153 Million Driver's Licenses Went Up for Sale. What Credit Unions and Community Banks Should Do.
What happened
On August 31, a new seller on the Russian-language cybercrime forum Exploit began advertising Nexus, a searchable service offering identity documents on more than 170 million people in North America. Brian Krebs published his investigation on September 1.
- The inventory: 153 million-plus U.S. and Canadian driver's licenses, 10 million-plus state ID cards, 3 million-plus travel documents, 579,000-plus medical cards.
- Not just data fields. Each record held front-and-back images plus infrared and ultraviolet versions of the document, timestamped.
- The source. Krebs matched timestamps with nine people whose licenses appeared. The common thread was rental car counters and a cannabis dispensary, all served by IDScan.net, a New Orleans identity verification vendor that reports 21 million-plus verifications monthly at 20,000-plus locations.
- It was live. Nexus claimed a year of continuous exfiltration, and the license count grew by roughly 400,000 during the 24 hours Krebs spent reporting.
- Where it stands. The FBI's New Orleans field office opened an investigation September 1. Nexus went dark hours after publication, which changes nothing about data already sold. IDScan.net says data "may have been accessed without authorization" and calls it a potential security incident pending third-party forensics; it has not confirmed a breach or a count. Several proposed class actions were filed in the Eastern District of Louisiana.
- No lookup tool exists. Any site offering to check whether your license was included is a scam. Tell your members before someone else tells them otherwise.
Why this is not a card breach
A card number has a shelf life. A driver's license does not.
What is for sale is the artifact, not the data. Each record is the license itself, captured as images: a color scan of the front and back, plus infrared and ultraviolet captures of the same card. On the face of them sits everything a license carries — full legal name, address, date of birth, license number, issue and expiration dates, height and eye color, signature and photograph.
The infrared and ultraviolet layers are the part that should worry anyone who authenticates documents. States embed security features into licenses that appear only under those wavelengths, precisely because they are hard to reproduce, and verification systems check exactly those layers to tell a genuine card from a forgery. So what is for sale is not just the data on the license. It is the proof that the license is real.
Finally, the exposed population did not self-select by financial behavior. It is anyone who rented a car, checked into a hotel or bought legal cannabis. For an institution of any size, that is a real share of your membership, and there is no list.
Where you will see it
- Digital account opening. Flows built on an uploaded license plus a selfie now face applicants with a genuine document. Liveness becomes the only real barrier, and tooling to defeat it is cheap.
- Synthetic identity. Real license images give fraudsters a verifiable anchor for fabricated or blended identities, feeding bust-out lending and mule account creation.
- Indirect and auto lending. Document-driven by design, with ID capture happening at a dealer site outside your controls.
- Servicing and ATO. A license image is the common step-up for address changes, card reissue, online banking re-enrollment and wallet provisioning. That is the shortest path from stolen identity to card fraud on your books.
- Member-facing scams. Breach headlines are dependable pretext. Expect imposter calls citing this breach and asking members to verify identity or move money to safety.
- Third-party risk files. Even with no vendor relationship, this is now a case study your examiners are reading too.
What to do
This week
- Inventory every point where you capture or accept a government ID image. Digital onboarding, branch and teller scanners, loan origination, indirect lending partners, ITMs and kiosks, wire and safe deposit procedures, and any fintech or CUSO partner acting on your behalf. Include your vendors' subprocessors, which is where the surprises are.
- Put written questions to every IDV vendor and to your core and digital banking partners. Get answers in writing for the vendor file:
- Do you use IDScan.net, VeriScan or DIVE at any layer, directly or through a subprocessor?
- Do you retain raw ID images, including infrared and ultraviolet captures? For how long, and why?
- Is that data encrypted at rest, and who internally can access it?
- Can you detect a re-presented genuine image, as distinct from a forged document? This is the question this incident actually raises.
- What changed in your retention or detection posture after September 1?
- How fast will you notify us of a suspected incident involving our members' data?
- Brief the contact center and branches, and update scripts. They need a plain answer for members asking if they are affected, and a heightened alert for imposters using the breach as cover.
Within 30 days
- Stop letting a clean document check stand as proof of identity. Require at least one signal that cannot be lifted from a license: device reputation and history, phone number tenure and SIM-swap or port-out signals, email age, an out-of-band callback to the number of record, or bureau-based verification. Any one of these now outweighs a document that scans perfectly.
- Re-tune digital account opening and add a monitored watch period. These accounts look clean on paper; the signal is behavioral and arrives later. Watch the first 30 to 90 days for no payroll deposit, immediate wallet provisioning, rapid ACH or RTP outflow, small trial funding then a large pull, and address changes soon after opening.
- Harden step-up on high-risk servicing events, with velocity and cooling-off rules. The combinations that matter: address change followed by card reissue, reissue to a newly added address, wallet provisioning after a phone change, re-enrollment from an unrecognized device.
- Review synthetic identity detection specifically. Look for the same license number or image across multiple applications, document data matching a real person while contact data does not, and thin or new credit files paired with a valid-looking license.
- Update the CIP and KYC risk assessment and document the decisions. Record the inventory, vendor responses and control changes. Where you find actual misuse, consider SAR filing under identity theft or synthetic identity typologies.
Ongoing
- Treat compromised document images as a standing assumption, not an incident to close. This dataset took a year to build quietly. Assume others exist and have not surfaced.
- Share what you see. An identity tried against you is being tried against institutions like you within days. FinCEN 314(b) lets participating institutions share fraud information with each other; if you are not registered, it is a low-cost filing worth doing.
- Watch for formal notification. Louisiana law generally requires notice to affected residents within 60 days of discovery. If notices land this fall, staff the phones.
What to tell members
- No legitimate site checks whether your license was included. Any link offering to is a scam.
- Freeze credit at Equifax, Experian and TransUnion, and consider the specialty bureaus used in deposit account opening.
- Turn on account and card alerts, and read them.
- We will never call and ask you to read back a code, confirm your license number, or move money to keep it safe. Hang up and call the number on your card.
- For actual misuse, start at IdentityTheft.gov. That report is also what most states require before considering a new license number.
Where Rippleshot may help
If your question is about your IDV stack, the questionnaire above is the more useful part of this briefing. Where we are relevant is after a stolen identity is put to work.
- Fraud Intelligence Collective. Cross-institutional fraud intelligence anchored in the FinCEN 314(b) framework, so patterns hitting one institution surface for peers instead of being relearned one loss at a time. When the same identities will be tried against hundreds of institutions, that view beats any single institution's own data.
- Fraud Interceptor. Card fraud detection that runs outside the institution with no integration, at the transaction layer where a fraudulently opened or taken-over account finally produces a loss.
- Scam Defender. For the member-facing scam wave that reliably follows coverage like this.
Happy to talk with any community institution, customer or not.
Sources: KrebsOnSecurity, "FBI Probes Service Selling 153M+ Drivers Licenses," September 1, 2026, plus subsequent reporting on the FBI inquiry, IDScan.net's statements and Eastern District of Louisiana filings. Developing story; details may have changed. This briefing is general information, not legal or compliance advice.
Let's Talk
You have fraud frustrations? We have the solutions. Let's discuss what you are dealing with and we can learn more and share how we can help.




%20(3).png)
