-
A cybercriminal listed a 195 million-record identity dataset on a dark web forum for $90,000, targeting US and Canadian individuals.
-
The dataset contains over 153 million driver’s license records, millions of ID cards, travel documents, and specialized government cards.
-
Security experts advise organizations and individuals to implement multi-factor authentication, monitor dark web activity, and freeze credit files.
A cybercriminal on an online forum states that he has a large database record of 195 million identities. Most of this data relates to the personal details of people living in the US and Canada.
The seller recently listed the complete archive for sale online after holding the stolen files for several years. Intelligence analysts continue monitoring the market advertisement while working to verify the overall authenticity of the compromised data.
Massive Identity Collection Listed for Underground Purchase
The advertised dataset contains an overwhelming volume of government-issued credentials and official identification records. Specifically, the listing includes over 153 million driver’s license files alongside more than 10 million state identification card records. Furthermore, the database contains roughly five million uncategorized identity files and nearly two million international travel document entries.
The dark web post also details specialized documentation gathered from various public and private institutions. The seller offers over 1.3 million international license files and more than 579,000 medical card records. Additionally, the collection holds over 429,000 common access cards, 91,000 residence cards, and 77,000 employment authorization files.
Security researchers trace a significant portion of the driver’s license records to the recently surfaced Nexus onion marketplace. Criminal actors frequently utilize these underground platforms to consolidate stolen records gathered from multiple enterprise intrusions over long periods.
Underground Price Drop Signals Urgency to Monetize Stolen Data
The threat actor initially offered the massive dataset for $120,000 on underground digital marketplaces. However, the seller recently dropped the asking price to $90,000 – a move to attract quick offers from prospective buyers. Such price cuts usually mean that the vendor wants to cash in on the fraudulent information before the information security teams disable the data.
On July 15, 2026, attackers stole about $23.75 million in USDC from Ostium by compromising its off-chain oracle system and manipulating BTC-USD price data. The stolen funds were converted to Ethereum and routed through Tornado Cash to obscure the trail.
Even though the price is quite high, independent experts have not verified all the details about the data yet. It is difficult to say if the records contain fresh breaches or are samples of old leaks that the criminal repackaged again. Cybersecurity reporting platforms such as KrebsOnSecurity routinely highlight how sellers exaggerate record counts on dark web forums to drive up prices.
Nevertheless, if genuine, the sheer volume of personal records presents immediate extortion risks for affected enterprise organizations. Criminal groups purchase these broad datasets to conduct secondary attacks, execute identity theft, and launch targeted phishing schemes. Consequently, security experts urge organizations named in the listing to audit external user access controls immediately.
Stolen Official Documents Enable Advanced Fraud Schemes
Exposing official government documents creates severe long-term security hazards for individuals and commercial enterprises alike. Physical identity cards, common access credentials, and driver’s licenses serve as primary trust anchors for remote authentication systems. Therefore, malicious actors acquiring these records can bypass automated identity verification checks used by financial institutions and retail portals.
Attackers use stolen medical cards and employment authorization details to execute sophisticated social engineering campaigns. Fraudsters are using real government identification numbers to persuade customer support representatives to change account passwords for clients. They can go even further, as possessing real Common Access Card information allows them to prepare very realistic scam emails targeting employees of companies.
In addition, criminals leverage international travel records and residence cards to establish fraudulent utility accounts or open illegal lines of credit. Unlike standard account passwords, individuals cannot easily change their driver’s license numbers or biological details. This has some negative consequences for victims whose identification cards have been posted on cybercrime websites, as they can suffer from fraud for years.
Critical Defensive Measures Against Large-Scale Data Exploitation
Organizations that collect personal information about customers must have strict access policies in place. This helps to reduce risks of data leaks brought about by third parties on the dark web.
Security managers must implement two-factor authentication systems for all gateways to prevent unauthorized logins using stolen passwords. Moreover, encrypting stored user records also makes it impossible for outsiders to read scanned documents, even if perimeter defenses break down.
Companies must also deploy continuous external threat monitoring tools to catch dark web listings that mention internal company domain names. Promptly discovering unauthorized data exports allows security staff to revoke compromised credentials before actors list the files publicly.
Individuals should freeze their credit reports with the top credit bureaus to avoid any fraudulent account opening with their details. Following the personal statements regarding finances and having instant transaction alerts helps clients detect illegal transactions in due time.
The implementation of preventive measures in terms of personal safety makes it possible to minimize the effects of huge compromised identities on sale on darknet markets.