Dark Web Identity Theft Service Selling 153 Million Driver’s Licenses Linked to IDScan.net Breach
- An identity theft service operating on the dark web has leaked and offered for sale digital scans of more than 153 million driver's licenses belonging to individuals in...
- The Nexus service appeared on the Russian cybercrime forum Exploit on Aug.
- Independent researchers and journalists analyzing the database found that specific timestamps on the stolen files correlate directly with recent travel dates and car rentals.
An identity theft service operating on the dark web has leaked and offered for sale digital scans of more than 153 million driver’s licenses belonging to individuals in the United States and Canada, according to security researcher Brian Krebs. The service, named Nexus, is allegedly siphoning images collected by Louisiana-based identity verification company IDScan.net. The Federal Bureau of Investigation’s New Orleans field office launched an official inquiry into the source of the data after high-ranking U.S. government credentials, including the driver’s license of U.S. Defense Secretary Pete Hegseth, appeared in the database.
Nexus Dark Web Service Details and Scale
The Nexus service appeared on the Russian cybercrime forum Exploit on Aug. 31, advertising access to identity documents for more than 170 million North Americans. According to findings from KrebsOnSecurity, a blank search of the platform returns roughly 11.5 million pages containing about 15 results each, confirming the immense scale of the data set. The compromised records include more than 153 million driver’s licenses, over 10 million identification cards, more than three million travel documents or international IDs, and at least 579,000 medical cards.
Beyond standard state driver’s licenses, the database houses commercial driver’s licenses, marijuana dispensary cards, and Common Access Cards used to access secure government buildings. Operators behind Nexus claimed in their initial forum post that they have been exfiltrating new records into a private database for over a year. Within a 24-hour window, the platform added nearly 400,000 new driver’s license records, indicating active, ongoing harvesting operations.
Investigation Points to IDScan.net
Independent researchers and journalists analyzing the database found that specific timestamps on the stolen files correlate directly with recent travel dates and car rentals. Security researcher Zach Edwards identified his own driver’s license in the Nexus system, noting that the timestamp matched a trip to Las Vegas where he scanned his ID at a cannabis dispensary. Records verified by multiple individuals confirmed that timestamps matched dates when they handed physical IDs to rental car representatives or verified age at commercial locations.
The connection leads directly to IDScan.net, a New Orleans-based identity verification provider. According to the company’s official documentation, IDScan.net processes verifications for more than 1,000 marijuana dispensaries across 19 U.S. states and counts major brands such as Hertz, Target, FedEx, Motorola Solutions, and Caesars Entertainment among its clients. The technology utilizes specialized infrared and ultraviolet light scanning, matching the specific multi-image formats found within the Nexus leak.
Caesars Entertainment spokesperson stated that the company has not been a client of IDScan.net and stopped using VeriScan software in February 2025, maintaining no active accounts or authorization for data retention at the time of the incident. IDScan.net acknowledged the security event in a statement on Sept. 8, confirming that an unauthorized third party accessed and copied customer information, including full names and government-issued identification numbers.
At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.
Jillian Kossman, IDScan.net
Security Implications and Regulatory Fallout
Cybersecurity professionals warn that the exposure of 153 million state-issued driver’s licenses creates severe risks for financial fraud and targeted identity theft. Larry Baldwin, principal intelligence researcher at Cybera, noted that driver’s licenses are frequently used as primary proof of identity for opening new lines of credit. Baldwin emphasized that the leak endangers vulnerable populations, including individuals fleeing domestic violence and persons protected under federal witness security programs who cannot easily change their facial features to evade AI-based image-matching tools.
Following inquiries from researchers, the Federal Bureau of Investigation initiated a formal investigation through its New Orleans field office. Zach Edwards argued that the breach highlights the dangers of corporate data collection practices under the guise of security.

This incident should bolster the determination of individuals opposing internet identification programs that force numerous companies to request drivers licenses for service access under the pretense of child safety. Such networks channel confidential records into an expanding pool of 3rd party vendors, while lacking adequate oversight to guarantee their protection.
Zach Edwards, Security and Privacy Researcher
Shortly after initial reporting on the database went public, the Nexus website on the dark web went offline, replacing its login portal with a brief message stating that the service is no longer available. IDScan.net stated it is currently notifying affected individuals and providing credit protection services.
