Cyber & AI intelligence
Wasteland.
Briefs indexed2367
Issues26
Published Mondays07:30 CT
▣ Breach DARK-WEB-DRIVERS 2026-09-02

IDScan.net: Nexus Dark Web Service Selling 153M Driver's License Scans

"A dark web identity theft service called Nexus went live this week advertising searchable access to digital scans of more than 153 million US and Canadian driver's licenses, and KrebsOnSecurity reports that the New…"

A dark web identity theft service called Nexus went live this week advertising searchable access to digital scans of more than 153 million US and Canadian driver's licenses, and KrebsOnSecurity reports that the New Orleans field office of the FBI has opened an official inquiry into the source of the images. Krebs, whose own Virginia license was used as the free sample in the seller's launch thread on the Russian cybercrime forum Exploit, traced the likely origin to IDScan.net, a Louisiana-based identity verification provider whose scanners sit at rental car counters, dispensary registers and retail onboarding flows across North America. The 153 million figure is the seller's own claim rather than a confirmed count of unique victims, and IDScan.net has not confirmed a breach; the company told Krebs it was investigating. By Tuesday night the Nexus site was gone, replaced by a login page reading "This service is no longer available."

What Happened

The timeline across sources is consistent. On Monday, August 31, a source alerted Krebs to a new seller on Exploit offering bulk access to North American identity documents. Krebs was tipped off specifically because his own license was the advertised freebie. The service, branded Nexus, offered a searchable front end: records previewable with sensitive fields redacted, with a $100 payment unlocking the full record including name, home address, date of birth and the complete document scan.

Reported inventory figures vary depending on which artifact you count. Krebs writes that the Exploit advertisement claimed identity documents on more than 170 million people in North America, while the Nexus platform itself claimed 153 million driver's licenses. A widely circulated post from the Dark Web Intelligence account, quoted by Metro, described the offering as "160M+ U.S. driver's license and ID records." Krebs' own sanity check on the platform pointed toward the high end: a blank search returned roughly 11.5 million pages at approximately 15 results per page, which works out to something near 170 million rows. Treat 153 million as the floor of a claimed range that runs to roughly 170 million, all of it attacker-supplied.

Verification came from victims, not from the vendor. Krebs confirmed the authenticity of his own scan, and per TFTC he searched for licenses belonging to more than a dozen friends and family members with their permission and found nine of them. The connective tissue was mundane commerce: record timestamps lined up with the days those people rented a car, visited a dispensary, or otherwise handed an ID to a business that scans documents. Engadget and AppleInsider both note the Hertz thread specifically, since Hertz uses IDScan.net at the counter.

The FBI inquiry is the one element of this story that is not attacker-sourced. Krebs reports that the Bureau's New Orleans field office opened the matter, and Metro reports agents confirmed the investigation to him directly. Engadget's framing that the FBI "seems to confirm Krebs' claims" is an inference drawn from the field office's geography, not a Bureau statement attributing the data to any company.

What Was Taken

Nexus advertised four buckets, and the figures are stable across every source: more than 153 million US and Canadian driver's licenses, more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. Metro notes the medical card set includes cards used to legally obtain marijuana. AppleInsider reports the inventory also contained commercial driver's licenses and Common Access Cards, the credentials used for physical entry to government facilities and secure spaces; that CDL and CAC detail appears in AppleInsider's account and should be treated as reported rather than independently confirmed.

The Canadian share is comparatively small. Krebs found roughly 1.1 million Canadian license results, with Ontario the heaviest concentration at 473,673 records. The overwhelming bulk is American.

What makes this cache worse than a typical PII dump is the image fidelity. IBTimes and TFTC both report that records carried multiple images per license: front and back, plus infrared and ultraviolet captures. Those are not photographs a criminal takes with a phone. They are the output of purpose-built forensic ID scanners, and their presence in the dataset is a large part of why Krebs pointed at IDScan.net, whose hardware produces exactly those image types. An IR and UV capture set is enough raw material to reproduce the security features that document authentication is supposed to check for.

The dataset was also live. Multiple outlets report the license count grew by nearly 400,000 in a single 24-hour period after discovery; byteiota characterizes that as roughly 400,000 per day. The operators claimed in their Exploit post that they had "been continuously exfiltrating new data for over a year into our private database." If accurate, that is an active pipeline, not a historical dump.

Why It Matters

Two high-profile records defined the news cycle. Krebs found a listing for US Defense Secretary Pete Hegseth's driver's license, offered at $100. Accounts differ on the detail: byteiota describes it as a Minnesota license, while Krebs, IBTimes and Metro report the listing without specifying the issuing state. byteiota further reports that an FBI official's license was in the inventory, a claim that appears in only that one source and is not corroborated elsewhere.

The structural point matters more than the celebrity record. Identity verification vendors are the purest form of honeypot in the current data economy: KYC, AML and age-verification rules compel ordinary people to hand over their most sensitive documents, businesses funnel those documents into a small number of third-party processors, and the processors retain the images. TFTC makes this argument bluntly, and the incident is a clean case study for it regardless of where you land politically. The victims here did nothing riskier than rent a car.

For defenders, the practical consequence is that document-image-based identity proofing has taken a serious hit. A driver's license scan cannot be rotated like a password. If an attacker holds front, back, IR and UV captures of a document alongside name, address and date of birth, then any onboarding flow that accepts an uploaded ID image as proof of identity is now checking a credential the adversary may already possess in higher fidelity than the legitimate user can produce. Expect downstream synthetic identity fraud, account takeover at institutions that use ID upload for recovery, and loan and account-opening fraud on a long tail.

The Attack Technique

The initial access vector is not established. No source reports how the data was obtained, and neither IDScan.net nor the FBI has published a technical account. What exists is the attackers' own claim, repeated across coverage, that they maintain persistent access to "a major identity verification company" and have been exfiltrating continuously for more than a year. The near-400,000-record daily growth is circumstantial support for that claim, since it is difficult to explain a live-growing dataset without ongoing access.

byteiota argues the exposure most likely runs through IDScan.net's API and SDK surface and its retention of document images, and notes that many organizations are exposed transitively: developers who never integrated IDScan.net directly may have built on a dispensary point-of-sale system, a rental management platform or a retail compliance tool that did. That analysis is byteiota's, not a vendor or Bureau finding, but the supply chain shape it describes is consistent with the victim pattern Krebs documented.

Scale gives a sense of the blast radius. TFTC cites IDScan.net as processing more than 21 million verifications per month across more than 20,000 locations; byteiota reports the same monthly figure and names Hertz, Target, FedEx and Caesars Entertainment among customers, plus more than 1,000 cannabis dispensaries across 19 states. 9to5Mac's client list adds Motorola Solutions and Jack Henry, the latter a core banking software provider. TFTC notes Planet 13 among named customers and partners. Customer lists in these reports come from public marketing material and reporting rather than from a breach notification, and appearing on one does not establish that a given company's records are in the cache.

Nexus going dark does not mean the data is contained. A marketplace shutting its login page is a distribution change, not a recovery. The cache is copied, and if the operators' access claim holds, the source may still be leaking.

What Organizations Should Do

  1. Inventory your ID verification supply chain, including transitive dependencies. Determine whether your onboarding, KYC, age-gating or fraud flows call IDScan.net directly, and whether any platform you embed (POS, rental management, dealership software, compliance tooling) calls it underneath. The transitive case is where most organizations will be surprised.

  2. Stop treating a document image as sufficient identity proof. Any flow where an uploaded or scanned license alone unlocks account access, account recovery, or credit should be reworked now. Require liveness-bound biometrics, device binding, or an out-of-band factor alongside the document.

  3. Audit and shorten document image retention. The reason this cache is catastrophic is that a vendor stored high-fidelity images long after the verification transaction closed. Verify what your providers retain, for how long, and under what encryption and key custody. Contractually force deletion where the images serve no ongoing compliance need.

  4. Rotate and constrain third-party API credentials. If you hold IDScan.net or comparable verification API keys, rotate them, scope them to the minimum required document operations, restrict by source IP, and review access logs for the past 18 months given the claimed year-plus dwell time.

  5. Raise fraud thresholds for identity-document-backed workflows. Assume attackers hold front, back, IR and UV captures plus name, address and date of birth for a large share of North American adults. Tune synthetic identity and new-account fraud detection accordingly, and flag ID-based account recovery for manual review.

  6. Prepare notification and support paths for affected individuals. If your customers passed IDs through an affected integration, you may carry state-level notification obligations even though you are not the breached party. Line up credit monitoring guidance and a documented process for customers who need to replace a compromised license number.

  7. Track the FBI New Orleans inquiry and any IDScan.net statement. The attribution to IDScan.net remains Krebs' assessment supported by image forensics and victim timestamps, not a confirmed finding. Hold your response plan loosely until a primary statement lands.

Sources: FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security | Digital Scans Of More Than 153 Million Driver's Licenses Leaked To... | 153 million driver's license scans appeared on the dark web | Pete Hegseth's Driver's Licence Listed for $100 on Dark Web Among 1... | Hackers sell scans of 153,000,000 US driving licences - and drivers... | IDScan.net Breach: 153M Driver’s Licenses on the Dark Web — and You... | The Identity Verification Honeypot Has Been Cracked Open · TFTC | FBI investigates as hackers sell digital scans of 153M drivers lice...