A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale.
On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.
The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.
A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).
Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards. Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.” Other records carry the source notation of “CAC,” which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms.
The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.

The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.
“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”
Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.
The record that features my drivers license includes six image files — three pairs of photos of the license’s front and back — a basic image scan — as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.

Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames. Not all records include photos, and some that do feature photos do not display the associated filenames.
Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).
At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp.
Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz.
After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport.
Here’s where it gets interesting: I was able to find my mother’s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.
According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don’t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply.
Zach Edwards is a well-known security and privacy researcher who recently launched a service called DecryptAds to help people better understand how online advertisers are tracking them. A scan of Edwards’s drivers license is available for purchase on this identity theft service, and Edwards said the timestamp on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference.
Edwards told KrebsOnSecurity that although he did not rent a car in Vegas, he did hand over his license at the TSA checkpoint, at a marijuana dispensary in Vegas, and at his hotel (the Aria). But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary.

To enter Planet13’s weed dispensary in Las Vegas, one must pass through a red telephone booth. Image: Zach Edwards.
Edwards said the dispensary he visited that day was Planet13, a multi-state chain with stores in California, Florida, Illinois and Nevada. In 2022, the New Orleans-based identity provider idscan.net published a press release announcing an exclusive identity verification agreement with Planet13’s dispensaries nationally. IDScan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states.
The “trust” page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, Target, Fedex, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment. And as idscan.net’s own documentation states, the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.

Image: idscan.net.
Contacted by KrebsOnSecurity, idscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email.
“At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” wrote Jillian Kossman, a marketing and operations leader at idscan.net.
During the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft service’s data. Probably they were tipped off when I shared with a trusted source that Nexus also is selling the drivers license information for the assistant director of the FBI (I did not find FBI Director Kash Patel’s license in Nexus).
Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.
Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.
“This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”
Larry Baldwin is principal intelligence researcher at the cybersecurity firm Cybera. Baldwin said a front and back scan of his drivers license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation.
Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).
This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.
“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.
Update, Sept. 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment said Caesars has not been a client of IDScan.net and has not used VeriScan since February 2025, despite IDScan.net listing them as a client on their website. That person said Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, and that IDScan.net said the incident should have no impact on Caesars Entertainment.
Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp.

My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account. I told them there was no way for someone to have my driver’s license, as it never leaves my sight, but they refused to believe that it wasn’t somehow my fault.
I also purchased a used vehicle from Hertz last year, so this is extremely validating. Please let me know if I can provide any helpful info to get to the bottom of this.
The scale here keeps getting harder to wrap your head around – 153 million driver’s license records changes the math on how much damage a single leak can do downstream. What I find striking is how quickly these aggregation services turn a batch of stolen PII into a routine product with tiers and bulk pricing, as if the supply side had normalized the whole thing. Fingers crossed the FBI probe lands accountability on the people reselling the data and not just on the original breach.
There’s no closing Pandora’s box. It won’t matter if they catch the people doing it and the people reselling, there are now tens of thousands of people with this database.
Actually, the seeds for this kind of thing are more political. Large corporations have sway with campaign contributions and affiliate ways to get legislation and laws in their favor. In the case of Hertz Global Holdings, you’re looking at a $2.4B quarter ending June 30, 2026. With that kind of financial power, similar to (fill in the blank corporation B, C, etc.) the wage slaves at the counter will follow orders and most people have a tendency to comply because they just want to get on their way. However you slice it, third party outsourcing is the biggest vulnerability in the modern age, and joined at the hip to executive cost-cutting bonuses. The concept of privacy left the room in the 20th century.
Thank you for your research and writing this article. I’m shocked and appalled at how much of our personal info is available on the web! I was recently cyber stalked by a neighbor from home that we had moved from a year ago. She was a schizophrenic that got our new neighbors email addresses and sent malicious emails about us to every neighbor up and down the street of our new home. How did she get this info? I Google searched my name and was shocked at my personal info being on the web. So, I had Google clean it up and the big plus is all the spam calls stopped! Thanks again for the work you do and this article.
Data brokers need to be put into a rocket and fired into the sun.
There is a difference between this and data brokers. Anyone who can tell the difference between “data” and PII useable to take over an identity can tell you that. Hell, your own Christmas address book is ‘data brokering’ the minute you sit down with it to send out your yuletide cards,
This is grotesque sh%t.
That’s like saying there’s a difference between the p*do preying on 5 year olds and the one preying on 12 year old. Sure, they’re different, but they both belong on the other side of the grass. Look up the NPD guy. He’s a serious pos and NPD has caused a LOT of people to experience identity theft.
So mostly legit data brokers should be given supplies for their trip to burn up on the sun, and these folks should die of dehydration on the way?
A data broker is a specific business entity whose primary commercial model is to collect, aggregate, and license or sell personal data to third parties. Using an address book to address Christmas cards is not data brokering.
This is crazy, and infuriating that there is almost no mainstream coverage of this incident. Actually, since the image of Hegseth or you (Krebs) on the Nexus screenshots are what is being widely shared, people are commenting that its ‘no big deal’ that a tiny face pic has been leaked.
Wsb-tv in atlanta featured a story on your report and said there was a way to check and see if your license was compromised, however, i find no mention of how to check, any ideas?
Not sure where they got that information, but the site as far as I know is currently offline, and nobody I know has a copy of their database.
I am amazed at your stories – thanks for posting them and teaching us. These are all simply my opinions.
A warning for Ontario. My cable service came up for renewal a few months back. I was visited by no less than seven (!!!!) door-to-door sales people offering cheaper service with a different provider. (How did they know I was up for renewal I wondered.) I was tempted to sign up with one visit. We were doing fine until he said I will need a photocopy of your drivers licence – front and back to email (SMTP no less) with the application.
I said that is not happening – how do we get around it. He said no way. I stood up and said goodbye to them and didn’t sign up. Years ago my drivers licence “apparently” was stolen by a couple of European cousins who were here when it went missing. I had no proof and could not believe it happened so I let it go.
On the way out the door I asked for the cable provider IDs of the two people here. He forgot it at the office apparently. The other person had something face down on his waist that he flashed at me when I asked. It said ‘trainee”. Searching google for fake cable door-to-door ( sometimes known as slamming from a decade ago) brought up a recent case in Vancouver and one in Ontario investigated by police if I recall correctly.
I once reported to a bank internal security department that someone in their branch requested over the phone my access card PIN number. When I told the person that is a security violation – the requester freaked out and so I told them I would let it go. When I reported this, the bank security “professional” had to ask someone else while I was on hold if they could request my pin to verify my ID! She eventually came back and shouted back at me the correct answer. She. didn’t know the correct answer!
My first intranet application was in 1998. I was one of the top people on call during Y2K. I know a little bit about the subject.
When I worked decades ago I used to warn people – nothing and I mean nothing at all is safe on the internet. In my view, a little paranoia is a very useful thing for a security professional to have. Trust broken is not easily re-gained.
Has any determination been made yet as to when the breach may have begun? What was the farthers-back timestamp observed?
The inclusion of CACs has sparked a bit of a debate between some of my associates and I… remember that whole business with DOGE and their unauthorized hardware attached to Federal servers? The timing and access level fits, especially considering CACs aren’t valid ID for anything that would create these kinds of records. Can’t help but wonder, y’know?
Just a beyond face palm, I swear hopefully this breaks the camels back, and FORCES both chambers to draft proper legislation that states if you store X amount of data if you loose it n a breach the fine is = repeat = to shutting down your company, thank you have nice day. And verify every fuckin HD is physically destroyed, every serial recorded Mr C level, everyone of them.
Bill Germany:
You’re shocked at the lack of MSM coverage? Hoo, boy, this is America, man, and “If it bleeds, it leads.” Why dote on something geekish like this, when you can parade the latest murders, shootings, stabbings, and other gory gory stories? Our mainstream media this country is pathetic when it comes to anything more complicated but the latest video game.
This story was actually on the morning National news (CBS) 2 days ago.
We are all to wrapped up in our own business.
That the big guys Don t care about our info .
It generates money for the scammers and the it guys.
Snowden said it also.
China north Korea Russia are at it everyday like a full time job.
Even the drug cartels are at it
It is more profitable than selling drugs
Our data is not safe anywhere.
The facial recognition at thd airport
What third party has all that info
FLOCK CAMERAS THE NEW INVASION OF PRIVACY JUST DRIVING AROUND
NEXT IT WILL HAVE A DRONE FOLLOW YOU HOME LIKE THEY DO IN CHINA.
WE NEED TO TAKE BACK OUR COUNTRY
United STATES. OF AMERICA .
I’m old enough to remember when all a rental car company needed with your license was make sure it wasn’t expired and that the picture vaguely resembled you. Why do they need to do more than that??
Terrorism. That’s why.
Multiple terrorists used rented cars in their attacks.
I swear this country’s desperate attempt to curb terrorism puts all of us at risk of having our rights taken away.
They use that as an excuse byt really it is just bout theft and insurance and whatnot.
It is, indeed disheartening and who knows how many will suffer. Whereas I wish and want the guilty to be brought to justice, on the other hand, I wish the corporate world is held accountable for letting the PII leakage. They treat citizens’ data as a commodity to trade and make money by selling the information. If you jail the officials of companies who did not do due diligence in safe keeping PII data, like encrypt at column level, perhaps future loss of data will get reduced or people (corporations) will think before asking PII data that they cannot safely keep. Paying a small fine or issuing apology should not be an option. Jail time should be mandatory for the profiteering companies.
Great reporting and writing, Brian.
You do amazing work.
I just dont think it’s a leak. I think it’s a paid for siphon that certain lobbying for id verification has made even easier and more profitable for the siphoner.BUT MY MIDDLE NAME IS “SKEPTICAL”
Brian, ShinyHunters has reached out to Nexus, promising a large amount of money for the DLs. This situation is going from bad to worse. I wanted to let you know about that.
Beginning Jan 1, 2026
The state of Utah implemented what they called “the most rigorous alcohol compliance updates in recent years”.
Utah House Bill 437, commonly referred to as Utah’s “100% ID law,” changes how alcohol sales are verified across the state.
For those who may not know Utah owns all liquor stores through out the state. IDScan.net offered several ID scanning solutions with the use of either VeriScan or ParseLink. The plan is to have restricted licenses which will be used to deny alcohol sales. Also, if you have cannabis delivered by a Utah dispensary, yup you guessed it your license must be scanned.
Hackers and scammer should get death pen penalty…
I’m somewhat baffled. Basically they aren’t scanning ID to see if its valid and not a fake one. They are verifying the ID and storing a digital copy?