Cyber & AI intelligence
Wasteland.
Briefs indexed2445
Issues26
Published Mondays07:30 CT
▣ Breach 153M-DRIVERS-LICEN 2026-09-06

IDScan.net: Nexus Dark Web Identity Theft Service

"A dark web identity theft service calling itself Nexus began selling searchable digital scans of more than 153 million US and Canadian driver's licenses, and the FBI's New Orleans field office opened a formal…"

A dark web identity theft service calling itself Nexus began selling searchable digital scans of more than 153 million US and Canadian driver's licenses, and the FBI's New Orleans field office opened a formal investigation on Sept. 1, 2026. The service was first surfaced by journalist Brian Krebs, who was tipped off after the operators posted his own Virginia license as a free sample on the Russian-language cybercrime forum Exploit. Reporting across KrebsOnSecurity, SecurityWeek and Security Affairs points to Louisiana-based identity verification vendor IDScan.net as the likely source, though that attribution remains journalistic inference rather than a confirmed finding. Nexus went dark shortly after Krebs published.

One caveat up front: there is no PRIMARY-tier source in this story. IDScan.net has not issued a statement, no regulator filing or CERT advisory exists, and the FBI has not publicly named a victim company. SecurityWeek says it emailed IDScan.net for comment and had not received a response at publication. Engadget's characterisation that "the FBI seems to confirm Krebs' claims" overreaches: opening an inquiry in New Orleans is consistent with a Louisiana-based source, but it is not a confirmation of one.

What Happened

On Monday, Aug. 31, 2026, a source alerted KrebsOnSecurity to a new user on Exploit advertising access to digital scans of identity documents covering more than 170 million people in North America. The seller's hook was Krebs' own driver's license, offered as a free sample in the opening sales thread. The service behind the ad was Nexus, a searchable identity theft platform.

Accounts differ slightly on the service timeline. KrebsOnSecurity and InfoSecBulletin date the Exploit listing to Aug. 31; Security Affairs describes Nexus itself as appearing on Sept. 1. The FBI investigation date is consistent across sources: KrebsOnSecurity reported the New Orleans field office launched its inquiry on Sept. 1, matched by BetaNews, Security Affairs and InfoSecBulletin.

Krebs validated the data before publishing. He searched Nexus for more than a dozen friends and family members with their consent; nine were found, and each confirmed they had travelled on or near the date stamped on their image files. Timestamps appeared to run on Greenwich Mean Time, inferred from car rental records shared by participants. His own record carried a June 2025 timestamp from a trip to the Midwest for a family funeral. Notably, he had not presented his license at Reagan National Airport that day: lacking a Real ID at the time, he used a passport at the TSA checkpoint. The scan instead traced to a Hertz car rental later the same day, the same transaction in which his mother handed over her license.

That common thread of Hertz rentals is what pointed reporting toward IDScan.net, which Security Affairs and Engadget list as a Hertz vendor. Tom's Hardware notes one divergent data point: security and privacy researcher Zach Edwards told Krebs their information was also in Nexus despite not having rented a car recently, having presented ID in another context. That suggests exposure is not limited to rental car counters.

Both SecurityWeek and Tom's Hardware report that Nexus was taken offline shortly after Krebs' article ran. Reuters carried the story as well, though the version in our source set resolves only to the wire's front page and contributes no independent detail.

What Was Taken

The headline figure, 153 million-plus driver's licenses for US and Canadian residents, is consistent across all eight sources. The wider claim of documents on more than 170 million North Americans comes from the Nexus operators' own sales post and should be read as a seller's marketing claim, not a verified count.

The category breakdown is where sources diverge. Most reporting follows the Krebs summary:

Tom's Hardware publishes a more granular and partly incompatible inventory: 1.9 million travel documents and 1.3 million international driver's licenses listed separately (which sums to 3.2 million, roughly consistent with the "3 million+" figure elsewhere), plus categories no other source enumerates: 429,000 common access cards, 91,000 residence cards, 77,000 employment authorization records and 5 million other documents. Engadget separately mentions employment records and residence cards without figures. Treat the Tom's Hardware sub-counts as single-source and unverified; the 429,000 common access cards figure, if accurate, would carry direct national security weight, and it deserves confirmation before anyone acts on it.

Verification of the 153 million total also differs by method. Krebs reported that a blank search on Nexus returned approximately 11.5 million pages at roughly 15 results per page, which multiplies out to the claimed scale. SecurityWeek compresses this to "a blank search on Nexus appeared to return approximately 153 million results." The underlying evidence is the same; the phrasing in the Krebs original is the more careful one.

Geographic split: the overwhelming majority of records are American. Canadian driver's licenses number roughly 1.1 million, with the largest concentration from Ontario at 473,673 records, per KrebsOnSecurity and SecurityWeek.

The sensitivity here is not in the record count but in the record structure. Security Affairs reports that each Nexus record contains six images of a single license: front and back captured under visible, infrared and ultraviolet light, plus a timestamp. That is not a photocopy. It is the full forensic capture set that ID authentication hardware produces to prove a document is genuine, which makes it the ideal raw material for producing counterfeits that pass automated verification, and for defeating remote KYC and liveness-adjacent document checks.

At least one US Secretary of Defense, Pete Hegseth, had a license in the listings, and Krebs reported several other senior US government officials were also present.

Why It Matters

This is a supply chain exposure in the identity verification layer itself, which is the control many organisations rely on as their last line of assurance that a person is who they claim to be. If the source is IDScan.net, the blast radius is defined by the vendor's footprint rather than by any one customer's security posture. SecurityWeek reports the firm performs more than 21 million verifications per month at over 20,000 locations across roughly a dozen industries including automotive, banking and fintech, gaming, education, transportation, hospitality, law enforcement, retail and security. Named clients across Security Affairs and Engadget include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment and financial services firm Jack Henry.

Three consequences matter for defenders. First, driver's license images are not rotatable credentials. A leaked password is a 10-minute fix; a leaked multispectral scan of a state-issued ID is valid until the document expires, and the reissue burden falls on 50-plus DMVs and provincial registries, not on the breached vendor.

Second, the presence of timestamps and implied location context turns this from an identity dataset into a travel and movement dataset. Records that reveal when a named individual rented a car, checked into a hotel or passed an age check are useful for targeting, stalking and physical surveillance independent of any financial fraud use.

Third, the exposure of senior government officials' licenses, and possibly common access cards if the Tom's Hardware figure holds, converts a commercial breach into a counterintelligence problem. A high-fidelity forged federal ID is a very different threat class from a stolen credit card number.

Security Affairs adds a detail that should shape response urgency: the record total was climbing by roughly 400,000 per day at the time of publication, which the operators attributed to ongoing exfiltration from a live intrusion they claimed had been running for over a year. That claim comes from the criminals themselves and is unverified, but if even directionally true it means the access was persistent and undetected across a long dwell time, and that taking Nexus offline does not mean the underlying access was closed.

The Attack Technique

The initial access vector is not established in any source. What is documented is the outcome pattern and the operators' own account of it.

The Nexus operators claimed the documents came from an active breach at an identity verification firm serving multiple Fortune 500 companies, per SecurityWeek's reading of the Krebs reporting. Krebs' attribution to IDScan.net is inferential and rests on victim overlap: the individuals he confirmed in the database shared a common touchpoint in ID scans captured at IDScan.net customer locations, most prominently Hertz rental counters. Zach Edwards' case, where ID was presented in a non-rental context, is consistent with a vendor-level compromise rather than a single customer's breach, and arguably strengthens the vendor hypothesis.

The forensic tell is the six-image, multispectral record format. Visible, infrared and ultraviolet captures are what commercial ID authentication scanners produce, not what a merchant's point-of-sale system stores. That the leaked records retain this format points to compromise of a system that ingested or retained the scanner output at the platform level, meaning stored verification artifacts rather than transient check results.

The daily growth rate of roughly 400,000 records suggests either continued live access to a production data store or an automated feed the attackers established and left running. Neither is confirmed. No CVE, no malware family, no named intrusion set and no ransomware or extortion component has been reported. Distribution and monetisation were conventional: an Exploit forum sales thread driving traffic to a searchable subscription-style lookup service, with a free celebrity-adjacent sample used as the lure.

What Organizations Should Do

  1. Inventory your identity verification vendors and what they retain. If you use IDScan.net or any comparable ID authentication platform in car rental, hospitality, gaming, retail age checks, banking onboarding or physical access control, ask the vendor in writing what document images they store, for how long, where, and whether raw multispectral captures are retained after a verification returns. Retention of the scan is the risk; the verification result is not.

  2. Assume document images are compromised and downgrade their trust weight. Treat a submitted driver's license image as an unauthenticated claim, not proof of identity. Where scanned ID currently gates account recovery, high-value transactions or remote onboarding, add a second independent factor: knowledge of transaction history, an out-of-band callback, a device or possession signal, or in-person verification for the highest-risk paths.

  3. Hunt for downstream abuse now, not after the FBI concludes. Build detections for account takeover and new account fraud where a submitted ID image is pristine and multispectral-consistent but other signals do not match: mismatched device fingerprints, new geographies, or the same document appearing across unrelated accounts. Sudden success rates on previously failing KYC attempts are a signal worth alerting on.

  4. Notify the people whose documents you handed to a third party. If your customers presented ID at your counters and your vendor is implicated, they are your customers to inform, regardless of where legal liability lands. Point them to credit freezes and, where a state or province offers it, driver's license number change or fraud-flag procedures. Be honest that reissue is the only real remediation and that it is slow.

  5. Contractually require breach notification and third party attestation from ID vendors. Add clauses covering notification timelines measured in hours, the right to audit retention practice, and evidence of egress monitoring on stores holding document images. A vendor claiming 21 million verifications a month is a concentration risk that deserves the same diligence as a payment processor.

  6. Watch for the primary sources and revise accordingly. Nothing in this brief is vendor-confirmed. If IDScan.net publishes a statement, a state attorney general notification is filed, or the FBI names a victim, that supersedes everything reported here. In particular, the granular sub-counts in the Tom's Hardware inventory and the operators' "live breach for over a year" claim should not drive irreversible decisions until corroborated.

Sources: 153M driver's licenses leaked, FBI investigates breach | FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security | 153 Million Driver License Images Offered on Dark Web - SecurityWeek | Dark Web Service Nexus Sells 153M+ Driver's Licenses | FBI probes report of data breach exposing millions ... | Digital Scans Of More Than 153 Million Driver's Licenses Leaked To... | FBI investigating 153 million US and Canadian driver’s licenses lea... | 153 Million Driver’s License Surfaced on Dark Web: FBI Starts Inves...