A dark-web service called Nexus reportedly offered access to more than 153 million driver’s-license records from people across the United States and Canada, raising fresh questions about what happens to sensitive identity documents after organizations collect them.

The 153 million figure comes from claims made by the operators of Nexus and has not been independently verified as the number of people affected. The FBI’s New Orleans office has confirmed that it is looking into the incident, while the exact source and scope of the data remain under investigation.

The concern extends beyond the size of the reported dataset. According to reporting on the incident, many available files reportedly included front-and-back images of identification cards, while some records also contained barcode information, ultraviolet images, and infrared captures.

For businesses that routinely collect identification documents, the story raises an important question:

Once the original reason for collecting a sensitive document has passed, why is the organization still retaining it?

What Do Businesses Need to Know About the Nexus ID Scan Report?

Nexus appeared on a Russian-language cybercrime forum advertising access to a large collection of identity documents.

According to investigative reporting by Brian Krebs on KrebsOnSecurity, the service claimed to hold more than 153 million driver’s-license records, more than 10 million identification-card records, more than 3 million travel and international documents, and at least 579,000 medical-card records.

Those numbers should be treated carefully. They are claims associated with the Nexus service, not a confirmed count of affected individuals.

Additional reporting found that the service claimed continuing access to a major identity-verification company and its customers. However, investigators have not publicly confirmed the complete source of the data, and the company referenced in reporting has not confirmed unauthorized access involving its systems.

The FBI has confirmed only that it is examining the incident and has declined to provide further details while the investigation remains ongoing.

Why Does This Matter for Sensitive Document Retention?

Businesses often have legitimate reasons to collect driver’s licenses and other government-issued identification.

These documents may be used for identity verification, employment processes, financial transactions, customer onboarding, rental activity, regulated processes, or other operational requirements.

But collecting a sensitive document and retaining it indefinitely are two different decisions.

Every sensitive document that remains in storage continues to create responsibilities around protection, access, retention, and eventual disposition.

The issue is therefore not simply whether an organization can secure a document today.

It is also whether the organization can explain why it still has that document tomorrow.

Which Businesses Face the Highest Retention Risk?

The issue is particularly relevant to organizations that routinely collect copies of government-issued IDs or other highly sensitive documents as part of everyday operations.

That can include employers handling identification during onboarding, financial-services businesses performing identity verification, property and rental businesses collecting customer IDs, healthcare organizations handling identification alongside sensitive records, and other businesses that verify customers or employees using scanned documents.

The level of risk does not depend only on how many documents an organization collects.

It also depends on how sensitive those documents are, how broadly they can be accessed, how long they remain stored, and whether there is a defined reason for continuing to retain them.

A small organization holding a limited number of highly sensitive documents without clear access or retention controls can still face significant information-governance risk.

What Should a Sensitive Document Retention Policy Cover?

A useful retention policy should help an organization answer several basic questions for every category of sensitive document.

Why was the document collected?
There should be a defined legal, regulatory, contractual, operational, or legitimate business reason for retaining it.

Where is the document stored?
Organizations should know where sensitive documents reside rather than allowing copies to accumulate unnoticed across inboxes, shared folders, employee devices, or disconnected repositories.

Who can access it?
Access should reflect actual job responsibilities and business requirements rather than simply being available to everyone who can reach a folder or system.

How long should it remain?
Retention periods should reflect applicable legal, regulatory, contractual, and operational requirements.

What happens when the retention period ends?
Organizations should have a defined review and disposition process rather than allowing sensitive records to remain indefinitely because storage is available.

Does Better Retention Mean Deleting Old Documents Immediately?

The lesson from this incident is not that businesses should automatically delete every old document.

Certain records may need to be retained because of legal requirements, regulatory obligations, contractual commitments, litigation holds, audits, or legitimate operational needs.

The more useful principle is:

Retain sensitive documents for as long as there is a legitimate requirement to keep them — and have a defined process for what happens when that requirement ends.

That is the difference between a structured retention strategy and simply keeping everything forever.

Data minimization should also be applied carefully. Removing information without considering applicable obligations can create its own compliance and operational problems.

What Should Businesses Review Now?

Organizations that collect identification documents can use the current news as a reason to review their own practices.

A practical review should answer:

  • What categories of sensitive documents do we currently hold?
  • Why are we retaining each category?
  • Where are those records stored?
  • Who can access them today?
  • Are former employees, external users, or unnecessary roles still able to reach them?
  • What retention requirements apply?
  • Is there a defined review or disposition date?
  • Can we demonstrate what happened to a document during its lifecycle?

This type of review does not replace a broader cybersecurity, legal, privacy, or compliance program.

It is one part of responsible information governance.

How Can Document Management Support Sensitive Document Governance?

Document management can support this process by giving organizations greater visibility and control over sensitive records throughout their lifecycle.

A structured system can help businesses centralize records, limit access according to roles, maintain activity histories, retrieve documents efficiently, and apply retention processes more consistently.

Docupile supports capabilities including role-based access, audit trails, searchable document records, and retention management, helping organizations maintain clearer control over the documents they are responsible for.

The goal is not simply to store more information.

It is to know:

what you have, why you have it, who can access it, how long it should remain, and what should happen when it is no longer required.

Sensitive Document Retention Review

If your organization routinely handles customer, employee, or identity documents, use the Sensitive Document Retention Review to examine how those records are being managed.

The review can help your team document:

  • the type of sensitive record,
  • why it is retained,
  • where it is stored,
  • who owns or manages it,
  • what retention requirement applies,
  • and when it should be reviewed or disposed of.

Sources

KrebsOnSecurity — Primary investigative reporting
FBI Probes Service Selling 153M+ Drivers Licenses
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/

FreightWaves — Supporting reporting and FBI confirmation
FBI investigating dark-web service claiming 153M license records, raising CDL security concerns
https://www.freightwaves.com/news/fbi-investigating-dark-web-service-claiming-153m-license-records-raising-cdl-security-concerns

Editor’s note: The investigation remains ongoing. The figures associated with Nexus are claims made by the service and should not be interpreted as a confirmed number of affected individuals.

At a Glance

Discover Docupile in 15 minutes — Book Your Demo Now!

Join to newsletter.

100% No Spam. We won’t share your email.

Get a personal consultation.

Call us today at (281) 942-4545

Smart Document Management System