Massive Dark Web Breach Exposes 153 Million North American Driver’s Licenses, Sparking FBI Investigation

WASHINGTON — In what cybersecurity experts are calling one of the most catastrophic identity theft events in North American history, a newly launched dark web operation has begun commercializing digital scans of more than 153 million driver’s licenses and government-issued identification documents.

Dubbed Nexus, the illicit service emerged on a prominent Russian-language cybercrime forum, offering open access to vast troves of personal identifiable information (PII) belonging to residents of the United States and Canada. Investigative findings, corroborated by interviews with victims and high-ranking security researchers, point directly to a massive data harvesting pipeline originating from a prominent Louisiana-based identity verification company, IDScan.net.

The scale of the breach is staggering, affecting everyday citizens, high-ranking political figures, and federal employees alike. The unfolding crisis has already prompted an active federal inquiry led by the Federal Bureau of Investigation’s New Orleans field office, raising urgent questions regarding the ubiquitous collection and retention of sensitive biometric and identity documents by private corporations.


Main Facts: The Scope of the Nexus Operation

The Nexus platform first advertised its catalog on the Russian cybercrime forum Exploit, claiming to hold an exhaustive database of North American identity documents. According to preliminary site metrics and independent audits of the platform, the operation’s repository includes:

  • More than 153 million driver’s licenses primarily from the United States and Canada.
  • Over 10 million identification cards.
  • More than 3 million travel documents and international IDs.
  • At least 579,000 medical cards.

A cursory inspection of the platform reveals that these figures are not exaggerated. Unfiltered searches across the Nexus interface yield roughly 11.5 million pages of indexed records. While records feature citizens from both sides of the northern border—including approximately 1.1 million Canadian records, heavily concentrated in Ontario—the overwhelming majority of victims are American citizens.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Beyond standard driver’s licenses, the database incorporates niche identification classes, including commercial driver’s licenses (CDLs), marijuana dispensary intake cards, and Common Access Cards (CACs) typically reserved for physical entry into secure U.S. government facilities.

The profiles are shockingly comprehensive. Many records include up to six distinct image files: front and back color scans, standard digital images, and specialized infrared and ultraviolet (UV) scans. Crucially, these files bear exact date and time stamps, alongside high-resolution photographs of the victims and heavily detailed personal metadata.

The inclusion of high-profile targets underscores the breadth of the compromise. Among the records available for preview or purchase on Nexus are the driver’s licenses of U.S. Defense Secretary Pete Hegseth and a senior assistant director of the FBI.


Chronology of Discovery and Takedown

The timeline of the Nexus incident highlights the lightning-fast speed at which modern cybercriminal enterprises monetize high-volume data exfiltration:

  • Monday, August 31: A threat intelligence source alerts investigative journalist Brian Krebs to a newly posted service on the Exploit forum. The Nexus proprietor uses Krebs’ own Virginia driver’s license as a promotional "free sample" in the forum’s introductory sales thread.
  • Early September: Independent researchers begin testing the service by querying family, friends, and colleagues. Timestamps on recovered records correlate precisely with recent in-person transactions, such as car rentals and dispensary visits.
  • September 2, Afternoon: Word of the investigation reaches federal law enforcement. Following inquiries regarding the exposure of senior federal officials, Krebs is added to a secure conference call with roughly half a dozen FBI personnel, confirming that the FBI’s New Orleans field office has officially launched a criminal probe into IDScan.net.
  • September 2, 6:05 PM ET: Caesars Entertainment issues a public statement clarifying that it has not been an active client of IDScan.net since February 2025 and did not authorize the retention of consumer data.
  • September 2, 8:56 PM ET: Shortly after initial reports go public, the Nexus dark web portal abruptly vanishes. Its login page is replaced with a single static text string: "This service is no longer available."
  • September 8: IDScan.net officially publishes a data security notification acknowledging that an unauthorized third party accessed and potentially copied customer information, including full names and government-issued identification numbers.

Supporting Data and The IDScan.net Connection

Determining the origin of the Nexus repository required extensive forensic tracking. Researchers matched timestamps on compromised driver’s license scans with real-world travel and commercial activities.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

For instance, security researcher Zach Edwards found his driver’s license cataloged on the site, matching a timestamp from a trip to Las Vegas for the DEFCON security conference. While Edwards visited multiple venues, he noted that the only entity that physically scanned his ID through an electronic verification device was a local cannabis dispensary, Planet 13.

Public records and corporate disclosures point directly to IDScan.net as the central nexus of the leak. In 2022, IDScan.net announced an exclusive national identity verification partnership with Planet 13. The company boasts processing capabilities for over 1,000 marijuana dispensaries across 19 U.S. states.

Furthermore, IDScan.net’s promotional materials and "Trust" portal claim partnerships with major enterprise brands, including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. The company’s specialized hardware and software utilize multi-spectral scanning technology—specifically capturing infrared and ultraviolet imaging vectors to authenticate physical cards. This technological detail matches the precise six-file format (including IR and UV scans) discovered inside the Nexus repository.

IDScan.net processes more than 21 million verifications monthly across over 20,000 global locations, creating a massive, centralized bottleneck of sensitive, highly regulated biometric and documentary data.


Official Responses

As the fallout from the Nexus leak reverberates through corporate boardrooms and federal agencies, impacted entities have rushed to respond:

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security
  • IDScan.net: Following initial requests for comment, marketing and operations lead Jillian Kossman acknowledged the assistance provided by external researchers, noting that tips were helpful to the internal investigation. On September 8, the company issued a formal security notification confirming the incident and offering credit protection services to impacted individuals.
  • The Federal Bureau of Investigation: The FBI’s New Orleans field office initiated an official criminal inquiry into the breach vector, treating the unauthorized exposure of government and civilian credentials as a matter of national security.
  • Caesars Entertainment: Moving swiftly to distance itself from the controversy, a Caesars spokesperson stated that the hospitality giant terminated its use of IDScan’s VeriScan product in February 2025. The company asserted that no active accounts existed during the breach window and that IDScan.net had no authorization to retain user data.
  • Hertz and Other Corporate Partners: Additional enterprise clients listed on IDScan’s marketing materials have faced intense scrutiny regarding their data retention policies and third-party vendor oversight.

Broader Implications: Privacy, Security, and Public Policy

The exposure of 153 million North American identities is far more than a corporate data breach; it represents a systemic failure of modern digital authentication frameworks. Cybersecurity experts have lined up to condemn the practices that allowed this trove to be compiled.

Larry Baldwin, principal intelligence researcher at Cybera, highlighted the severe real-world dangers posed by the circulation of high-resolution front-and-back license scans. Because state-issued driver’s licenses serve as the primary foundational anchor for opening financial lines of credit, millions of Americans are now at immediate risk of synthetic identity fraud and account takeover attacks.

Furthermore, Baldwin raised alarm bells regarding vulnerable populations. Individuals fleeing domestic violence, as well as participants in federal witness protection programs who have been assigned completely new identities, rely heavily on their ability to maintain operational security in physical spaces. The widespread availability of high-fidelity facial and documentary scans undermines the safety nets designed to protect these groups from malicious actors equipped with AI-based image-matching and facial recognition tools.

Zach Edwards argues that the incident should serve as a wake-up call regarding the endless collection of personal data under the guise of security:

"This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids," Edwards noted. "These systems are putting sensitive data into more and more third-party vendors, and we don’t have nearly the oversight to ensure they are safe."

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

As the Nexus portal goes dark, the data has already been distributed across underground channels, ensuring that the downstream consequences of this breach will be felt by consumers, financial institutions, and law enforcement agencies for years to come.