Cyber & AI intelligence
Wasteland.
Briefs indexed2438
Issues26
Published Mondays07:30 CT
▣ Breach 153-MILLION-DRIVER 2026-09-05

IDScan.net: Nexus Dark Web Identity Service Advertises 153M+ Driver's License Scans

"A dark web identity theft service calling itself Nexus surfaced during the week of August 31, 2026, offering searchable access to digital scans of more than 153 million US and Canadian driver's licenses, with its…"

A dark web identity theft service calling itself Nexus surfaced during the week of August 31, 2026, offering searchable access to digital scans of more than 153 million US and Canadian driver's licenses, with its operator claiming identity documents on over 170 million people across North America. KrebsOnSecurity broke the story on September 1 after the service's proprietor posted Krebs' own Virginia license as a free sample on the Russian-language cybercrime forum Exploit, and traced the source to Louisiana-based identity verification provider IDScan.net. The FBI's New Orleans field office opened an inquiry into the source of the images the same day, a step reported by KrebsOnSecurity and independently confirmed by Reuters per BleepingComputer. IDScan.net has issued no public statement, and no source has established how the data was obtained. This brief is built entirely on press reporting and one on-the-record marketing comment; there is no victim notification, regulator filing, or vendor advisory in the record as of publication.

What Happened

On Monday, August 31, a source alerted KrebsOnSecurity to a new user on Exploit advertising bulk access to North American identity documents. The advertised service, Nexus, presented a searchable front end over the collection. Security Affairs dates the public appearance of Nexus itself to September 1, 2026, while CybersecurityNews and InfoSecBulletin date the Exploit sales thread to August 31; the two are compatible, with the forum listing preceding or coinciding with the searchable service going live.

Krebs verified the data rather than taking the seller's word for it. He located his own license, then checked records for friends, family, and other individuals who consented to the lookups. Tom's Hardware reports that the common denominator among the people Krebs found was that they had all rented vehicles from Hertz, an IDScan.net client. Security and privacy researcher Zach Edwards told Krebs his information was also present despite not having rented a car recently, which points to a broader ingest surface than car rental alone. Krebs' own record carried a timestamp matching a June 2025 flight and car rental, per Security Affairs.

IDScan.net is a New Orleans firm selling ID fraud prevention, access management, and age verification, including mobile scanners and an ID-activated door lock. SecurityWeek notes the company advertises more than 21 million verifications per month across more than 20,000 locations, spanning automotive, banking and fintech, gaming, education, transportation, hospitality, law enforcement, retail, and security. Named clients across CSO Online and Security Affairs include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and financial services firm Jack Henry. Its systems are also deployed in car rental counters, gun shops, and cannabis dispensaries, per BleepingComputer.

The Nexus site was taken offline shortly after Krebs published. BleepingComputer is explicit that this changes little: the operators still hold the database.

The company's only attributed comment came through KrebsOnSecurity and was relayed by CSO Online. Jillian Kossman, a marketing and operations leader at IDScan.net, said: "I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation." That is an acknowledgment of an internal investigation, not a confirmation of a breach. BleepingComputer states plainly that it remains unclear whether IDScan.net's systems were compromised or how many individuals are affected.

What Was Taken

The headline figure of 153 million driver's licenses is a seller claim that reporters found plausible but did not fully enumerate. Krebs ran a blank search on Nexus and got roughly 11.5 million pages of results at approximately 15 results per page, which works out closer to 170 million records than 153 million. SecurityWeek characterized that same blank search as returning "approximately 153 million results." Treat the exposure as somewhere in the 153 million to 172 million range depending on whether you count driver's licenses alone or all document types.

The composition of the non-license documents is where the sources diverge most. Krebs, and the outlets following him, list more than 10 million identification cards, more than 3 million travel documents and international IDs, and at least 579,000 medical cards. Tom's Hardware publishes a more granular breakdown attributed to the same listing: 1.9 million travel documents, 1.3 million international driver's licenses, 579,000 medical cards, 429,000 common access cards, 91,000 residence cards, 77,000 employment authorization records, and 5 million other documents. The Tom's Hardware breakdown is single-source and OTHER-tier, so treat it as reported rather than confirmed. If accurate, the 429,000 common access cards are the most operationally alarming line item, since CACs are US Department of Defense credentials.

Geographic split: the bulk is US. CybersecurityNews reports roughly 1.1 million Canadian driver's licenses in the set, including 473,673 from Ontario specifically, a figure that appears in only that source. SecurityWeek independently cites the same approximate 1.1 million Canadian total.

The sensitivity here is not the record count, it is the fidelity. Each record reportedly contains six image files: front and back of the document captured in visible, infrared, and ultraviolet light, with date and time stamps in the filenames. Not every record includes photos. The IR and UV layers matter disproportionately because those are precisely the captures identity verification platforms use to validate a document's embedded security features and detect forgeries. A stolen visible-light photo of a license is a fraud input; a stolen IR and UV capture set is a fraud input that can satisfy the checks designed to catch fraud inputs.

Named individuals in the set include US Defense Secretary Pete Hegseth, reported by KrebsOnSecurity, CSO Online, and Tom's Hardware, alongside several other senior US government officials.

Why It Matters

This is a third-party trust failure, not a perimeter failure at any of the named brands. Hertz, Target, FedEx, and Caesars did not lose this data from their own environments. They handed identity documents to a verification vendor as part of a legitimate, often legally mandated workflow, and the aggregation point became the target. CSO Online frames this correctly: no amount of internal hardening protects a business from the security posture of the supplier that holds its customers' documents.

Three structural problems compound the impact.

First, driver's licenses do not rotate. A compromised password is a Tuesday afternoon problem. A license number, DOB, address, signature, and multi-spectrum document scan remain valid for years and cannot be reissued at scale without state DMV involvement.

Second, the IR and UV captures degrade the entire remote-KYC model. Any verification provider relying on document image analysis now faces a corpus of authentic security-feature captures circulating in criminal hands. This is a supply-chain problem for the fraud prevention industry itself.

Third, the collection is a targeting dataset, not just a fraud dataset. The presence of the sitting US Defense Secretary, plus a reported 429,000 common access cards, makes this relevant to counterintelligence, not only to consumer identity theft.

Legal exposure is already materializing. BleepingComputer reports multiple lawsuits filed in Louisiana against IDScan.net, with law firms including Markovits, Stock & DeMarco and Hall Attorneys opening class action investigations. The suits allege IDScan.net failed to protect information collected on behalf of clients such as Hertz.

The Attack Technique

The intrusion method is unknown. No source describes an initial access vector, a vulnerability, an exploited credential, or a ransomware or extortion component. Nothing here should be read as a confirmed technical account.

What the sellers themselves claim, reported by SecurityWeek and Security Affairs, is that the documents were exfiltrated from an active breach at an identity verification firm serving multiple Fortune 500 companies, and that the intrusion had been running for more than a year. Security Affairs adds that the Nexus record total was climbing by roughly 400,000 per day at the time of publication, which the operators attributed to ongoing live exfiltration. If that growth rate is real, it is the single strongest available indicator that access was persistent and unremediated during the advertising window rather than a one-time historical dump. It is still a criminal's claim in a sales thread, and sales threads inflate.

The forensic breadcrumb worth tracking is the timestamped filenames. Krebs matched his own record's timestamp to a June 2025 flight and car rental, which places at least some captures more than a year before the listing and is consistent with either a long dwell time or the theft of an archive.

Attribution of the source to IDScan.net rests on Krebs' victim-correlation methodology, not on a company admission or a forensic report. It is well-supported and every outlet in this set has adopted it, but it is inference.

What Organizations Should Do

  1. Inventory which vendors hold scans of your customers' or employees' identity documents, and get retention answers in writing. The core question is not whether the vendor verified an ID, it is whether the vendor kept the image afterward and for how long. If a verification vendor retains multi-spectrum captures indefinitely, that is a liability you are carrying without visibility.
  2. If you are an IDScan.net customer, open a direct written inquiry now rather than waiting for a public statement. Ask specifically for scope, capture date ranges, whether IR and UV layers were retained, and whether exfiltration has been contained. The company has not published anything as of September 5, 2026, and BleepingComputer reports it has not responded to press queries.
  3. Stop treating document images as a sufficient identity proof for high-value actions. Any workflow where a submitted license scan alone unlocks account recovery, credit issuance, wire changes, or privileged access should be re-architected to require a liveness check or an independent out-of-band factor. Assume the attacker has an authentic-looking scan set.
  4. Raise fraud detection sensitivity on account takeover paths keyed to identity documents, particularly synthetic identity creation and new-account fraud. Watch for a lag: aggregated document sets are typically monetized over months, not days.
  5. Push document-collection contract terms toward minimization. Require verification-then-delete where regulation permits, demand encryption at rest with customer-controlled keys where feasible, and require breach notification timelines measured in hours.
  6. For government and defense-adjacent organizations, treat the reported common access card exposure as a targeting risk pending confirmation, and review whether physical or logical access processes anywhere accept a scanned credential image as proof.

Individuals in the US and Canada who have rented a car, visited a regulated retailer, or presented ID at a gaming or hospitality venue in the past several years should assume potential inclusion, place credit freezes, and be alert to identity-based social engineering. There is no consumer-facing lookup tool and no notification process, because no breach has formally been declared.

Sources: 153 Million Driver’s License Scans Surface on Dark Web as FBI Opens... | FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security | IDScan sued over alleged data breach affecting 153 million drivers | 153 Million Driver License Images Offered on Dark Web - SecurityWeek | Dark Web Service Nexus Sells 153M+ Driver's Licenses | FBI investigates breach of 153 million driving license records at I... | FBI investigating 153 million US and Canadian driver’s licenses lea... | 153 Million Driver’s License Surfaced on Dark Web: FBI Starts Inves...