HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Breach

Dark‑Web Marketplace Sells 153M+ U.S. & Canadian Driver’s Licenses After Identity‑Verification Breach

A new dark‑web service, Nexus, is offering scans of over 153 million driver’s licenses harvested from a major identity‑verification provider. The breach highlights the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor controls.

Verisq™ Intelligence · 📅 September 02, 2026 · 📰 krebsonsecurity.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
krebsonsecurity.com

FBI Probes Service Selling 153M+ Drivers Licenses

What Happened – A dark‑web marketplace called “Nexus” is offering digital scans of more than 153 million U.S. and Canadian driver’s licenses, plus other government‑issued IDs. The data appears to have been harvested from a widely‑used identity‑verification provider, prompting an FBI New Orleans field office investigation.

Why It Matters for Trust & Control Assurance

  • The incident is a textbook example of a third‑party data breach that defeats any organization that relies on that verification service without continuous oversight.
  • Continuous control‑assurance programs require documented vendor‑risk assessments, ongoing monitoring of third‑party security posture, and defensible evidence that data handling agreements are being honored.
  • Verisq’s Vendor Risk Management capability supplies the audit‑ready evidence stream needed to prove you’re actively managing and monitoring such suppliers.

Who Is Affected – Companies that integrate external identity‑verification APIs (financial services, SaaS platforms, e‑commerce, health‑tech, etc.).

Recommended Actions

  1. Initiate an urgent third‑party risk review of any identity‑verification provider you use; verify breach notifications and assess data‑handling controls.
  2. Collect and map evidence of vendor due‑diligence (contracts, security questionnaires, monitoring logs) to the relevant control objective in your audit framework.
  3. Update incident‑response playbooks to include a “third‑party breach” scenario and test the communication flow.

Technical Notes – The service claims the source is an “active breach” at a major verification company; records include driver’s licenses, commercial driver’s licenses, Common Access Cards, and medical cards. No specific CVE is cited; the vector is likely a compromised internal system or API used by the provider to collect and store scanned IDs. Source: Krebs on Security

📰 Original Source
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →