet13 dispensaries, an IDScan partner. The FBI’s New Orleans field office has opened an investigation. The criminals even advertised the driving licence of the US Defense Secretary, Pete Hegseth.

Why leaked documents pose such a threat

Once these documents are breached, they are exposed forever. 153 million people are not going to get new licences. A few US states might reissue a licence number after proven identity theft, but that is a slow, narrow process that effectively covers nobody. A new number would not help anyway, because what leaked is the face, the name, the date of birth and the signature.

Having the full image files makes this far more dangerous than a standard data leak. Social media already supplies a person’s face and voice in public. A stolen document supplies the rest. A remote identity check asks for two things, a document and a face, and an attacker now has both.

Firms are adding document checks to defend against deepfakes. This breach is what makes those checks easier to beat. When a document alone stops being enough, the ID verification industry’s answer is liveness checks. That means their final fallback is detection: a defence that must continually hold the line against every new AI model released.

It’s not the first time

This has happened before. A look at recent history shows this is a recurring problem.

Incident What was exposed What happened next
AU10TIX, June 2024 Credentials to a logging platform linking to uploaded identity documents, names, dates of birth and ID numbers, for TikTok, Uber and X Harvested by malware in December 2022, posted to Telegram in March 2023, still live when a researcher found it 18 months on
Discord, October 2025 Roughly 70,000 government ID photos through its support vendor 5CA, submitted for age verification appeals. Attackers claimed 2.1 million Mandatory age verification rolled out anyway, four months later
The Tea app, 2025 Verification selfies, left in an open storage bucket Posted to 4chan
IDScan.net, 2026 153 million driving licences, with the infrared and ultraviolet scans attached FBI investigation opened

Research from Mysterium VPN counted 88 incidents from 2011 to August 2026 in which identity verification data was breached, exposed or sold, with 42% of those occurring since January 2024 alone.

The UK context

There are no British documents reported in the IDScan data, which is heavily US and Canadian. But the UK is enforcing the exact same model.

Since the Online Safety Act took effect in July 2025, highly effective age checks have become a requirement. In practice, this means ID uploads and face scans. The Age Verification Providers Association told the government this produced an extra five million age checks a day in the UK. Retention periods are set by each provider, commonly ranging from seven to thirty days, with no uniform standard. Every single point in that process is a place a document can leak from.


Drawing the line on collection

Government ID verification remains an essential part of KYC and regulated onboarding processes, at least until digital identity solutions, like those currently being developed and rolled out in Europe, are adopted more broadly. UK firms still have a legal duty to perform documentary identity checks under the Money Laundering Regulations, and that obligation is not going away.

The danger lies in over-reliance. We should not be leaning on government ID for every routine identity confirmation, because doing so inevitably leads to more copies being stored and a far higher risk of a breach.

Think about the IT help desk asking an employee to send a licence photo to reset a password, or a wealth manager asking for ID again before acting on a change of bank details. None of these routine interactions between people and firms that already know each other actually need a document. Yet, all of them create a copy. Every copy stays stored on a system until a breach occurs.

When a client needs to re-prove their identity, a challenge sent directly to the real person on their own registered phone confirms it in seconds. It relies on a human-to-human layer, and it leaves no documents behind.