153 Million Driver's Licenses for Sale on the Dark Web: Inside the IDScan.net Breach
A dark-web service dubbed Nexus is selling scans of 153M+ US and Canadian driver's licenses — infrared and ultraviolet images included — traced to Louisiana ID-verification firm IDScan.net. The FBI's New Orleans field office has opened an investigation.
On August 31, 2026, a source tipped off security journalist Brian Krebs to a new service being advertised on Exploit, a Russian-language cybercrime forum. The product on offer was not malware or stolen credit cards but something more intimate: digital scans of identity documents — more than 153 million driver’s licenses from the United States and Canada, along with over 10 million ID cards, 3 million travel documents and international IDs, and at least 579,000 medical cards. The proprietor, dubbing the service “Nexus,” offered Krebs’s own Virginia driver’s license as a free sample in the sales thread. By September 2, the FBI’s New Orleans field office had opened an official investigation, and the trail led back to a Louisiana-based identity-verification company called IDScan.net.
What Nexus is selling
The scale claim is not marketing hype. A blank search in Nexus — no parameters entered — returns roughly 11.5 million pages of results at about 15 records per page. The bulk of the records are on Americans; a search restricted to Canadian licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).
What makes the dataset unusually dangerous is its depth. Records for some licenses — Krebs’s own included — contain six image files: three pairs of front-and-back photos captured in basic scan, infrared, and ultraviolet light. That trifecta is the signature of professional ID-verification hardware, not a phone camera pointed at a bar counter. Each image file carries a date-and-timestamp, effectively documenting when and where the document was scanned.
The record types are telling in other ways. Beyond driver’s licenses, the trove includes marijuana dispensary cards, and some entries carry source notations like “CDL” (presumably commercial driver’s license) and “CAC” — possibly Common Access Cards, the government-issued credentials that grant physical access to federal buildings and secure rooms. Records for high-ranking officials are present, including U.S. Defense Secretary Pete Hegseth.
Most alarmingly, the operators claim they “have been continuously exfiltrating new data for over a year into our private database.” That claim has observable support: over a single 24-hour window during Krebs’s reporting, the number of license records listed in Nexus grew by nearly 400,000 — fresh stolen data is still flowing in on a semi-regular basis.
How the source was traced
Krebs’s forensics read like a textbook investigation. He asked more than a dozen friends and family members for permission to search for their licenses in the service. Nine were found, and every one of them had either traveled or completed a documented transaction on or very close to the date in their image timestamps.
The initial airport theory collapsed quickly: there were no passports in the dataset, and some affected people had never flown recently. One person whose license appeared in Nexus had simply rented a car from Hertz for several months around the timestamp date. Two federal employees in the sample had shown other credentials at airport security — but both handed their state driver’s licenses to Hertz rental counters later the same day. Krebs then found his own mother’s license in the service, with timestamps just seconds apart from his own — the moment they both handed their licenses to the same Hertz representative.
The second thread ran through security researcher Zach Edwards, whose record timestamp matched a Las Vegas trip that included a visit to Planet 13, a multi-state cannabis dispensary chain. In 2022, IDScan.net announced an exclusive identity verification agreement with Planet 13’s dispensaries nationally, and the company says it processes ID verification for more than 1,000 marijuana dispensaries across 19 U.S. states.
IDScan.net’s own trust page names Hertz, Target, FedEx, Motorola Solutions, financial-services firm Jack Henry, and Caesars Entertainment among its customers. Its documentation describes scanning IDs under infrared and ultraviolet light — matching the six-image record format — and the company states its systems perform more than 21 million verifications monthly across more than 20,000 locations worldwide.
Contacted by Krebs, IDScan.net acknowledged an active investigation but offered no substantive answers. Within hours, the company had sent customers a preliminary incident notice confirming it “received information suggesting that certain information may have been exposed and that IDScan.net may be implicated,” and listing standard response steps: securing systems, notifying its cyber insurance carrier, engaging outside counsel and an independent forensic firm, coordinating with law enforcement, and preserving logs.
The FBI’s involvement crystallized after Krebs discovered that Nexus was also selling the driver’s license information of the FBI’s assistant director — prompting a conference call with a half-dozen agents, including senior leaders from the agency’s cyber division, and the opening of a formal inquiry by the New Orleans field office. Shortly after the story published, the Nexus service vanished from the dark web, replacing its login page with a plain-text message: “This service is no longer available.”
Why this matters beyond identity theft
The immediate harm vector is new-account fraud: state-issued driver’s licenses remain the canonical breeder document for opening lines of credit. But the secondary effects are more insidious.
Larry Baldwin, principal intelligence researcher at Cybera — whose own license appears in the service with a Hertz-rental timestamp — noted that the dataset could expose people who cannot meaningfully change their appearance and do not wish to be found. That includes those fleeing domestic violence, and potentially participants in the federal witness protection program. Modern AI-based face-matching tools make physical relocation far less protective than it once was.
The breach also lands at an awkward moment for the identity-verification industry. Regulators and platforms are pushing ever more ID-collection requirements — most prominently online age-verification laws framed around protecting minors — which funnel license scans into an expanding ecosystem of third-party vendors. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe,” Edwards told KrebsOnSecurity.
There is also an AI connection that makes the timing worse. The same class of AI-verification tooling that IDScan.net sells — document parsing, face matching, liveness detection — is what makes a high-fidelity scan bundle (basic, infrared, and ultraviolet, with timestamps) so valuable to attackers. A dataset like this doesn’t just enable classic identity theft; it is precisely the raw material needed to defeat or poison automated verification systems, and to train or target the next generation of them.
The larger lesson
A single mid-sized vendor in Louisiana became the choke point through which scans from car rental counters, dispensaries, retailers, and financial institutions across North America allegedly flowed for more than a year — continuously. Neither Hertz, Target, FedEx, nor Planet 13 was directly breached in the traditional sense; their customers’ documents were, in effect, aggregated by a downstream supplier most consumers had never heard of.
That is the structural risk of third-party data concentration: security is only as strong as the least-governed node in the pipeline, and the node with the most to lose reputationally (the brand at the counter) often has the least visibility into the vendor actually storing the scans. For enterprises, the takeaway is vendor-level data minimization — verifying that suppliers delete rather than accumulate document images. For everyone else, the practical advice in the story’s comments section is blunt but accurate: assume your license was in the dataset, freeze your credit, and treat any service demanding a license scan as a risk in itself.
Nexus is offline, for now. But the data — a year of continuous exfiltration, 170 million people’s documents — is out, copied, and not coming back.