A clandestine service operating on the dark web has emerged, peddling digital scans of an astonishing trove exceeding 153 million driver’s licenses belonging to individuals in the United States and Canada. Preliminary investigations, including interviews with individuals whose licenses are listed for sale, strongly suggest that this operation is systematically pilfering images acquired by a prominent identity verification company headquartered in Louisiana. In response to these alarming revelations, the New Orleans field office of the Federal Bureau of Investigation (FBI) has officially launched an inquiry into the origins of this compromised data.

The exposé began on Monday, August 31st, when a source brought to the attention of KrebsOnSecurity a new user on the Russian cybercrime forum "Exploit." This user was advertising access to a vast database of identity documents, claiming to encompass over 170 million individuals across North America. The source’s concern was amplified when the proprietor of this identity theft service offered the source’s own Virginia driver’s license as a complimentary sample within their initial sales thread on Exploit, underscoring the alarming accessibility of such sensitive information.

The illicit service, operating under the moniker "Nexus," boldly claims to possess more than 153 million driver’s licenses from both the United States and Canada. Beyond this staggering number, Nexus also purports to offer over 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards. A cursory examination of the Nexus platform appears to corroborate the claim regarding the sheer volume of driver’s license records. An unparameterized search within Nexus yields approximately 11.5 million pages of results, with each page displaying around 15 entries. This comprehensive collection includes documents from individuals in both Canada and the United States, though the overwhelming majority of these records pertain to Americans. A focused search for Canadian driver’s licenses alone returns approximately 1.1 million results, with the most significant concentration originating from Ontario, numbering 473,673 records.

Intriguingly, the identity records available through Nexus extend beyond driver’s licenses to include marijuana dispensary cards. Some records cryptically denote their "source" as "CDL," a likely abbreviation for "commercial driver’s license." Other entries bear the notation "CAC," which may refer to Common Access Cards, government-issued identification cards essential for physical access to federal buildings and secure areas. The architects behind Nexus assert that the source of these compromised license images stems from an ongoing breach at "a major identity verification company" whose clientele includes numerous Fortune 500 corporations.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The Nexus service boasts about its continuous data exfiltration efforts, stating in its introductory post on Exploit, "We have been continuously exfiltrating new data for over a year into our private database. Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." This assertion is supported by the observable increase in available driver’s license records within Nexus. Over a mere 24-hour period, the number of listed records surged by nearly 400,000, a stark indicator that freshly pilfered license data is being actively harvested and uploaded to the service on a near-constant basis.

The record containing KrebsOnSecurity’s own driver’s license exemplifies the depth of compromise. It includes six image files: three pairs of front and back scans, along with infrared and ultraviolet renditions of the same images. Each image file is appended with a date and timestamp. The timestamp on this particular scan corresponds to June 2025, a period during which KrebsOnSecurity traveled to the midwestern United States for a family funeral.

Driven by a desire to pinpoint the source of this compromised data, KrebsOnSecurity solicited permission from over a dozen friends and family members to search for their licenses on the Nexus service. Each individual whose license was found (nine in total) confirmed having traveled on or around the dates indicated by the timestamps attached to their respective images. While the precise timezone of these timestamps remains unclear, an analysis of car rental records shared by several research participants suggests the timezone is set to Greenwich Mean Time (GMT).

Initially, the hypothesis centered on airports as a potential nexus of data collection. However, this theory was quickly disproven when it became evident that passports were absent from the dataset. Furthermore, only a subset of those who assisted with the research recalled presenting their driver’s license at airport security on their travel days. One individual whose license was found in Nexus had not flown recently but had been renting a car from Hertz for several months around the date of their timestamp.

Two federal employees who participated in the research stated that while they presented other forms of government identification at airport security, they subsequently handed over their state-issued driver’s licenses later that day for vehicle rentals. Both of these individuals confirmed that they rented their cars from Hertz. Recalling a calendar reminder on the day of the June 2025 flight to bring a passport, KrebsOnSecurity remembered not actually presenting a driver’s license at Reagan National Airport security. This was due to not yet possessing a Real ID, a security-enhanced license now mandated by the Transportation Security Administration (TSA) for all domestic travel. Instead, a U.S. passport was presented to the TSA agent.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The investigation took a more compelling turn when KrebsOnSecurity discovered their mother’s driver’s license within the Nexus service. The timestamps associated with her images were mere seconds apart from those of KrebsOnSecurity’s own license. This proximity is significant, as both individuals handed their licenses to the Hertz rental car representative simultaneously. According to the mother, the only entity that received her driver’s license that day was the rental car company, a recollection that aligns with KrebsOnSecurity’s own. While the act of the rental car representative inserting the licenses into a machine is not definitively recalled, the representative did hold onto them for several minutes behind the counter while forms were being signed. KrebsOnSecurity reached out to Hertz for comment and will update this story should a response be provided.

Zach Edwards, a respected security and privacy researcher who recently launched DecryptAds to help individuals understand online tracking, also found his driver’s license available for purchase on Nexus. Edwards confirmed that the timestamp on his record aligns with his recent trip to Las Vegas for the annual DEF CON security conference. Although Edwards did not rent a car in Vegas, he did present his license at the TSA checkpoint, a marijuana dispensary, and his hotel (the Aria). He noted that the dispensary was the only one of these locations that definitively scanned his ID using some form of device.

The dispensary in question was Planet13, a multi-state chain with locations in California, Florida, Illinois, and Nevada. In 2022, the New Orleans-based identity provider idscan.net published a press release announcing an exclusive identity verification agreement with Planet13 dispensaries nationwide. IDScan states that it processes ID verification for over 1,000 marijuana dispensaries across 19 U.S. states. The "trust" page of idscan.net lists numerous prominent brands as clients, including Hertz, Target, Fedex, Motorola Solutions, financial services giant Jack Henry, and Caesars Entertainment. Furthermore, idscan.net’s own documentation indicates that its technology scans IDs using both infrared and ultraviolet light, a capability that aligns with the multiple image formats found in the Nexus data. IDScan.net reports that its systems perform over 21 million verifications monthly across more than 20,000 locations globally.

When contacted by KrebsOnSecurity, idscan.net stated it was investigating the matter but had not yet provided an official statement or detailed responses to specific inquiries. Jillian Kossman, a marketing and operations leader at idscan.net, acknowledged the updates provided, stating, "At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation."

As research for this story progressed, word of KrebsOnSecurity’s investigation into the apparent source of Nexus’s data reached the FBI. This likely occurred when KrebsOnSecurity shared with a trusted source that Nexus was also selling the driver’s license information of the Assistant Director of the FBI (though the license of FBI Director Kash Patel was not found). Earlier this afternoon, KrebsOnSecurity was included in a conference call with several FBI agents, including senior leaders from the agency’s cyber division. During this call, the FBI confirmed that its New Orleans field office had initiated a formal investigation into a suspected breach involving idscan.net.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Edwards emphasized that as more in-person and online interactions necessitate the sharing of driver’s licenses, vendors collecting this sensitive data must be held to a higher standard. He remarked, "This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids. These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe."

Larry Baldwin, principal intelligence researcher at the cybersecurity firm Cybera, also found his driver’s license available on Nexus. The front and back scans included timestamps corresponding to a recent car rental from Hertz during a vacation. Baldwin highlighted the significant security and privacy risks posed by the Nexus service. He noted that state-issued driver’s licenses are commonly used to establish credit lines and that the service could endanger individuals seeking to remain anonymous, including those fleeing domestic violence or individuals in the federal witness protection program. Baldwin lamented, "Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised."

Update, September 8: IDScan.net published a brief notice confirming that it "has determined that an unauthorized third party may have access and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers." The statement indicated that IDScan.net is notifying affected individuals and offering credit protection services.

Update, September 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment clarified that Caesars has not been a client of IDScan.net and has not utilized VeriScan since February 2025, despite IDScan.net listing them as a client. The spokesperson stated that Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, adding that IDScan.net indicated the incident should have no impact on Caesars Entertainment.

Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the dark web. Its login page was replaced with a simple text message stating, "This service is no longer available."

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp.