The dark web has witnessed the emergence of a new and alarming identity theft service, "Nexus," which is actively marketing over 153 million digital scans of United States and Canadian driver’s licenses. Investigations suggest a connection to a prominent identity verification company based in Louisiana, and the New Orleans field office of the Federal Bureau of Investigation (FBI) has launched a formal inquiry into the origins of this vast trove of personal data. The sheer scale of the breach and the potential for widespread identity fraud have sent shockwaves through the cybersecurity community.
The illicit service was brought to light on Monday, August 31st, when a source alerted KrebsOnSecurity to its advertisement on the Russian cybercrime forum "Exploit." The proprietor of Nexus offered a sample of compromised data, including the source’s own Virginia driver’s license, to entice potential buyers. Nexus claims to possess an extensive collection beyond driver’s licenses, boasting over 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. A preliminary search within Nexus revealed approximately 11.5 million pages of results for driver’s licenses alone, with the majority pertaining to individuals in the United States, though a significant portion, around 1.1 million records, are from Canada, particularly Ontario.

Intriguingly, the data available through Nexus extends beyond standard driver’s licenses to include marijuana dispensary cards. Some records are sourced with the notation "CDL," likely indicating commercial driver’s licenses, while others bear the "CAC" designation, which could refer to Common Access Cards, government-issued identification used for accessing secure facilities. The operators of Nexus assert that their data is being exfiltrated from an ongoing breach at "a major identity verification company" that serves numerous Fortune 500 clients. They claim to have been continuously acquiring data for over a year, offering previews of records with redacted sensitive information and displaying customer photos where available. The rapid increase in the number of driver’s license records—nearly 400,000 added in just 24 hours—underscores the continuous harvesting and uploading of compromised data.
The compromised driver’s license scans in Nexus are remarkably detailed, often including six image files: front and back views, along with infrared and ultraviolet versions. Each image is appended with a date and timestamp. For the author of this report, the timestamp on the scanned license corresponded to a flight taken in June 2025 to the Midwestern United States for a family funeral. Further investigation, involving over a dozen friends and family members who granted permission for their licenses to be searched, revealed a pattern: for nine individuals whose licenses were found, the timestamps closely aligned with their recent travel dates or significant events requiring identification. The timestamps appear to be set to Greenwich Mean Time (GMT), based on car rental records shared by some participants.
Initial speculation that the data originated from airport security was quickly dispelled by the absence of passport information in the dataset. While some individuals confirmed presenting their driver’s licenses at airports, others did not. One individual whose license was compromised had not flown recently but had been renting a car from Hertz for an extended period around the timestamp date. Two federal employees, who presented other government IDs at airport security, stated they used their state-issued driver’s licenses for car rentals later that day, both from Hertz. The author’s own experience, where a passport was used for TSA security at Reagan National Airport due to not yet possessing a Real ID, further complicated the airport theory. However, the author’s mother’s driver’s license was also found in Nexus, with timestamps mere seconds apart, suggesting they both presented their licenses to a Hertz rental car representative simultaneously. The mother confirmed that the rental car company was the only entity to whom she provided her license that day.

Security and privacy researcher Zach Edwards, whose driver’s license scan is also available for purchase on Nexus, provided further crucial insights. The timestamp on his record coincided with a recent trip to Las Vegas for the DEFCON security conference. While Edwards did not rent a car, he presented his license at the TSA checkpoint, a marijuana dispensary, and his hotel. He noted that the dispensary was the only entity confirmed to have scanned his ID. The dispensary in question was Planet13, a multi-state chain that, in 2022, announced an exclusive identity verification agreement with the New Orleans-based provider idscan.net. Idscan.net specializes in identity verification for over 1,000 marijuana dispensaries across 19 U.S. states and boasts a client list that includes major corporations like Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment.
Idscan.net’s technology, as detailed in their own documentation, utilizes infrared and ultraviolet light to scan IDs, mirroring the types of images found in the Nexus data. Idscan.net performs millions of verifications monthly across thousands of locations globally. When contacted by KrebsOnSecurity, idscan.net acknowledged the investigation but had not yet provided a substantive response to specific inquiries. Jillian Kossman, a marketing and operations leader at idscan.net, stated that updates provided by KrebsOnSecurity were "welcome, and helpful to our team’s investigation."
The FBI’s involvement was triggered when KrebsOnSecurity shared that Nexus was also selling the driver’s license information of an FBI assistant director. Earlier that afternoon, a conference call was held with FBI agents, including senior leaders from the cyber division. During this call, the FBI confirmed that its New Orleans field office had initiated an official investigation into a suspected breach involving idscan.net.

Edwards emphasized the need for higher standards from vendors collecting sensitive personal data, especially as more transactions, both online and in-person, require the presentation of driver’s licenses. He stated, "This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids. These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe."
Larry Baldwin, principal intelligence researcher at the cybersecurity firm Cybera, also confirmed that his driver’s license scan on Nexus contained timestamps corresponding to a car rental from Hertz during a recent vacation. Baldwin highlighted the severe security and privacy risks posed by the Nexus service. He pointed out that driver’s licenses are commonly used to open new lines of credit, and their compromise could expose individuals seeking to remain anonymous, including those fleeing domestic violence or in federal witness protection programs. Baldwin lamented, "Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised."
Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website was taken offline, replaced by a simple message stating, "This service is no longer available." The rapid disappearance of the service suggests a swift law enforcement or cybersecurity response. This story remains a developing situation, and any further updates will be noted.

