Dark Web Service 'Nexus' Exposes 153 Million Driver's Licenses, FBI Investigates
A new dark web identity theft service, **Nexus**, is selling digital scans of over 153 million driver's licenses from the U.S. and Canada. Evidence suggests the data originates from a breach at a widely-used identity verification company based in Louisiana. The **Federal Bureau of Investigation (FBI)** has launched an official inquiry into the incident.
A newly launched dark web service, dubbed **Nexus**, is offering for sale an alarming database containing digital scans of over 153 million driver's licenses belonging to individuals in the United States and Canada.
The service, advertised on the Russian cybercrime forum **Exploit**, also claims to possess over 10 million identification cards, three million travel documents, and 579,000 medical cards. A quick review of **Nexus**'s interface suggests the 153 million figure for driver's licenses is likely accurate, with the vast majority of records belonging to Americans.

### The Source of the Breach
**Nexus** operators claim the images are being continuously exfiltrated from an active breach at a "major identity verification company" that serves multiple Fortune 500 businesses. The sheer volume and ongoing nature of the data exfiltration are concerning, with nearly 400,000 new driver's license records added within a 24-hour period.
Individual investigations by KrebsOnSecurity, including verification of personal records and those of friends and family, indicate a strong link to a Louisiana-based identity verification provider, **idscan.net**. Many of the exposed records include six image filesβthree pairs of front and back scans in basic, infrared, and ultraviolet formatsβeach appended with a date and timestamp.
### Tracing the Data's Origin
Crucially, the timestamps on these images often correlate with specific instances where individuals presented their driver's licenses. For instance, the original reporter's license scan aligns with a flight and rental car pickup in June 2025. Similarly, other individuals found their records linked to dates they rented cars, often from **Hertz**.
While initial theories considered airport security as a potential source, the absence of passports in the dataset and the experiences of multiple individuals pointing to car rental agencies shifted the focus. Notably, the reporter and their mother, whose licenses appeared in **Nexus** with timestamps just seconds apart, both handed their licenses to a **Hertz** representative at the same time.

### Marijuana Dispensaries and IDScan.net
Further investigation by security and privacy researcher **Zach Edwards**, whose driver's license was also found on **Nexus**, revealed another potential vector: marijuana dispensaries. **Edwards** noted his license timestamp corresponded to a trip to Las Vegas for **DEFCON**, where he presented his ID at a dispensary, **Planet13**. In 2022, **idscan.net** announced an exclusive identity verification partnership with **Planet13**.
This connection strongly suggests that **idscan.net**, a company specializing in identity verification solutions, is the likely source of the compromised data. The presence of not only driver's licenses but also marijuana dispensary cards, and references to βCDLβ (commercial driver's license) and βCACβ (Common Access Cards) in the records, further points to a comprehensive identity verification solution as the origin.
The **FBI**'s New Orleans field office has launched an official inquiry, signaling the serious nature of this breach and its potential implications for millions of individuals.