So Do We KNOW Which Identity Verification Company Was Hacked to Give Nexus the 153 Million Driver’s Licenses?

No, we don’t really KNOW yet.

If you missed the story about the 153-plus million Driver’s licenses on the dark web, see my post from yesterday.

Bredemarket blog, September 3, 2026.

Specifically:

“The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.”

Of course, the Nexus hackers may be lying to misdirect anti-fraudsters and cover their tracks. Fraudsters are not trustworthy people.

But if the Nexus hackers are telling the truth about the source of the hacked driver’s license data, some identity verification company is going to be in very big trouble.

Now some of you are saying, “But John…we KNOW who the identity verification company is!”

  • Yes, I know that the Krebs on Security article stated that some of the hacked ID cards were for marijuana dispensaries, and that a particular named ID verification company does business with marijuana dispensaries.
  • And that some of the hacked data appears to have been from car rental agencies, and this same ID verification company does business with a very large car rental agency.
  • And the FBI opened an investigation in its office where this ID verification company happens to be headquartered.

So how come I’m not naming the company now?

Two words: Richard Jewell.

Richard Jewell, hero turned suspect turned hero.

He was falsely accused of the Atlanta Olympics bombing in 1996.

By August 2007 he was dead from complications from diabetes; he was only 44. His mother, who was caught in the same negative press onslaught, outlived him by over a decade.

So I’m waiting for more definitive information. Smoke isn’t enough.

Leave a Comment