The dark web has seen the emergence of a new, alarming identity theft service, "Nexus," which is reportedly offering digital scans of over 153 million drivers licenses belonging to individuals in the United States and Canada. This exposé by KrebsOnSecurity suggests a potential compromise of a widely-used identity verification company based in Louisiana, leading to an official inquiry launched by the New Orleans field office of the Federal Bureau of Investigation (FBI). The scope of the breach extends beyond drivers licenses, with Nexus also advertising over 10 million identification cards, more than three million travel documents, and nearly 600,000 medical cards.

The alarming scale of the data leak was first brought to light on Monday, August 31st, when a source alerted KrebsOnSecurity to a new user on the Russian cybercrime forum "Exploit." This user was advertising access to a vast repository of identity documents, claiming to possess data on over 170 million North Americans. The proprietor of this service even offered Krebs’s own Virginia driver’s license as a free sample, underscoring the immediate and personal threat posed by the leak.

A preliminary examination of the Nexus service revealed that its claims of over 153 million drivers licenses are likely not exaggerated. A broad, parameter-free search on the platform returned approximately 11.5 million pages of results, with roughly 15 records per page. This extensive collection includes documents from both Canada and the United States, with a significant majority pertaining to American citizens. A targeted search for Canadian driver’s licenses alone yielded approximately 1.1 million results, with Ontario showing the highest concentration at over 473,000 records.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Intriguingly, the data available through Nexus extends beyond simple driver’s licenses to include marijuana dispensary cards. Some records indicate "CDL" as the source, potentially referring to commercial driver’s licenses, while others bear the notation "CAC," which could signify Common Access Cards, government-issued identification for accessing secure facilities. The perpetrators behind Nexus assert that the license images are being siphoned from an active breach at "a major identity verification company" that serves numerous Fortune 500 clients.

The service proudly proclaimed on Exploit, "We have been continuously exfiltrating new data for over a year into our private database. Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." The rapid growth of the database further corroborates these claims; over a single 24-hour period, the number of listed driver’s license records increased by nearly 400,000, indicating a continuous and active harvesting of stolen data.

KrebsOnSecurity’s own driver’s license record within Nexus contained six image files: three pairs of front and back scans, along with infrared and ultraviolet versions of each. Each image file was appended with a date and timestamp, which for Krebs’s license, corresponded to a date in June 2025, aligning with a flight taken for a family funeral. This temporal correlation proved to be a crucial clue in tracing the origin of the compromised data.

To further investigate, KrebsOnSecurity reached out to over a dozen acquaintances and family members, requesting permission to search for their licenses on the Nexus service. Nine individuals who granted permission found their licenses available for purchase. Notably, each of these individuals confirmed having traveled or engaged in activities around the dates indicated in the timestamps associated with their scanned licenses. While the timezone of these timestamps was initially unclear, a review of car rental records shared by participants suggested Greenwich Mean Time (GMT).

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Initial hypotheses linking the data source to airports were challenged by the absence of passport information in the dataset. Furthermore, not all individuals who had their licenses scanned at airports had necessarily presented their driver’s licenses at security checkpoints. One individual whose license appeared on Nexus had not flown recently but had been renting a car from Hertz for an extended period around the timestamp date.

A significant breakthrough came with the discovery that two federal employees, who had used other forms of government identification at airport security, had subsequently used their state-issued driver’s licenses to rent vehicles from Hertz at their destinations. Their license timestamps aligned with their rental periods. For Krebs, a calendar reminder for a June 2025 flight, mentioning a passport, indicated that their driver’s license was not presented at airport security due to not possessing a Real ID at the time. Instead, a U.S. passport was used.

The connection deepened when Krebs’s mother’s driver’s license was found on Nexus, with timestamps for her images mere seconds apart from Krebs’s. Both had presented their licenses to a Hertz rental car representative at the same time. The mother confirmed that the rental car company was the only entity to whom she had provided her license that day, a sentiment echoed by Krebs. While the exact process of the rental car representative handling the licenses remained hazy, the prolonged period they were held behind the counter during the signing of forms suggested a potential point of data capture. KrebsOnSecurity sought comment from Hertz, with plans to update the story pending a response.

Further corroboration came from security and privacy researcher Zach Edwards, whose driver’s license was also available for purchase on Nexus. The timestamp on his record corresponded with a recent trip to Las Vegas for the annual DEFCON security conference. Edwards recalled handing over his license at the TSA checkpoint, a marijuana dispensary, and his hotel. However, he confirmed that only the dispensary definitively scanned his ID using a device.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The specific dispensary Edwards visited was Planet13, a multi-state chain with locations in California, Florida, Illinois, and Nevada. In 2022, the New Orleans-based identity provider idscan.net had announced an exclusive identity verification agreement with Planet13 dispensaries nationwide. IDScan.net claims to process ID verification for over 1,000 marijuana dispensaries across 19 U.S. states. The "trust" page on idscan.net’s website lists a diverse range of prominent clients, including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. The company’s own documentation highlights that its technology scans IDs using both infrared and ultraviolet light, performing over 21 million verifications monthly across more than 20,000 locations globally.

When contacted by KrebsOnSecurity, idscan.net stated it was investigating the matter but had not yet provided an official statement or detailed responses to specific inquiries. Jillian Kossman, a marketing and operations leader at idscan.net, acknowledged the provided updates were "welcome, and helpful to our team’s investigation."

As research for this story progressed, word of KrebsOnSecurity’s investigation reached the FBI, likely after the discovery that Nexus was also selling the driver’s license information of an FBI assistant director. This prompted a conference call with several FBI agents, including senior leaders from the agency’s cyber division. During this call, the FBI confirmed that its New Orleans field office had initiated an official investigation into an apparent breach involving idscan.net.

Zach Edwards emphasized the need for increased accountability for vendors collecting sensitive data, especially as more online and in-person interactions necessitate the sharing of driver’s licenses. He commented, "This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids. These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe."

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Larry Baldwin, principal intelligence researcher at cybersecurity firm Cybera, also found his driver’s license available on Nexus, with timestamps correlating to a Hertz car rental during a recent vacation. Baldwin highlighted the significant security and privacy threats posed by the Nexus service, noting that driver’s licenses are commonly used to open new lines of credit. He also pointed out the danger to individuals seeking to remain anonymous, including those fleeing domestic violence or participating in the federal witness protection program, as their identities could be easily exposed by AI-based image matching tools. Baldwin lamented, "Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised."

Update, September 8: IDscan.net has published a brief notice acknowledging that "an unauthorized third party may have access and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers." The company stated it is notifying affected individuals and offering credit protection services.

Update, September 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment clarified that Caesars has not been a client of IDScan.net and had not used VeriScan since February 2025, despite their listing on IDScan.net’s website. They stated that Caesars had no active VeriScan accounts at the time of the incident and did not authorize data retention, and that IDScan.net indicated the incident would have no impact on Caesars Entertainment.

Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website disappeared from the dark web, replaced by a simple message stating, "This service is no longer available."