153 Million Driver's Licenses for Sale — Is Yours One of Them?
Monday, September 7, 2026 · 5-minute read
A new identity theft service called Nexus appeared on a Russian cybercrime forum this week, selling digital scans of more than 153 million US and Canadian driver's licenses. The data appears to come from an ongoing breach at a major identity verification company — one whose customers include multiple Fortune 500 companies. The FBI's New Orleans field office has opened an official investigation, and the stolen records keep growing: nearly 400,000 new licenses were added in a single 24-hour window, suggesting the breach is still active.
↗ Krebs on SecurityA group tracked as PREY-0058 is running a sophisticated scam targeting corporate executives — directors, VPs, and senior staff. The attackers call victims on the phone, impersonate IT help desk workers, and trick them into handing over access to their Microsoft 365 accounts. Once inside, they steal data and then extort the company, threatening to publish it. The same group is linked to data extortion operations known as Cinder and Pink.
↗ The Hacker NewsMathspace, an online math learning platform used in schools, disclosed a breach affecting more than one million people over the weekend. Attackers got in through the company's internal reporting system — a tool called Metabase — and stole data on students, parents, and staff. If your child's school uses Mathspace, watch for any suspicious emails or account activity tied to the email address you used to register.
↗ BleepingComputerTwo separate attack campaigns are hitting Microsoft 365 users right now. The first — PREY-0058 — calls executives directly, poses as IT support, and walks them into approving a session token hand-off, bypassing MFA entirely. The second — a phishing-as-a-service platform called BigBear 2.0 — has already stolen more than 5,000 Microsoft 365 passwords from 258 organizations, also bypassing MFA. Both attacks work because they steal the login session after MFA has already been passed, so turning on MFA alone is no longer enough.
Attackers are chaining two newly disclosed vulnerabilities in MikroTik RouterOS to take full control of routers that have their SSH service exposed to the internet. Once a router is compromised, attackers can intercept traffic, redirect users to fake websites, or use the device as a launching pad for other attacks. MikroTik devices are common in small businesses, apartment buildings, and internet service providers.
N-able's N-central platform — software that IT teams use to remotely monitor and manage computers — has two critical flaws being actively attacked right now. An outsider with no login credentials can completely bypass the authentication system and gain full control of the platform. That's a big deal because N-central itself has admin-level access to every computer it manages. Think of it like a master key: steal it, and you can walk into every room in the building.
Status: Emergency hotfix released. If your IT provider uses N-central, ask them to confirm they've applied it immediately.
Citrix NetScaler is used by thousands of businesses to control who can log into their internal networks remotely. A critical authentication bypass flaw in NetScaler is now being actively exploited in the wild — meaning attackers are already using it, not just experimenting with it. Someone who exploits this can walk past the login gate entirely and access corporate systems as if they were an authenticated employee.
Status: Patch available. If your organization uses Citrix NetScaler, escalate this to your IT or security team today — active exploitation is confirmed.
Google has warned of a new zero-day vulnerability in Chrome that is already being used in real attacks. The details of exactly what the flaw allows attackers to do are limited, but Google has confirmed exploitation in the wild, which puts everyone who hasn't updated Chrome at risk just from visiting a malicious website.
Status: Patch available. Open Chrome, click the three-dot menu in the top right, go to Help → About Google Chrome, and let it update. Then restart the browser.
Security researchers at BleepingComputer have documented a new phishing technique called ASCII smuggling that uses invisible Unicode characters to hide malicious content from email security filters. The characters are technically invisible to scanners but still get interpreted by your email app — meaning a link that looks harmless passes security checks and then shows you something different when you click it. In a related twist, attackers are also now building fake QR codes out of plain text characters so that blocking email images doesn't stop the scam from appearing. Both techniques are active in the wild right now and represent a meaningful step forward for attackers trying to sneak past corporate email defenses.
A new dark web service called Nexus is selling high-quality scans of more than 153 million North American driver's licenses — complete with front, back, infrared, and ultraviolet images. That's nearly half the adult population of the United States. The records are priced for individual purchase, organized by state, and come with timestamps. And according to the people behind Nexus, they've been quietly siphoning fresh data for over a year.
The source of the breach appears to be a major identity verification company based in Louisiana. Journalist Brian Krebs investigated by searching for his own license and those of family and friends — nine out of the dozen he checked were in the database. The timestamps attached to each license matched the exact date each person had shown their ID somewhere. Cross-referencing those dates with travel records and car rental receipts pointed to a single common thread: Hertz car rental locations. When people showed their license to rent a car, that image was captured and eventually found its way into this criminal database.
This matters for a few reasons beyond the sheer scale. First, the breach is still live — records are being added daily, which means the source hasn't been shut down. Second, these aren't just names and email addresses. They're high-resolution government ID scans, the same kind of document used to open bank accounts, verify age, apply for loans, and pass identity checks on dozens of platforms. A criminal with your license image has a powerful tool for identity fraud. Third, the records include some remarkably sensitive people — Krebs found the driver's license of a sitting US cabinet secretary in the database.
For now, the FBI is investigating, and IDScan — the Louisiana identity verification company widely suspected as the source — faces multiple lawsuits. Watch for official notices from car rental companies or identity verification services you've used. In the meantime, consider placing a free credit freeze at all three major bureaus (Equifax, Experian, TransUnion) — it costs nothing and makes it significantly harder for someone to open new accounts using your identity.