Identity September 7, 2026 · 4 min read · By Forum Desk

A Dark Web Service Listed 153 Million Driver's License Scans. The Timestamps Led to an ID Verification Vendor.

A new criminal service called Nexus advertised searchable scans of 153 million US and Canadian driver's licenses, with file timestamps that traced back to rental counters and dispensaries. KrebsOnSecurity followed the trail to identity verification provider IDScan.net, and the FBI has opened an inquiry.

  • #identity
  • #data-breach
  • #third-party-risk
A tall stack of blank plastic cards on a dark counter under the violet glow of an ultraviolet lamp

The identity documents organisations collect to prove people are who they say they are have become a liability at scale. KrebsOnSecurity reported on September 1 that a new service on the Russian-language forum Exploit, calling itself Nexus, was offering searchable scans of more than 153 million driver’s licenses from the United States and Canada, alongside roughly 10 million ID cards, 3 million travel documents, and 579,000 medical cards. By the following evening the site had replaced its login page with a notice that it was no longer available. The data has not gone anywhere.

Following the timestamps

The investigation is a case study in attributing a breach before the vendor says a word. Each Nexus record held up to six image files: front and back scans in visible, infrared, and ultraviolet light, each with a timestamp in the filename. Brian Krebs found his own license offered as a free sample in the seller’s launch post and matched its timestamp to a June 2025 trip. Nine friends and relatives whose licenses also appeared confirmed travel on or near their timestamps. The common thread was not airport security, since several had shown passports at the checkpoint. It was the rental counter. Krebs’ mother’s record was stamped seconds apart from his own, at the moment they both handed licenses to a Hertz agent.

Researcher Zach Edwards found his own scan stamped during DEFCON in August. The only place his ID had been machine-read that day was a Planet13 cannabis dispensary, a chain with an exclusive verification agreement with New Orleans-based IDScan.net. The vendor’s public materials list Hertz, Target, FedEx, Jack Henry, and Caesars as customers, describe scanning IDs under infrared and ultraviolet light, and claim over 21 million verifications a month at more than 20,000 locations. IDScan.net told Krebs it was investigating but offered no substantive statement. Caesars later said it had not used the vendor’s product since February 2025 and had not authorised any data retention.

An active pipeline, not an archive

Nexus claimed to have been exfiltrating data “for over a year”, and Krebs watched the license count grow by nearly 400,000 in a single day, which points to a live feed rather than a one-time dump. Records included commercial driver’s licenses and entries tagged CAC, which may denote military Common Access Cards. Licenses belonging to senior US officials, including the defence secretary and an FBI assistant director, were listed. The FBI’s New Orleans field office opened an official investigation the same day Krebs briefed the agency.

What this means

Two threads matter for practitioners. The first is third-party risk in its purest form. The retailer, rental agency, or venue whose customers are exposed never held this data on its own systems, yet will own the reputational and regulatory fallout. Contracts with verification vendors should specify retention limits and deletion timelines, and those terms should be audited rather than assumed. Cybera’s Larry Baldwin noted the irony that license scans are exactly what newer identity-proofing controls depend on; when the reference documents leak in bulk, with multispectral images attached, the attacker holds the raw material to defeat those same controls, and the people who cannot change their face, from domestic-violence survivors to protected witnesses, pay the highest price.

The second thread is policy. As Edwards put it, age-verification and know-your-customer mandates keep pushing government IDs into more vendors’ hands with little oversight. Every new collection point is another Nexus waiting to happen. Security leaders should classify identity-document images as regulated data, push vendors to verify and discard rather than verify and store, and demand evidence that they do.