FBI Investigates Dark Web Service Selling 153 Million Driver's License Scans
A dark web marketplace called Nexus emerged this week offering digital scans of more than 153 million driver's licenses from people across the United States and Canada, prompting an FBI investigation into what appears to be an ongoing breach of a Louisiana-based identity verification company. The service, which also lists over 10 million ID cards, 3 million travel documents, and hundreds of thousands of medical cards, represents one of the largest collections of identity documents ever offered for sale on cybercrime forums.
Security researcher Brian Krebs first reported the breach on September 1 after a source alerted him that his own Virginia driver's license was being used as a free sample to advertise the service on Exploit, a Russian-language cybercrime forum. By cross-referencing the dates stamped on stolen license images with travel records from friends and family members whose documents appeared in the database, Krebs traced the likely source to idscan.net, a New Orleans company that provides identity verification services to Hertz, marijuana dispensaries, and other businesses across North America.

The Scale of the Breach
The Nexus service claims to hold more than 170 million identity documents in total. A blank search in the marketplace returns approximately 11.5 million pages of results, with roughly 15 records displayed per page. The bulk of the records are for US residents, though the database includes about 1.1 million Canadian driver's licenses, with the largest concentration from Ontario at 473,673 records.
The stolen documents include not only driver's licenses but also marijuana dispensary cards, commercial driver's licenses, and what appear to be Common Access Cards—government-issued IDs that grant physical access to secure federal buildings and rooms. According to Krebs's analysis, the number of driver's license records increased by nearly 400,000 in just 24 hours, suggesting that freshly stolen data is being harvested and uploaded on a continuous basis.
Each license scan includes six image files: front and back photos captured under standard lighting, infrared, and ultraviolet conditions. The filenames include timestamps that, in multiple cases examined by Krebs, correspond to the exact dates when victims rented cars from Hertz or visited marijuana dispensaries that use idscan.net's verification systems.
How the Breach Was Traced
Krebs asked more than a dozen friends and family members to check whether their licenses appeared in the Nexus database. Nine were found, and each person confirmed they had traveled on or very close to the dates embedded in the image timestamps. Two federal employees whose licenses appeared in the database said they used government-issued identification at airport security but handed over their state driver's licenses later that day when renting vehicles from Hertz.
The timestamps on Krebs's own license correspond to a June 2025 trip when he flew to the Midwest for a family funeral. He recalled using his passport at the TSA checkpoint because his license lacked Real ID compliance, but handing over his license at the Hertz counter. His mother's license scan bears timestamps only seconds apart from his own—both licenses were handed to the rental car representative at the same time.
Security researcher Zach Edwards found his license in the database with a timestamp matching a July trip to Las Vegas for the DEFCON conference. Edwards said he handed his license to TSA, to a marijuana dispensary, and to his hotel, but only the dispensary scanned it with a device. The dispensary Edwards visited was Planet13, a multi-state chain. In 2022, idscan.net announced an exclusive identity verification agreement with Planet13 dispensaries across the country.

The "trust" page on idscan.net's website lists clients including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. The company says its systems perform more than 21 million verifications monthly at over 20,000 locations worldwide. The technology scans IDs with both infrared and ultraviolet light, producing the same six-image sets that appear in the Nexus marketplace.
FBI Opens Investigation
The FBI's New Orleans field office opened an official investigation on September 2, according to a conference call Krebs participated in with half a dozen FBI agents, including senior leaders from the agency's cyber division. The call was arranged after Krebs shared with a trusted source that the Nexus database included the driver's license of an assistant FBI director, as well as the license of Defense Secretary Pete Hegseth.
Contacted by Krebs, idscan.net acknowledged it was investigating the matter but has not released an official statement. Jillian Kossman, a marketing and operations leader at the company, told Krebs the updates he provided were "welcome and helpful" to the investigation team but shared no additional information.
Shortly after Krebs published his initial report on September 1, the Nexus website vanished from the dark web, replaced by a plain text message reading "This service is no longer available." However, the disappearance of the marketplace does not mean the stolen data is contained. As security experts noted, tens of thousands of people likely downloaded the database before the site was taken offline, and the data cannot be retrieved.
Downstream Threats
The breach poses multiple serious security threats. Driver's licenses are commonly used as proof of identity when opening new lines of credit, resetting bank account credentials, or accessing sensitive services. One commenter on Krebs's article described how a criminal reset his Chase bank account credentials using his driver's license after he purchased a used vehicle from Hertz, despite the account having two-factor authentication enabled. Chase insisted the breach was the victim's fault because the attacker presented a valid license.
Larry Baldwin, principal intelligence researcher at Cybera, said the service could expose people who do not wish to be found but cannot meaningfully change their appearance, including those fleeing domestic violence and individuals in the federal witness protection program. Today's AI-based image matching tools make it nearly impossible for such individuals to avoid identification if their license photos are widely available.
The scale of the breach also changes the economics of identity fraud. With 153 million records available, attackers can conduct targeted campaigns against specific demographics or locations, or they can use the data to validate synthetic identities by pairing real license scans with fabricated financial profiles.

The Identity Verification Dilemma
The Nexus breach highlights a growing tension in digital identity systems. As more services require proof of identity—whether for age verification on social media platforms, compliance with alcohol sales laws, or access to marijuana dispensaries—the number of third-party vendors collecting and storing sensitive documents has exploded. Each vendor becomes a potential single point of failure.
Edwards told Krebs the episode should strengthen the resolve of people fighting back against online ID schemes that require driver's licenses to access services under the guise of protecting children. "These systems are putting sensitive data into more and more third-party vendors, and we don't nearly have the oversight to ensure they are safe," Edwards said.
SANS Institute analysts who reviewed the breach emphasized that organizations should ask not only "Can we collect this information?" but also "Once we have verified the person's identity, do we still need to keep it?" Data minimization principles dictate that identity verification providers should delete scanned documents immediately after confirming authenticity, rather than retaining them indefinitely in online repositories.
Several cybersecurity professionals who commented on the SANS analysis noted that they had encountered repositories of scanned driver's licenses and passports during penetration tests. Providers performing identity proofing have become de facto identity vaults without designing their security, retention, and deletion practices to reflect that reality.
Regulatory and Policy Gaps
The breach arrives as multiple US states and countries consider or implement age-verification requirements for social media and other online platforms. Utah recently passed House Bill 437, commonly called the "100% ID law," mandating ID scans for all alcohol purchases at state-owned liquor stores. The legislation also requires cannabis delivery services to scan licenses. Florida recently started issuing partially randomized driver's license numbers to make it harder for attackers to guess valid numbers, though that change does not protect the images themselves from being stolen.
No federal law currently sets minimum security standards for identity verification providers, and state privacy laws vary widely in their requirements. The industry has operated largely on trust, with clients performing vendor assessments but rarely auditing what happens to the data after verification.
Baldwin and other security professionals argue that contracts with identity verification providers should include logging, data segregation, retention limits, incident notification requirements, evidence access rights, and mandatory independent security audits. At present, most contracts do not address what happens if a provider's repository is compromised.
The Nexus breach also exposes the limits of credit freezes and other protective measures consumers can take. A credit freeze prevents new accounts from being opened, but it does not stop someone with a valid driver's license scan from resetting credentials on an existing account, as the Chase bank incident demonstrates. Banks and financial institutions rely on driver's licenses as a primary form of authentication, and no easy alternative exists for the millions of people whose licenses are now circulating on cybercrime forums.
What Happens Next
The FBI investigation will likely focus on whether idscan.net was breached through a technical vulnerability, an insider threat, or a supply chain compromise. The fact that new records were being added to Nexus at a rate of 400,000 per day suggests the breach was not a one-time exfiltration but an ongoing siphon of data from live systems.
Update: On September 2 at 6:05 p.m. ET, a spokesperson for Caesars Entertainment said the company has not been a client of idscan.net since February 2025 and had no active VeriScan accounts at the time of the incident. The spokesperson said idscan.net confirmed the incident should have no impact on Caesars.
Contacted separately, Hertz has not responded to requests for comment.
The long-term impact of the breach will depend on how quickly law enforcement can identify the operators of Nexus, whether idscan.net can confirm the scope of the compromise, and whether legislators respond with new regulations for identity verification providers. In the meantime, the 153 million people whose licenses are circulating on the dark web have no practical way to revoke or replace the stolen credentials, since driver's licenses remain valid for years and replacing a license does not invalidate the stolen image.
For more cybersecurity coverage, see Cybersecurity.
Related reading: McKesson Data Breach.