The Scale of the Breach
A dark web service dubbed Nexus has put more than 153 million driver licenses from the U.S. and Canada up for sale. That’s not a typo. The service also claims to hold over 10 million ID cards, 3 million travel documents, and nearly 580,000 medical cards.
To put that number in perspective, a blank search on Nexus returns roughly 11.5 million pages of results. Most records belong to Americans, but Canadian licenses are also well represented, with Ontario alone accounting for over 473,000 entries.
The data appears to be fresh, too. In a single 24-hour window, the service added nearly 400,000 new driver license records. That suggests a live pipeline of stolen information, not a one-time dump.
The Likely Source: idscan.net
KrebsOnSecurity, which first reported the story, traced the likely origin to idscan.net, a Louisiana-based identity verification company. The firm’s own marketing materials boast of scanning IDs with both infrared and ultraviolet light—a detail that matches the image files found in Nexus.
Each license record in the service includes up to six images: front and back scans, plus infrared and ultraviolet versions. Timestamps on those files line up with specific travel dates for individuals who agreed to help with the investigation.
idscan.net has acknowledged the inquiry but hasn’t released a formal statement. Jillian Kossman, a marketing and operations leader at the company, told KrebsOnSecurity that the updates were “helpful to our team’s investigation,” but offered no further details.
How the Data Was Collected
At first, the trail pointed to airports. Many of the timestamps matched days when people had flown. But that theory fell apart quickly. No passports appeared in the dataset, and some victims hadn’t flown at all recently.
One person whose license was found in Nexus had been renting a car from Hertz for months. Two federal employees who used other ID at airport security later handed over their driver licenses at Hertz rental counters—on the exact dates stamped on their records.
Even more telling: a mother and son who rented a car together had timestamps just seconds apart. Both had given their licenses to the same rental agent at the same time.
Hertz hasn’t commented publicly, but the pattern is hard to ignore. idscan.net’s own trust page lists Hertz as a client, along with Target, FedEx, and Caesars Entertainment.
Not Just Rental Cars
Rental cars aren’t the only vector. Security researcher Zach Edwards found his license in the service with a timestamp from a Las Vegas trip. He didn’t rent a car, but he did visit Planet13, a marijuana dispensary that uses idscan.net for ID verification.
Edwards noted that the dispensary was the only place that scanned his ID in a device. Planet13 has locations in several states, and idscan.net announced an exclusive verification deal with the chain back in 2022.
Marijuana dispensary cards also appear in the dataset, which suggests a wide net of ID-scanning clients may have been compromised.
FBI Opens Investigation
The FBI’s New Orleans field office has launched an official inquiry into the apparent breach. That news came during a conference call with KrebsOnSecurity and senior FBI cyber division leaders.
The investigation reportedly involves idscan.net, though the FBI hasn’t confirmed specifics publicly. The agency’s interest is understandable—the service even lists driver licenses for high-ranking government officials, including Defense Secretary Pete Hegseth.
Notably, the Nexus site vanished from the dark web shortly after the story broke, replaced by a message reading “This service is no longer available.” Whether that’s a shutdown or a move to cover tracks remains unclear.
Why This Matters
Driver licenses are a goldmine for identity thieves. They’re commonly used to open credit lines, verify accounts, and even pass age checks. Unlike a credit card number, you can’t just cancel a driver license and get a new one.
Larry Baldwin, a principal intelligence researcher at Cybera, warned that the leak could expose people who can’t easily change their appearance—including domestic violence survivors and those in witness protection. “Just when it seems like we’re making some headway in improving authentication controls,” he said, “this happens.”
For everyday consumers, the takeaway is grim: every time you hand over your ID to a hotel, rental car agency, or dispensary, you’re trusting a chain of third-party vendors with your most sensitive data. As Edwards put it, “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”
If you’re concerned about your own exposure, it’s worth checking whether your information appears in known breach databases. And as always, monitor your credit reports for suspicious activity. This story is still developing, and we’ll update as more details emerge.