
The FBI is investigating an apparent breach involving identity verification provider IDScan after a dark web service began selling access to more than 153 million US and Canadian driver’s license scans, according to an exclusive KrebsOnSecurity report.
The marketplace, called Nexus, also claimed to hold more than 10 million other ID cards, over three million travel or international documents, and at least 579,000 medical cards. The figures have not been independently confirmed, and IDScan has not acknowledged a breach or its scope.
Brian Krebs began investigating Nexus after a source alerted him on August 31 to a listing on the Russian-language cybercrime forum Exploit. The seller offered access to identity documents belonging to more than 170 million people and used a scan of Krebs’s own Virginia driver’s license as a sample.
Nexus claimed the records came from an ongoing compromise of a major identity verification company. Krebs reported that the service added nearly 400,000 driver’s licenses within 24 hours, suggesting the source may still have been providing new data.

Brian Krebs
His investigation eventually focused on IDScan.net, a New Orleans-based identity verification provider whose technology is used to validate government-issued IDs. IDScan says it processes more than 21 million verifications per month across over 20,000 locations worldwide and lists companies including Hertz, Target, FedEx, Caesars Entertainment, Motorola Solutions, and Jack Henry among organizations using its services.
IDScan told KrebsOnSecurity it was investigating the information he provided but did not issue a detailed response.
Krebs said the FBI later told him its New Orleans field office had opened an official investigation into an apparent incident involving IDScan.
A key clue came from timestamps and imaging data attached to the stolen documents.
Krebs’s own Nexus record contained front and rear license scans captured using standard, infrared, and ultraviolet imaging. IDScan documents similar scanning capabilities in its technology.
Krebs then asked friends and relatives for permission to search the database. Nine people whose licenses were found said the timestamps matched occasions when they had recently presented their IDs, frequently while traveling.
Several cases involved Hertz rentals, with Krebs mentioning that his own license and his mother’s were scanned only seconds apart on a day when both handed their IDs to the same Hertz rental counter.
Security researcher Zach Edwards also found his license in Nexus with a timestamp matching a trip to Las Vegas. He said he presented his ID at several locations, including a Planet 13 cannabis dispensary that uses IDScan technology.
Nexus also reportedly contained records belonging to senior US officials, including Defense Secretary Pete Hegseth, as well as identity information associated with an FBI assistant director.
Some records carried labels such as “CAC,” potentially referring to US government Common Access Cards.
Shortly after publication of this massive exposure, the Nexus site disappeared from the dark web and was replaced with a message stating that the service was no longer available.
Driver’s license scans pose a significant identity theft risk because they can be used to support fraudulent account creation, defeat identity verification checks, and strengthen social engineering attacks.
People concerned their identity documents may have been exposed should freeze their credit, monitor financial accounts, enable strong multi-factor authentication, and report suspected identity theft through IdentityTheft.gov.






Leave a Reply