Massive Dark Web Breach Exposes Over 153 Million North American Driver’s Licenses Tied to Identity Verification Giant

Share
Massive Dark Web Breach Exposes Over 153 Million North American Driver’s Licenses Tied to Identity Verification Giant

Executive Overview

In what cybersecurity experts are calling one of the most alarming digital identity leaks in recent history, a newly launched dark web platform has begun offering digital scans of more than 153 million driver’s licenses and government-issued identification cards belonging to residents of the United States and Canada.

The illicit marketplace, operating under the moniker Nexus, surfaced on prominent Russian-language cybercrime forums, boasting a sprawling repository of personal data that includes tens of millions of state IDs, international travel documents, medical cards, and commercial driver’s licenses. High-ranking U.S. government officials, including Defense Secretary Pete Hegseth and high-profile cybersecurity researchers, have been identified among the exposed records.

An independent investigative deep-dive points the finger at idscan.net, a Louisiana-based identity verification provider whose enterprise software powers security checkpoints, car rental agencies, major hotel chains, and retail cannabis dispensaries globally. Following investigative inquiries and outreach by security journalists, the Federal Bureau of Investigation’s (FBI) New Orleans field office swiftly launched an official inquiry into the security failure.

While the Nexus dark web portal went offline shortly after initial public disclosures, the incident has exposed foundational vulnerabilities in the modern security ecosystem—specifically, the widespread corporate collection and retention of biometric and photographic identity documents under the banner of customer verification and regulatory compliance.


Detailed Chronology: Unraveling the Nexus Operation

The Discovery on the Dark Web

The incident came to light when a threat intelligence source alerted cybersecurity journalist Brian Krebs to a service advertised on Exploit, a Russian cybercrime forum. The threat actor behind Nexus was offering access to digital scans of identity documents spanning more than 170 million individuals across North America. To prove the legitimacy of their inventory, the proprietor included a free, high-resolution sample file in the initial sales thread: the Virginia driver’s license of the journalist himself.

Dubbed Nexus, the platform claimed to house over 153 million U.S. and Canadian driver’s licenses, alongside more than 10 million state identification cards, 3 million international travel documents, and roughly 579,000 medical cards.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

A preliminary database query corroborated the immense scale of the breach. Running an unconstrained search query on Nexus yielded roughly 11.5 million result pages with approximately 15 records per page. While records covered both nations, the vast majority targeted U.S. citizens, supplemented by over 1.1 million Canadian profiles—led heavily by the province of Ontario with more than 473,000 records.

Tracing the Trail: From Car Rentals to Cannabis Dispensaries

Determined to uncover the origin of the stolen data, researchers conducted empirical testing by cross-referencing records of friends, family members, and industry peers against the Nexus database.

Each individual whose license appeared in the breach confirmed having traveled or engaged in transactions matching the precise date and timestamp appended to their image files. By analyzing car rental records and travel itineraries, researchers deduced that the timestamps—set to Greenwich Mean Time (GMT)—directly correlated with moments when individuals presented their physical IDs for scanning at third-party commercial locations.

  • The Hertz Connection: Multiple victims discovered their records featured timestamps matching car rental counters. In one instance, a mother and son who handed their physical driver’s licenses to a Hertz rental representative simultaneously found that their respective image files shared virtually identical timestamps, spaced mere seconds apart.
  • The Dispensary Scanning Ecosystem: Zach Edwards, a privacy researcher and founder of DecryptAds, found his license listed on Nexus. His timestamp traced back to a trip to Las Vegas for the annual DEFCON security conference. While Edwards visited multiple venues, he noted that the only establishment that explicitly passed his ID through an electronic document reader was Planet13, a multi-state cannabis dispensary chain.

Planet13 utilizes identity verification infrastructure provided by idscan.net, a Louisiana-based enterprise specializing in automated ID authentication and age verification technology.

The Scale and Sophistication of the Exfiltration

The architecture of the stolen records revealed a high degree of technical capture. Many profiles contained six distinct image files: front and back standard scans, alongside specialized infrared and ultraviolet (UV) versions of the documents. These advanced optical layers indicate that the data was harvested directly from professional-grade document-reading hardware—such as the multi-spectral scanners deployed by idscan.net—rather than simple smartphone snapshots or low-resolution photocopies.

Furthermore, the database was actively expanding. Within a single 24-hour window following its initial discovery, the total count of available driver’s license records on Nexus surged by nearly 400,000, confirming that the underlying exfiltration pipeline was automated, recurring, and potentially still active at the time of discovery.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Supporting Context & Metrics: The Anatomy of a Mega-Breach

Breakdown of Compromised Assets

The sweeping variety of identification formats found within Nexus indicates a sweeping, indiscriminate harvest of identity verification logs. The catalog included:

  • Driver’s Licenses (U.S. & Canada): 153,000,000+ records
  • State Identification Cards: 10,000,000+ records
  • International Travel / Passports: 3,000,000+ documents
  • Medical & Cannabis Dispensary Cards: 579,000+ records
  • Commercial Driver’s Licenses (CDL) & Common Access Cards (CAC): Thousands of federal and commercial security profiles.

The Central Infrastructure: idscan.net

Headquartered in New Orleans, idscan.net markets its technology as an advanced compliance and fraud-prevention tool. According to the company’s public documentation, its systems process upwards of 21 million identity verifications monthly across more than 20,000 client locations globally.

The company’s clientele list historically included prominent corporate giants spanning various sectors, such as Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. However, the breadth of these integrations meant that millions of everyday consumers unknowingly handed over high-security biometric-grade scans of their driver’s licenses to third-party corporate servers every time they rented a car, checked into a hotel, or purchased age-restricted goods.


Official Statements & Institutional Response

As news of the breach cascaded through the cybersecurity community, federal law enforcement and corporate entities scrambled to respond.

The Federal Bureau of Investigation (FBI) Step-In

During the course of investigative reporting, it was discovered that Nexus was actively hosting the driver’s license records of high-ranking federal officials, including U.S. Defense Secretary Pete Hegseth and assistant directors within the FBI.

Prompted by these revelations and direct investigative queries, the New Orleans field office of the FBI formally opened an official inquiry into idscan.net. Federal cyber division agents convened briefings to coordinate an investigation into how threat actors managed to siphon terabytes of multi-spectral identity documents over what the hackers described as "a period of over a year."

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Corporate Acknowledgments and Retractions

  • idscan.net Response: Following initial outreach, Jillian Kossman, a marketing and operations leader at idscan.net, acknowledged that the company was conducting an internal investigation. On September 8, idscan.net published an official security notification confirming that an "unauthorized third party may have accessed and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers." The firm began notifying affected individuals and offering credit monitoring services.
  • Caesars Entertainment Clarification: Following the publication of idscan.net’s partner list, a spokesperson for Caesars Entertainment issued a strict clarification stating that Caesars had ceased using IDScan’s VeriScan software in February 2025 and maintained no active accounts during the timeframe of the breach, asserting that the incident should have no operational impact on their properties.

The Sudden Disappearance of Nexus

Hours after initial investigative reports went public, the dark web infrastructure underpinning Nexus abruptly vanished. Visitors attempting to access the platform’s login gateway were greeted by a stark plain-text message:

"This service is no longer available."

Despite the portal going dark, security researchers warn that the 153 million records have likely already been mirrored, downloaded, or distributed across private buyer circles within underground Russian cybercrime forums.


Future Outlook: Implications for Privacy and Digital Identity

The Nexus breach marks a watershed moment in the ongoing debate over digital surveillance, identity verification mandates, and corporate data hoarding. Security professionals argue that the incident underscores the inherent risks of forcing citizens to surrender sensitive physical identity documents to an unregulated web of third-party vendors.

Growing Backlash Against Mandatory ID Verification

Zach Edwards emphasized that the incident should serve as a stark warning to legislators pushing for mandatory age-verification and identity-checking regimes online:

"This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids. These systems are putting sensitive data into more and more third-party vendors, and we don’t have nearly the oversight to ensure they are safe."

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Severe Real-World Dangers

Larry Baldwin, principal intelligence researcher at Cybera, underscored the profound downstream dangers of a compromised driver’s license dataset of this magnitude. Unlike credit card numbers—which can be easily canceled and reissued—a compromised state-issued driver’s license, complete with front, back, infrared, and ultraviolet scans, represents permanent biometric and demographic exposure.

Baldwin pointed out that such troves are routinely utilized by sophisticated fraudsters to bypass biometric liveness checks, establish fraudulent lines of credit, and impersonate victims in financial systems. Most critically, the leak poses an existential threat to vulnerable populations who rely on anonymity for physical safety, including survivors of domestic violence and individuals enrolled in federal witness protection programs whose physical identities cannot easily be altered to fool AI-driven image-matching software.

A Broken Trust Paradigm

The exposure of 153 million North American identities shatters the illusion of security surrounding commercial data collection. As regulatory bodies step up scrutiny and federal investigators comb through the digital wreckage of idscan.net, the fundamental question facing the digital economy remains: If multi-billion-dollar verification networks cannot secure the very documents used to prove our identities, who protects the public from the systems built to protect them?

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *