Federal investigators are examining reports that scans of millions of American identity documents may have been exposed through a company that verifies IDs for businesses, Bloomberg News reported after a bureau spokesperson confirmed the inquiry.
The warning arrived as an underground service calling itself Nexus advertised access to a vast collection of North American driver’s-license images on a Russian-language cybercrime forum known as Exploit.
According to that advertisement, cited by Bloomberg, buyers were being offered more than 160 million “North American” driver’s licenses, with a separate line promoting “160M+ USA DL/ID Scans + data.”
If those figures are even roughly accurate, the incident would rank among the largest exposures of government-issued identity documents in the United States and Canada.
Unlike a typical account-credential dump, the material at issue is not a password that can be changed overnight.
It is a digital copy of a physical card: a face photograph, address, date of birth, license number, and, in many reported samples from later coverage of the same marketplace, additional imaging used to check whether a card is genuine.
That combination is what makes the case more than a routine data leak.
Driver’s licenses remain the default key for opening bank accounts, renting cars, proving age, completing know-your-customer checks at financial platforms, and authorizing transfers.
A high-quality scan of a real license can be reused to impersonate the person named on it.
When infrared or ultraviolet captures travel with those scans, as later technical reporting on Nexus described, criminals may also obtain the hidden marks that verification software treats as proof a document is authentic.
In that scenario, fraudsters are not merely copying a photo; they are inheriting the blueprint that institutions use to accept the photo as legitimate.
Bloomberg’s account is careful about what is proven.
The FBI confirmed it is looking into a possible breach at an ID-verification firm and the possible exposure of millions of American licenses.
It did not, in that report, name the company, confirm the 160-million figure, or say how long any intrusion lasted.
Separate reporting elsewhere has pointed toward a New Orleans-based vendor used at rental counters, retail checkouts, hotels, and other high-volume locations, and has said the Nexus listing also claimed millions of other ID cards, travel documents, and medical cards.
Those details remain under investigation.
The marketplace itself later vanished from public view, which does not mean copies of the files disappeared with it.
The practical risk for the public is uneven but serious. People whose licenses were scanned at an ordinary business transaction may have no idea the image was stored, let alone copied.
Victims cannot simply request a new “password” for their identity.
A new license number helps only so much when the old photograph, address history, and document features are already circulating.
The same records can support synthetic identities, fraudulent accounts, and social-engineering attacks that look more convincing because they rest on real personal data.
There is also a physical-safety concern for anyone trying to keep an address private.
For companies that outsource ID checks, the episode is a reminder that third-party vendors can concentrate enormous amounts of sensitive imagery in one place.
For regulators and banks, it raises a harder question: whether a scanned government ID, standing alone, should still be treated as sufficient proof of who someone is. Until the FBI’s investigation produces a fuller accounting, the safest assumption is that any license captured by a commercial scanner could now exist outside the system that was supposed to protect it.