Dark Web Service Sells 153 Million US and Canada Driver’s Licenses in Major IDScan Breach
FBI Launches Inquiry into Service Selling 153M+ Drivers Licenses Linked to IDScan.net
The Federal Bureau of Investigation’s New Orleans field office launched an official inquiry following the appearance of a dark web service advertising digital scans of more than 153 million driver’s licenses and identification documents belonging to individuals in the United States and Canada, according to information confirmed by KrebsOnSecurity on September 1, 2026. The identity theft service, known as Nexus, surfaced on the Russian cybercrime forum Exploit on Monday, August 31, boasting a database that included records for high-ranking government officials, including U.S. Defense Secretary Pete Hegseth.
The Tech TL;DR:
- The Incident: A dark web platform named Nexus began offering over 153 million North American driver’s license scans, allegedly sourced from an active breach at a major verification vendor.
- The Investigation: The FBI’s New Orleans field office opened an official inquiry focusing on Louisiana-based identity verification provider idscan.net.
- The Impact: Victims and security researchers confirmed that infrared, ultraviolet, and standard image scans matched precise travel and rental car timestamps dating back to June 2025.
Anatomy of the Nexus Leak and Infrastructure
The Nexus service operators claimed in their introductory Exploit forum post that they had been continuously exfiltrating data into a private database for over a year. A blank search of the Nexus platform returned approximately 11.5 million pages of results with roughly 15 items per page, confirming the massive scale of the repository. While records included U.S. and Canadian documents—such as 1.1 million Canadian records, heaviest in Ontario with 473,673 entries—the dataset also incorporated marijuana dispensary cards, commercial driver’s licenses (CDL), and Common Access Cards (CAC) used for physical access to secure government facilities.
Security researcher Zach Edwards, founder of DecryptAds, discovered his own driver’s license for sale on the platform with a timestamp matching a trip to Las Vegas for the DEFCON conference. Edwards noted that while he passed through TSA checkpoints and visited hotels, the only entity that physically scanned his ID through a specialized device was Planet13, a cannabis dispensary chain utilizing identity verification technology provided by idscan.net. Public documentation from idscan.net states that the firm handles identity checks for over 1,000 dispensaries across 19 states, processing upwards of 21 million verifications monthly across more than 20,000 global locations.
Timestamps, Cryptographic Evidence, and Vendor Exposure
Independent analysis of individual records retrieved from Nexus revealed rigorous multi-spectral imaging files. Each compromised profile frequently contained six distinct image assets: standard front and back scans, basic image files, along with infrared and ultraviolet versions. Timestamps appended to these files aligned precisely with real-world travel events. For instance, investigative reporting by Brian Krebs verified that his own driver’s license scan carried a timestamp corresponding to a June 2025 flight to the Midwest, a date confirmed via airline and calendar records.
Further correlation emerged when family records were analyzed. A separate record belonging to Krebs’s mother showed a timestamp separated by only a few seconds from his own, matching the exact moment both individuals handed their physical identification cards to a Hertz rental car counter representative. Larry Baldwin, a principal intelligence researcher at Cybera, similarly identified a front and back scan of his driver’s license tied to a recent Hertz car rental timestamp. When software engineering teams and enterprise IT architects evaluate third-party vendor integrations, incidents like this underscore the extreme risks associated with sprawling API-driven identity pipelines and cloud database retention policies.
On September 8, 2026, idscan.net issued a formal notice confirming that an unauthorized third party may have accessed and copied customer information, including full names and government-issued identification numbers. Meanwhile, a spokesperson for Caesars Entertainment clarified that Caesars had not been a client of IDScan.net and had not used VeriScan since February 2025, maintaining no active accounts at the time of the incident despite prior vendor listings. Shortly after initial reporting went live, the Nexus dark web portal replaced its login page with a plaintext message declaring the service no longer available.
Enterprise Risk Mitigation and Directory Triage
The exposure of 153 million identity documents presents severe downstream vectors for credential stuffing, synthetic identity fraud, and account takeover attacks. Because state-issued driver’s licenses serve as primary verification tokens for opening financial lines of credit, corporate security teams must immediately audit identity verification subprocessors. Organizations should coordinate with vetted cybersecurity auditors and penetration testers to evaluate third-party API data hygiene, storage encryption standards, and retention lifecycles.
Furthermore, consumer privacy advocates point out that regulatory pushes requiring identity verification for online services are compounding systemic risk by funneling sensitive data into disparate vendor environments. To harden internal systems against upstream supply chain compromises, engineering leaders are urged to partner with enterprise compliance and IAM consultants to implement zero-trust data minimization frameworks.