The FBI is investigating after a newly launched dark web identity-theft service claimed to have more than 153 million U.S. and Canadian driver’s license records available for sale, along with millions of other identity documents.
The service, called Nexus, appeared at the end of August and was promoted on the Russian cybercrime forum Exploit. Its operators claimed access to more than 170 million identity records in total, including driver’s licenses, identification cards, travel documents and medical cards.
The scale alone would make this one of the most troubling identity-data exposures in recent years.
But the source of the data may be even more important.
An investigation by cybersecurity journalist Brian Krebs found evidence suggesting that at least some of the driver’s license images may have originated through an identity-verification provider used by businesses to scan and authenticate customer IDs.
The FBI’s New Orleans field office has opened an investigation into an apparent incident involving Louisiana-based ID verification company IDScan.net, Krebs reported. IDScan.net has said it is investigating but, as of this writing, has not publicly confirmed that its systems were breached or that it is the source of the entire Nexus database.
That distinction matters. Nexus’s claim of 153 million driver’s license records remains a claim made by a criminal service, and investigators have not established that those records represent 153 million unique individuals.
What has been established is concerning enough.
Nexus Appeared With an Enormous Collection of Government IDs
Krebs first reported on Nexus on September 1 after a source pointed him to an advertisement on Exploit.
The criminal service claimed to possess more than 153 million driver’s licenses, more than 10 million additional identification cards, over three million travel documents and international IDs, and roughly 579,000 medical cards.
The collection appeared to be heavily weighted toward Americans. A search limited to Canadian driver’s licenses reportedly produced approximately 1.1 million results.
Krebs also tested whether Nexus’s advertised numbers appeared plausible.
A blank search of the service returned roughly 11.5 million pages of records, with about 15 results per page, broadly consistent with the site’s claim that it held more than 153 million driver’s license entries.
The number was not static.
During Krebs’s investigation, the total number of driver’s license records displayed by Nexus increased by nearly 400,000 within approximately 24 hours.
The operators claimed they had been continuously exfiltrating new information for more than a year.
That statement has not been independently verified.
But if the collection was still growing when Nexus became public, investigators will want to determine whether this was an old database being resold or an ongoing compromise that allowed the operators to obtain new ID scans as they were created.
The Records Were More Than Names and License Numbers
This does not appear to have been an ordinary database of names, addresses and driver’s license numbers.
Some records contained actual digital images of the documents.
Krebs found six image files associated with his own driver’s license: multiple front-and-back images, including standard scans and versions captured using infrared and ultraviolet imaging.
Those additional images are important because sophisticated ID-verification systems use UV, infrared, barcodes, microprinting and other document features to determine whether an identification card is authentic.
SecurityWeek reported that Nexus offered more than just driver’s licenses, with the database also containing identification cards, travel documents and medical cards.
For identity thieves, a high-quality image of a genuine government ID can be considerably more valuable than an ordinary identity record.
The document can potentially be used in account takeover attempts, financial fraud, synthetic identity schemes and attacks against know-your-customer systems that ask users to upload identification.
The irony is difficult to miss.
The same type of technology designed to prevent identity fraud may have created extraordinarily valuable identity records if the underlying scans were retained and then compromised.
How Researchers Began Connecting the Records to ID Verification
The source of the Nexus information has not been conclusively established, but Krebs found several clues pointing toward IDScan.net.
He searched Nexus for driver’s licenses belonging to friends and relatives who gave him permission to check.
Nine people whose licenses appeared in the service were able to associate timestamps attached to their images with recent travel or transactions involving presentation of their IDs.
Several had rented vehicles from Hertz.
Krebs found his own license and his mother’s license with timestamps only seconds apart. He said they had handed their driver’s licenses to a Hertz employee at approximately the same time during a June 2025 rental.
Security and privacy researcher Zach Edwards also found his driver’s license in Nexus.
His record contained a timestamp corresponding to a recent trip to Las Vegas.
Edwards had shown his driver’s license at several locations, but told Krebs that the location he knew had electronically scanned it was Planet 13, a marijuana dispensary.
That became another clue.
IDScan.net previously announced that its identity-verification technology was being used by Planet 13 dispensaries. The company says its technology performs identity verification across a wide range of industries.
IDScan.net’s website currently markets products for cannabis businesses, hospitality, automotive businesses, banks, logistics companies, gaming operators, retailers and other industries. The company says its systems conduct more than 21 million identity verifications each month across more than 20,000 locations.
Its document-authentication systems are designed to examine IDs using features including ultraviolet and infrared images, the same types of images found in some Nexus records.
None of those facts, individually or together, conclusively proves that all of the Nexus information came from IDScan.net.
IDScan.net had not confirmed a breach when Krebs published his findings.
The company told Krebs it was investigating and said the information he provided was useful to that investigation.
The FBI Is Now Investigating
The FBI subsequently became involved.
Krebs reported participating in a call with FBI personnel, including senior cyber officials, during which the agency said its New Orleans field office had opened an official investigation into an apparent incident involving IDScan.net.
FreightWaves separately received confirmation from FBI New Orleans.
“The FBI can confirm that it is looking into the incident,” the bureau told the publication, while declining further comment because the investigation remains ongoing.
The Nexus database apparently included identification belonging to federal officials as well.
Krebs reported finding the driver’s license of U.S. Defense Secretary Pete Hegseth and an FBI assistant director among records available through the service.
Shortly after Krebs published his investigation, Nexus disappeared from the dark web.
Its login page was replaced by a message stating that the service was no longer available.
There is currently no public evidence showing that law enforcement caused the shutdown, and taking the original service offline does not mean copies of the underlying data disappeared with it.
The Incident Exposes a Bigger Problem With ID Verification
The Nexus investigation arrives at a time when businesses and governments are asking consumers to prove their identities more often.
Banks conduct KYC checks.
Car rental companies verify driver’s licenses.
Hotels scan identification.
Cannabis retailers verify age.
Online marketplaces perform identity checks.
Social networks and websites are increasingly facing age-assurance and age-verification requirements.
The result is that a government-issued credential that once stayed primarily inside someone’s wallet can now pass through scanners, APIs, cloud services and third-party identity-verification platforms.
Each additional step creates another potential data flow.
That does not mean businesses should abandon identity verification. In many industries, it is legally required or necessary to combat fraud.
But there is a major privacy difference between looking at an ID and creating a permanent digital copy of it.
And there is another difference between verifying an attribute, such as whether someone is over 18, and storing the entire front and back of a driver’s license containing the person’s name, address, date of birth, photograph, license number and other information.
This incident should force companies to revisit that distinction.
Age Verification Is Part of the Debate
The story also lands squarely in the growing debate over online age verification.
Governments around the world are introducing or considering requirements intended to prevent children from accessing pornography, social media platforms and other age-restricted services.
Some verification systems can operate without retaining a government ID. Others may ask users to upload identification documents or send information through specialized verification vendors.
Edwards, who investigated Nexus alongside Krebs, argued that the expanding use of ID checks creates a larger ecosystem of third parties holding extremely sensitive information.
His concern is not that every age-verification system necessarily stores driver’s licenses.
The concern is architectural.
Whenever lawmakers or businesses create new reasons for millions of people to submit identity documents, the security and privacy practices of the intermediaries processing those documents become critical.
The privacy question cannot stop at:
“Did we verify the person’s age?”
Companies also need to ask:
What information did we collect to perform that verification?
Did we retain the underlying document?
Did our vendor retain it?
Was a full driver’s license necessary when an age attribute would have been sufficient?
Who can access the images?
How long are they retained?
Can the information be used for another purpose?
Can a subcontractor access it?
What happens when the commercial relationship ends?
And can the company prove that deletion actually occurred?
Those are data-minimization and vendor-governance questions as much as cybersecurity questions.
A Driver’s License Is Particularly Dangerous Data to Lose
Passwords can be changed.
Credit card numbers can be cancelled.
A driver’s license is different.
The document contains several relatively stable identifiers about a person, and much of the information printed on it does not change after a breach.
Even replacing the physical credential does not change someone’s photograph, birth date or much of the biographical information contained on the previous document.
That can make compromised identity documents useful for a long time.
Larry Baldwin, a cybersecurity researcher interviewed by Krebs, warned that genuine driver’s license images can be used because state-issued licenses remain a common way to prove identity when opening accounts or applying for credit.
He also raised a less obvious risk.
A database containing genuine photographs, addresses and identity documents could create serious physical-safety consequences for people trying to remain difficult to locate, including domestic-violence survivors and others whose whereabouts are particularly sensitive.
Modern facial-recognition technology adds another dimension.
A photograph from a driver’s license is not simply another static image when automated systems can use facial matching to associate it with other photographs and identities.
The Verification Vendor Is Part of Your Privacy Program
The episode also provides a basic lesson for businesses using outside identity companies.
Outsourcing verification does not outsource privacy risk.
An organization may never intentionally store a customer’s driver’s license in its own systems and still create substantial exposure if it sends that document to a vendor that retains it.
That makes vendor diligence particularly important where identity documents are involved.
Companies should know whether their identity provider stores document images or processes them transiently.
They should understand default retention periods rather than assuming data disappears after verification.
Contracts should address retention, deletion, incident notification, subcontractors, security requirements and the customer’s ability to obtain evidence that those requirements are being followed.
Technical settings matter as well.
IDScan.net itself describes its platform as configurable to allow field-level storage and retention settings for personal information.
That is exactly why privacy teams should not treat vendor configuration as a purely technical implementation detail.
If a customer can configure a system to avoid retaining unnecessary identity information but leaves retention enabled, the resulting privacy risk may be substantially different.
Data Minimization Is a Security Control
Privacy professionals often discuss data minimization as a regulatory requirement.
Incidents like Nexus show why it is also a security strategy.
A company cannot lose information that it never collected.
A vendor cannot expose an ID image that it did not retain.
And an attacker cannot exfiltrate years of historical identity documents if those documents were deleted after the purpose for which they were originally collected was completed.
There will be legitimate circumstances where retention is necessary.
But “we might need it later” is not a meaningful retention policy for a database of government identification.
Businesses should be able to explain why the document is stored, how long it is needed and what event causes it to be deleted.
That analysis should extend through the vendor chain.
Consumers Should Assume Stolen IDs Can Be Used for More Than One Attack
The FBI’s general identity-theft guidance advises consumers to monitor financial accounts and credit reports and consider placing a fraud alert or credit freeze with the major credit bureaus.
A credit freeze is particularly useful because a driver’s license scan may provide criminals with information they can use when attempting to open new accounts.
But financial fraud is not the only concern.
People should be cautious about unexpected account-recovery requests, phone calls, emails or messages from companies claiming there is a problem with their identity.
An attacker possessing an authentic driver’s license image may already know someone’s legal name, address, birth date and other details normally used to make a social-engineering attempt appear legitimate.
Consumers can also begin asking a simple question when a business wants to scan their ID:
Does the company need to store a copy, or does it only need to verify it?
Those are not the same thing.
What We Still Don’t Know
Several major questions remain unanswered.
It has not been confirmed that IDScan.net is the source of the entire Nexus database.
The advertised total of 153 million driver’s license records has not been independently verified as 153 million unique people.
It is not known whether the same person may appear multiple times because their ID was scanned on different occasions.
Investigators have not publicly disclosed how the information was allegedly obtained.
And there has been no public confirmation that the Nexus operators truly maintained the continuous access they claimed.
Those distinctions matter, particularly at this stage of an active FBI investigation.
But none of them eliminates the central privacy issue.
A criminal service appears to have assembled an enormous collection of genuine government identity documents that people handed over in circumstances where they believed their identities were simply being verified.
The investigation will eventually determine how those documents got there.
For privacy teams, the more immediate question is whether their own organizations know what happens to an ID after a customer hands it over.
Because “we use a third party for verification” is not an answer.