The digital underworld has been shaken by the emergence of a new identity theft service on the dark web, brazenly offering over 153 million digital scans of driver’s licenses belonging to individuals in the United States and Canada. Initial investigations and interviews suggest that this illicit operation is siphoning sensitive imagery collected by a prominent identity verification company headquartered in Louisiana. In response to this alarming development, the New Orleans field office of the Federal Bureau of Investigation (FBI) has officially launched an inquiry into the provenance of these compromised documents.

The exposé began on Monday, August 31st, when a source brought to the attention of KrebsOnSecurity a new user on the Russian cybercrime forum Exploit, advertising access to a trove of identity documents encompassing more than 170 million individuals across North America. The proprietor of this nascent identity theft service even offered the source’s own Virginia driver’s license as a free sample, immediately raising red flags. This service, christened "Nexus," claims to house an staggering collection of over 153 million driver’s licenses from the U.S. and Canada, complemented by more than 10 million identification cards, over three million travel documents or international IDs, and at least 579,000 medical cards.

A preliminary examination of the Nexus service strongly suggests that its reported figures are not inflated. A broad search without any specific parameters yielded approximately 11.5 million pages of results, with roughly 15 entries per page. These records encompass individuals from both Canada and the United States, though the vast majority are of American citizens. A targeted search for Canadian driver’s licenses alone returned around 1.1 million results, with a significant concentration originating from Ontario (473,673 records). Intriguingly, the identity records extend beyond driver’s licenses to include marijuana dispensary cards. Some entries note "CDL" as the source, likely an abbreviation for "commercial driver’s license," while others indicate "CAC," potentially referring to Common Access Cards, which are government-issued credentials for accessing secure facilities.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The architects behind Nexus assert that the compromised license images originate from an ongoing breach at "a major identity verification company" whose clientele includes numerous Fortune 500 corporations. The service proudly proclaimed in its introductory post on Exploit, "We have been continuously exfiltrating new data for over a year into our private database. Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." The dynamic nature of the data is underscored by a nearly 400,000 increase in listed driver’s license records within a mere 24-hour span, indicating a consistent flow of freshly stolen data being uploaded to the service.

The record containing the author’s driver’s license was particularly revealing, featuring six image files: three pairs of front and back scans, along with infrared and ultraviolet versions. Each image file was appended with a date and timestamp. The timestamp on the author’s license scan precisely correlated with a flight taken in June 2025 to attend a family funeral in the midwestern United States. Further investigation involving more than a dozen friends and family members revealed a compelling pattern: each of the nine individuals whose licenses were found on Nexus confirmed having traveled on or very near the dates indicated in the image timestamps. While the timezone of these timestamps remains uncertain, analysis of car rental records shared by research participants suggests it is set to Greenwich Mean Time (GMT).

An initial hypothesis that the data source might be linked to airports was quickly dispelled as passports were notably absent from the dataset. Furthermore, not all individuals who assisted with the research recalled presenting their driver’s license at airport security on the day of their travel. One individual whose license appeared in Nexus had not flown recently but had been renting a car from Hertz for several months around the date of their timestamp. Two federal employees who provided other forms of government identification for airport security confirmed using their state-issued driver’s licenses for car rentals at their destinations, both from Hertz.

A reminder in the author’s calendar for the June 2025 flight noted the need to bring a passport. It was also recalled that the driver’s license was not presented at Reagan National Airport security that day, as it was not yet a Real ID, a requirement for domestic travel by the TSA. Instead, a government-issued U.S. passport was used. The plot thickened when the author’s mother’s driver’s license was also found on the Nexus service, with timestamps mere seconds apart from the author’s. This was significant because both individuals presented their licenses to the Hertz rental car representative simultaneously. The mother confirmed that the rental car company was the only entity to which she provided her license that day, a sentiment echoed by the author. While it was unclear if the rental car representative scanned the licenses, they were held behind the counter for several minutes during the signing of paperwork. KrebsOnSecurity reached out to Hertz for comment and will update the story accordingly.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Zach Edwards, a prominent security and privacy researcher and creator of the DecryptAds service, also found his driver’s license available for purchase on Nexus. The timestamp on his record corresponded to a recent trip to Las Vegas for the annual DEFCON security conference. Edwards reported handing over his license at the TSA checkpoint, a marijuana dispensary, and his hotel (the Aria). He confirmed that the dispensary was the only one of these venues that definitively scanned his ID. The dispensary in question was Planet13, a multi-state chain with locations in California, Florida, Illinois, and Nevada. In 2022, the New Orleans-based identity provider idscan.net announced an exclusive identity verification partnership with Planet13 dispensaries nationwide. Idscan.net claims to process ID verifications for over 1,000 marijuana dispensaries across 19 U.S. states.

The "trust" page of idscan.net lists numerous major brands as clients, including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. As detailed in idscan.net’s own documentation, their technology scans IDs using both infrared and ultraviolet light. The company states that its systems perform over 21 million verifications monthly at more than 20,000 locations globally.

When contacted by KrebsOnSecurity, idscan.net acknowledged the investigation but had not yet provided an official statement or detailed responses to specific inquiries. Jillian Kossman, a marketing and operations leader at idscan.net, stated, "At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation."

As research for this story progressed, word of Krebs’s investigation reached the FBI, likely after the author shared information about the Nexus service also selling the driver’s license information of an FBI assistant director. Earlier that afternoon, the author was included in a conference call with several FBI agents, including senior cyber division leaders. During this call, the FBI confirmed that their New Orleans field office had initiated an official investigation into a suspected breach involving idscan.net.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Edwards emphasized the need for higher security standards from vendors collecting sensitive driver’s license data, particularly as more in-person and online interactions require its submission. He commented, "This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids. These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”

Larry Baldwin, principal intelligence researcher at cybersecurity firm Cybera, also found his driver’s license on Nexus, with timestamps corresponding to a Hertz car rental during a recent vacation. Baldwin highlighted the significant security and privacy threats posed by the Nexus service, noting that driver’s licenses are frequently used to open new lines of credit. He further warned of the danger to individuals seeking to remain anonymous, including those fleeing domestic violence or in witness protection programs, as their altered appearances might not fool advanced AI image-matching tools. Baldwin concluded, "Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised.”

Update, September 8: Idscan.net published a brief notice confirming that "an unauthorized third party may have access and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers." The company stated it is notifying affected individuals and offering credit protection services.

Update, September 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment clarified that Caesars has not been a client of IDScan.net and ceased using VeriScan in February 2025, despite its listing on IDScan.net’s website. They stated that Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, adding that the incident should have no impact on Caesars Entertainment.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website disappeared from the dark web, replaced by a simple message stating, "This service is no longer available."