Massive Dark Web Leak Exposes Over 153 Million North American Driver’s Licenses Tied to Identity Verification Breach

By Investigative Cyber Security Desk


Main Facts

A newly uncovered dark web identity theft service known as “Nexus” has rattled the cybersecurity community and federal law enforcement by putting digital scans of more than 153 million driver’s licenses and government-issued identification cards up for sale. Operating on the Russian-language cybercrime forum Exploit, the service launched with an astonishingly vast inventory of personal data targeting citizens across the United States and Canada.

The scope of the breach is staggering. In addition to the 153 million driver’s licenses, the repository includes over 10 million identification cards, more than 3 million international and travel documents, and at least 579,000 medical cards. High-ranking U.S. government officials—including U.S. Defense Secretary Pete Hegseth—have reportedly had their sensitive credentials compromised and listed for sale on the marketplace.

Preliminary investigations strongly link the massive cache of stolen data to a security compromise at idscan.net, a prominent Louisiana-based identity verification and document authentication company. The firm’s client base includes major enterprise brands, Fortune 500 companies, commercial rental services, and over 1,000 cannabis dispensaries spanning 19 states.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The Federal Bureau of Investigation (FBI) has treated the incident with maximum urgency, launching an official inquiry through its New Orleans field office to track down the exact intrusion vectors and unmask the malicious actors behind Nexus.


Chronology of the Discovery

The breach came to light through a combination of underground cyber threat intelligence gathering and targeted journalistic investigation:

  • August 31: A threat intelligence source alerted security researcher Brian Krebs to a newly advertised service on the Russian cybercrime forum Exploit. The threat actor behind "Nexus" offered access to identification documents belonging to more than 170 million North Americans. To prove the legitimacy of their database, the actor included Krebs’s own Virginia driver’s license as a free sample in the initial sales thread.
  • Early September: Security researchers, including Privacy and Data Researcher Zach Edwards and Cybera Principal Intelligence Researcher Larry Baldwin, began cross-referencing their personal data and records. They discovered that the precise timestamps appended to their stolen license image files matched almost down to the minute with recent real-world events, such as checking into hotels, flying to conferences, or renting vehicles.
  • September 2: Word of the investigation reached the FBI, prompting senior leaders from the agency’s cyber division to open formal communications. By late afternoon, an official federal investigation was launched into the data practices and security infrastructure of idscan.net. Shortly after the initial story was published, the Nexus dark web portal abruptly vanished, replacing its login prompt with a plain-text message: "This service is no longer available."
  • September 8: Facing intense public and regulatory pressure, idscan.net published an official security notification confirming that an unauthorized third party had accessed and copied customer data, including full names and government-issued identification numbers.

Supporting Data and Technical Analysis

Technical inspection of the Nexus archive revealed sophisticated harvesting methods. The data files are not merely low-resolution smartphone snapshots; rather, they appear to be high-fidelity document scans harvested directly from specialized optical hardware.

Deep Dive into the Data Structure

  • Massive Inventory Scale: A blank search within the Nexus backend yielded approximately 11.5 million pages of search results, averaging 15 individual records per page. While Canadian records accounted for roughly 1.1 million entries (led heavily by Ontario with over 473,000 records), the vast majority of the repository targets U.S. citizens.
  • Multi-Spectrum Imaging: Many compromised records contained a suite of six distinct image files. These included standard front-and-back light scans, alongside specialized infrared and ultraviolet (UV) versions. This multi-spectrum capture directly mirrors the scanning technology utilized by commercial document verification hardware—such as the systems deployed by idscan.net, which use UV and IR light to authenticate security holograms on modern IDs.
  • Temporal Precision: Metadata timestamps attached to the image files corresponded precisely with real-world interactions. For instance, researchers who had rented vehicles through Hertz or visited high-volume retail locations like Las Vegas’s Planet13 dispensary found that the file timestamps matched their physical transactions down to the exact day—and in several cases, within seconds of each other (such as family members handing documents across a counter simultaneously).
  • Diverse Document Subtypes: Beyond standard commercial driver’s licenses (CDLs) and state IDs, the platform indexed non-traditional credentials, including marijuana dispensary loyalty cards, international travel documents, medical cards, and even potential Common Access Cards (CACs) used for physical access to secure government buildings.

Official Responses and Corporate Accountability

As the fallout from the Nexus leak reverberates across corporate boardrooms and government agencies, affected entities have rushed to clarify their relationships with idscan.net and address systemic vulnerabilities.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

idscan.net’s Response

Following initial outreach by investigative journalists, idscan.net acknowledged that it was conducting an internal investigation. Jillian Kossman, a marketing and operations leader at the firm, noted that the real-time updates provided by security researchers were helpful to their forensic teams.

On September 8, idscan.net formalized its position by releasing a data security incident notification. The company conceded that an unauthorized third party had gained access to customer information, including names and identity card numbers. The firm stated it was actively notifying impacted individuals and offering supplementary credit protection services.

Third-Party Denials and Discrepancies

The fallout also exposed potential discrepancies in corporate client rosters. Although idscan.net’s marketing materials historically listed hospitality giant Caesars Entertainment among its verified partners, a Caesars spokesperson firmly pushed back. According to Caesars, the corporation had ceased using the VeriScan platform in February 2025, maintained no active accounts at the time of the security lapse, and never authorized idscan.net to retain customer data.

Federal Law Enforcement Engagement

The involvement of high-ranking government officials—including Defense Secretary Pete Hegseth and elements within the FBI itself—transformed a corporate data breach into a matter of national security. The FBI’s New Orleans field office spearheaded the cyber division’s investigation, looking into how millions of verified identity profiles could be systematically exfiltrated over a year-long period without triggering automated enterprise alarms.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Implications for Privacy, Security, and Identity Verification

Security experts warn that the exposure of 153 million verified identity scans introduces existential risks to modern digital infrastructure, consumer financial security, and individual safety.

The Threat to Financial Systems and Credit Integrity

State-issued driver’s licenses serve as the gold standard for remote and in-person authentication. Having millions of these documents—complete with infrared and ultraviolet authentication layers—readily available on cybercrime forums effectively hands bad actors the keys to the kingdom. Criminals can leverage these comprehensive image sets to bypass biometric "liveness" checks, open fraudulent lines of credit, take over bank accounts, and commit large-scale synthetic identity fraud.

Amplified Risks for Vulnerable Populations

Beyond financial fraud, experts like Cybera’s Larry Baldwin highlight the catastrophic human cost of such large-scale leaks. For individuals who rely on anonymity for physical protection—such as domestic violence survivors or individuals integrated into the federal witness protection program—the permanent exposure of facial recognition scans and legal identities is deeply dangerous. Even individuals who attempt to alter their appearance may find themselves unmasked by modern AI-powered facial recognition tools trained on high-resolution state identification archives.

A Backlash Against Over-Collection of Data

The incident has reignited fierce debates regarding the widespread corporate practice of demanding driver’s licenses for routine transactions. From digital age-verification mandates to commercial check-ins, consumers are routinely forced to surrender sensitive personal data to third-party vendors with opaque security standards.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Privacy researcher Zach Edwards noted that the episode should serve as a stark warning to lawmakers and regulators:

"This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids. These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe."

As the federal investigation deepens, corporations and identity verification providers will face unprecedented scrutiny over their data retention policies, cloud security hygiene, and the fundamental necessity of hoarding millions of biometric and legal profiles in centralized repositories.

By Nana Wu