FBI Investigates Alleged Leak of 153 Million Driver's License Records
If the claimed dataset is authentic, it would represent one of the largest exposures of state-issued identity documents in U.S. History, with direct implications for federal data-security policy...
The Federal Bureau of Investigation has confirmed it is actively investigating a claim by a dark web marketplace called Nexus that it holds more than 153 million driver's license scans, according to a report published by Fox News. The FBI confirmation was the first official government acknowledgment of the alleged breach as of the date of this report.
Driver's licenses are issued by individual state motor vehicle agencies, not a single federal database. That jurisdictional structure means that if the Nexus claim is accurate, records from multiple states would have to have been aggregated, either through a centralized third-party vendor, a multistate data-sharing arrangement, or individual breaches compiled over time. Which of those pathways applies is not yet publicly known.
The United States had approximately 235 million licensed drivers as of the most recent Federal Highway Administration count, published in the agency's annual Highway Statistics report for 2023. A dataset of 153 million records, if verified, would represent roughly 65 percent of all licensed drivers in the country.
The FBI has not publicly named suspects, confirmed the authenticity of the data, or identified which states or vendors may be involved. A spokesperson for the bureau did not respond to a request for additional comment by publication time. The document that would clarify the scope of any breach is a formal notification to affected state agencies, which would be required under most state data-breach notification laws once a breach is confirmed.
Congress has considered federal data-breach notification legislation in multiple sessions. The American Data Privacy and Protection Act, which passed the House Energy and Commerce Committee in July 2022 (Committee Report 117-669), included provisions that would have established a national breach-notification standard, preempting the current patchwork of 50 state laws. That bill did not receive a floor vote in either the 117th or 118th Congress. No comparable bill has been enacted as of the date of this report.
Dark web marketplaces routinely post claims of data for sale that prove to be exaggerated, duplicated from prior breaches, or fabricated entirely. The FBI's decision to open an investigation does not by itself confirm that a new breach occurred. Investigators have not publicly released any technical analysis of the Nexus dataset.
If driver's license images were exposed, the harm to affected individuals would extend beyond name and address. A scanned license typically includes a photograph, date of birth, physical descriptors, license number, and in many states a digital barcode encoding additional personal data. Security researchers have noted that such records are used in identity-document verification systems by financial institutions, employers, and government agencies. The Federal Trade Commission's identity theft data, published in its Consumer Sentinel Network report for 2024, recorded 1.1 million identity theft complaints nationwide in that year.
The Department of Homeland Security maintains the REAL ID program, which sets federal standards for state-issued licenses used for federal purposes such as boarding commercial aircraft. DHS has not issued a public statement regarding the alleged Nexus dataset. Any compromise of REAL ID-compliant documents could have implications for the program's integrity, though whether the alleged records meet REAL ID standards is unknown.
At the state level, motor vehicle agencies in most jurisdictions contract with private vendors for data processing, image storage, and license production. The names and contract values for those vendors are public records in most states under procurement disclosure rules. Which vendor, if any, may be the point of compromise has not been identified in any public filing or statement as of this report.
Several questions remain unanswered by available public records. First, the FBI has not confirmed whether the Nexus data is authentic or duplicated from prior breaches. Second, no state motor vehicle agency has issued a formal breach notification. Third, it is unknown whether the data originated from a state agency directly, a contracted vendor, or a federal program such as REAL ID. The documents that would answer these questions are the FBI's investigative findings once disclosed, any state breach notifications filed under applicable law, and federal procurement records identifying vendors with access to large volumes of license-image data.