A newly launched identity theft operation on the dark web has begun selling high-resolution digital scans of more than 153 million driver’s licenses belonging to individuals across the United States and Canada. Investigative reporting, corroborated by interviews with multiple affected individuals, indicates that the massive cache of sensitive records is being siphoned directly from an active data breach at a prominent, widely utilized identity verification company headquartered in Louisiana. The unfolding situation has already triggered an official federal response, with the Federal Bureau of Investigation’s New Orleans field office launching a formal inquiry into the source of the compromised documents.
The illicit operation first came to light when a source alerted cybersecurity journalist Brian Krebs to a service advertised on the Russian-language cybercrime forum Exploit. The threat actor, operating under a newly registered account, was promoting access to digital identification documents covering more than 170 million North Americans. Notably, the proprietor of the service used Krebs’ own Virginia driver’s license as a promotional free sample within their initial sales thread on the forum, prompting an immediate deep-dive investigation into the origins of the leak.
Dubbed "Nexus," the dark web service boasts an inventory consisting of more than 153 million driver’s licenses from the United States and Canada, alongside more than 10 million identification cards, upwards of three million travel documents and international IDs, and at least 579,000 medical cards. A preliminary examination of the platform suggests these staggering numbers are entirely accurate. Running an unconstrained, blank search on the Nexus platform yields approximately 11.5 million pages of results, with roughly 15 records displayed per page. While the dataset includes individuals from both countries, the vast majority of the files pertain to U.S. citizens, though searches for Canadian licenses alone return roughly 1.1 million results, with the highest concentration originating from Ontario.
Beyond standard driver’s licenses, the repository includes niche credentials such as marijuana dispensary customer cards. Some records bear internal source notations like "CDL"—presumably designating commercial driver’s licenses—while others are marked "CAC," an acronym that typically refers to Common Access Cards, which are government-issued identity credentials used to secure physical entry into federal buildings and restricted military installations. Highlighting the scale and sensitivity of the breach, the searchable database features identity records belonging to prominent high-ranking U.S. government officials, including U.S. Defense Secretary Pete Hegseth.

The threat actors behind Nexus claim the trove of high-definition license images originates from an ongoing security breach at a major identity verification provider whose corporate clientele includes multiple Fortune 500 companies. In their introductory post on the Exploit forum, the operators boasted that they had been continuously exfiltrating fresh data into a private database for over a year. They noted that records can be previewed prior to purchase with sensitive fields redacted, while customer photographs remain visible whenever available. The dynamic nature of the leak is underscored by rapid updates to the platform; within a single 24-hour window, the number of available driver’s license records surged by nearly 400,000, indicating that newly harvested credentials are being uploaded to the service on a regular, automated basis.
A forensic examination of the file structures associated with the compromised records reveals an alarming level of detail. Files tied to specific individuals frequently contain multiple image assets, including front-and-back photo pairs, standard digital scans, and specialized infrared and ultraviolet versions of the documents. Each image file appends precise date and timestamp metadata. For instance, the record matching Krebs’ personal profile contained six distinct image files with timestamps corresponding directly to a flight he took to the American Midwest in June 2025 to attend a family funeral.
Determined to trace the vector of the breach, researchers interviewed more than a dozen friends and family members who consented to have their names searched within the Nexus service. Every single person whose record was successfully retrieved—totaling nine individuals—confirmed that the timestamps on their respective files precisely matched dates when they had traveled or engaged in specific in-person transactions. Cross-referencing travel logs and car rental agreements provided by participants suggested the timestamps were recorded in Greenwich Mean Time (GMT).
Initial hypotheses that the data might have been harvested at commercial airports were quickly dismissed. The dataset conspicuously lacks passport scans, and several individuals whose driver’s licenses appeared on Nexus had not flown recently. Notably, one affected individual had not boarded an aircraft at all during the relevant timeframe, but had spent several months renting a vehicle through Hertz around the date indicated by their file’s timestamp. Furthermore, federal employees participating in the research noted that while they used alternative government-issued credentials at airport security checkpoints, they subsequently presented their state driver’s licenses later that same day when renting cars at their travel destinations through Hertz.

The investigative trail solidified when examining a dual record belonging to Krebs and his mother. Both of their files featured timestamps mere seconds apart, corresponding precisely to a moment when they simultaneously handed their physical driver’s licenses to a Hertz rental car representative behind a service counter to sign paperwork. While it remains unconfirmed whether the rental agent passed the physical cards through a dedicated scanning terminal, the physical handling of the documents provided a clear convergence point. Hertz was subsequently contacted for comment regarding the incident.
The scope of the breach expanded as other prominent privacy and security researchers discovered their own credentials listed on the platform. Zach Edwards, a security researcher who recently launched the tracking-awareness service DecryptAds, found his driver’s license available for purchase on Nexus. The timestamp on Edwards’ record aligned directly with a trip he took the previous month to Las Vegas for the annual DEFCON security conference. While Edwards did not rent a vehicle during his stay, his itinerary included presenting his identification at a TSA checkpoint, checking into his hotel, and visiting a local marijuana dispensary.
Of those locations, Edwards confirmed that the dispensary was the only establishment that explicitly inserted his physical ID card into an automated electronic scanning device. The dispensary in question was Planet13, a multi-state retail chain operating locations in states including California, Florida, Illinois, and Nevada. Public records indicate that in 2022, a New Orleans-based identity verification provider known as idscan.net announced an exclusive enterprise agreement to handle identity verification services for Planet13 dispensaries nationwide. IDScan.net reportedly processes identity checks for more than 1,000 cannabis dispensaries across 19 states.
According to its corporate documentation, idscan.net provides identity verification infrastructure for numerous major brands and institutions, including Hertz, Target, FedEx, Motorola Solutions, financial services provider Jack Henry, and Caesars Entertainment. The company’s technology utilizes advanced hardware capable of scanning identification documents under both infrared and ultraviolet light to detect counterfeits. Idscan.net boasts that its systems process more than 21 million verifications every month across upwards of 20,000 locations globally.

When initially contacted by journalists, representatives for idscan.net stated that the company was actively investigating the matter. Jillian Kossman, a marketing and operations leader at idscan.net, acknowledged the reports, noting that the external insights provided helpful context for the company’s internal incident response team.
As investigative efforts pressed forward, word of the probe reached federal law enforcement agencies, reportedly catalyzed when researchers noted that Nexus was also offering the driver’s license information of an assistant director of the FBI. Senior leaders from the FBI’s cyber division confirmed that the agency’s New Orleans field office had formally opened an official investigation into the security incident involving idscan.net.
Security experts have expressed deep concern over the implications of the breach. Zach Edwards emphasized that the widespread corporate mandate requiring consumers to surrender sensitive government-issued identification documents under the guise of security or age verification creates unnecessary systemic risk. By funneling millions of high-resolution identity scans through third-party vendors with inadequate oversight, the digital ecosystem exposes citizens to long-term fraud vectors.
Larry Baldwin, principal intelligence researcher at the cybersecurity firm Cybera, whose own driver’s license scan appeared on Nexus complete with timestamps matching a recent car rental vacation, warned that the service represents an acute threat to public safety. State-issued driver’s licenses are foundational documents commonly utilized as primary verification when opening lines of credit, securing loans, or verifying identity online. Baldwin pointed out that the exposure poses a severe danger to vulnerable populations who cannot easily alter their physical appearance to bypass automated facial recognition tools, including individuals fleeing domestic violence and participants in federal witness protection programs.

Following the initial wave of reporting, idscan.net published a formal notification addressing the data security incident. The company acknowledged that an unauthorized third party may have accessed or exfiltrated customer information, including full names, driver’s license numbers, and other government-issued identification details. The firm stated that it had begun notifying affected individuals and extending offers for credit protection services.
Meanwhile, representatives for Caesars Entertainment clarified that the hospitality giant had not maintained an active client relationship with IDScan.net, noting that its accounts with the verification provider had been terminated in February 2025 and that no active systems were in use at the time of the security breach.
Shortly after initial news reports went live, the Nexus identity theft portal abruptly vanished from the dark web. The platform’s login interface was replaced with a plain text notice simply reading, "This service is no longer available." Federal investigations into the source, distribution, and ultimate impact of the massive data compromise remain ongoing.
Leave a Reply