153 Million Driver’s Licenses for Sale on the Dark Web: IDScan Under FBI Scrutiny
Nexus is the name of a new dark web service that claims to hold copies of more than 153 million U.S. and Canadian driver’s licenses. One company is currently in the FBI’s sights and could be behind this data leak: IDScan. Here’s what we know.
On his KrebsOnSecurity website, Brian Krebs published an investigation into a data leak involving sensitive documents, including driver’s licenses, and their sale on the Dark Web. Krebs himself is directly affected by this leak: the free sample offered to buyers by the cybercriminals was Brian Krebs’s own driver’s license.
On the Dark Web, these licenses are tied to a service called Nexus: it allegedly provides access to more than 153 million U.S. and Canadian driver’s licenses, more than 10 million ID cards, more than 3 million travel documents, and at least 579,000 medical cards.

"It includes documents from people living in both Canada and the United States, but most of the records are for Americans: a search limited to Canadian driver’s licenses returns about 1.1 million results, with the largest concentration coming from Ontario (473,673 records).", Brian Krebs notes. Canada is affected too, but far less than the United States.
For their part, Nexus operators claim the images come from an ongoing compromise at "a major identity verification provider" whose customers include several Fortune 500 companies. "We have been continuously exfiltrating new data for more than a year into our private database", they say. The tap is still open and data keeps leaking to the attackers. But is that really the case? One figure seems to support their claim: within 24 hours, the driver’s license counter increased by nearly 400,000 records.
An investigation built from records belonging to his contacts
Each driver’s license includes a front-and-back scan, in visible light, infrared, and ultraviolet, timestamped to the second. To try to understand where the data came from, Brian Krebs conducted his own investigation. He asked a dozen acquaintances for permission to search for their licenses in Nexus: 9 of them were there. And all confirmed that they had traveled on, or very close to, the date attached to their images.
He tried to connect the scan of his own document to a provider responsible for processing this information. In the end, the answer came from researcher Zach Edwards, whose license is also for sale. Edwards linked his timestamp to a trip to Las Vegas for DEF CON. No rental car, but an ID scanned at the entrance to a Planet13 cannabis store. Interestingly, in 2022, IDScan had announced an exclusive partnership with Planet13 for identity verification: an intriguing common point.
IDScan, a discreet but ubiquitous link in the chain
Based in New Orleans, IDScan.net says it performs more than 21 million verifications per month across more than 20,000 service points worldwide. Its references page lists Hertz (that is where Krebs’s document leaked from), Target, FedEx, Motorola Solutions, and Caesars Entertainment. Its technology scans documents in infrared and ultraviolet, which matches the format of the images sold by Nexus. Hertz is a car rental company, so this incident could also affect people who rented a car in the United States while traveling, for example.
Contacted by KrebsOnSecurity, IDScan said it is investigating, but has not issued a formal statement. "At this point, I’m not able to share additional information, but the details you provided were welcomed and helpful to our team’s investigation", replied Jillian Kossman, marketing and operations manager at IDScan. Hertz, also contacted, had not responded at the time of publication. The FBI, however, moved faster: on September 1, its New Orleans office opened an official investigation into an apparent incident involving IDScan.
Among the records available, Brian Krebs found that of Defense Secretary Pete Hegseth, as well as that of a deputy FBI director. Some entries are marked "CAC", which could refer to Common Access Cards, the access badges used by U.S. federal agents. So yes, this is serious.
As for Nexus, it disappeared from the dark web a few hours after the journalist’s investigation was published: its login page now displays a simple message saying the service is no longer available (what about the data already exfiltrated?). It’s possible this is linked to an FBI action. For its part, IDScan reportedly began notifying customers during the night of September 1 to 2, 2026, but this remains to be confirmed. All signs point to a real intrusion tied to a massive data leak at this provider.


