Massive Dark Web Breach Exposes 153 Million North American Identity Documents

A sophisticated new identity theft service operating on the dark web has sent shockwaves through the cybersecurity community this week, claiming to offer digital scans of more than 153 million driver’s licenses belonging to residents across the United States and Canada. The platform, known as "Nexus," has become the focus of a major federal inquiry, with the FBI’s New Orleans field office launching an official investigation into the origins of the massive data repository. The sheer scale of the breach, which includes millions of identification cards, travel documents, and medical cards, suggests a systematic and long-term exfiltration of sensitive personal information from a central point of failure in the identity verification ecosystem.

The operation was first identified on Monday, August 31, when a source alerted security researchers to a post on the Russian cybercrime forum "Exploit." The threat actor behind the service was marketing access to a staggering volume of North American identity records, using the driver’s license of a known security journalist as a "free sample" to verify the legitimacy of the data. The breadth of the repository is immense: Nexus claims to host over 153 million driver’s licenses, 10 million identification cards, three million travel documents, and at least 579,000 medical cards.

A preliminary investigation into the Nexus search interface suggests these claims are not mere bluster. A blank search query yields approximately 11.5 million pages of results, with roughly 15 records displayed per page. While the dataset encompasses both Canada and the United States, the majority of the records pertain to Americans. Canadian records, while smaller in relative volume, are significant, with nearly half a million records originating from Ontario alone. The database is not limited to standard state-issued licenses; it also includes marijuana dispensary cards and records tagged as "CDL" for commercial driver’s licenses and "CAC" for Common Access Cards—the high-security credentials used for physical access to sensitive government buildings and secure facilities.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The threat actors behind Nexus claim the data is being sourced from an ongoing breach at a major identity verification provider that serves multiple Fortune 500 companies. "We have been continuously exfiltrating new data for over a year into our private database," the group boasted in its introductory forum post. The service allows prospective buyers to preview records, albeit with sensitive information redacted, and even displays user photographs when available. The velocity of the data growth is alarming; in a single 24-hour period, the number of driver’s license records available on the service increased by nearly 400,000, indicating that the threat actors have automated the harvesting and ingestion of fresh data.

The forensic evidence found within the records points to a highly technical exfiltration process. Many of the files, including the sample license identified in the researcher’s own name, contain six distinct image files: front and back scans, a standard document scan, and both infrared and ultraviolet versions of the credentials. Each file includes an appended date and timestamp. For those who have verified their own records within the database, the timestamps correlate precisely with dates and locations where they had recently presented their identification for verification.

To uncover the source of this data, researchers cross-referenced timestamps with the personal travel and transaction logs of more than a dozen individuals. Every person whose license was found in the database confirmed having been in a situation where their ID was scanned or held for processing on the date indicated in the file metadata. One striking example involved a mother and child whose licenses were scanned seconds apart; both recalled handing their IDs to a rental car representative at the same time. While initial theories suggested airports might be the source, the absence of passports in the dataset and the fact that many individuals had used passports—rather than licenses—at TSA checkpoints redirected the focus toward the private sector.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The trail eventually led to idscan.net, a Louisiana-based company that specializes in identity verification for thousands of businesses globally, including rental car agencies, large retail chains, and government contractors. The company’s own promotional materials confirm that its technology scans IDs using infrared and ultraviolet light, matching the specific file types found on the Nexus platform. Idscan.net lists prominent brands such as Hertz, Target, FedEx, Motorola Solutions, and Caesars Entertainment among its clients, and claims to perform more than 21 million verifications every month across 20,000 global locations.

When contacted, idscan.net initially provided a guarded response, stating they were investigating the matter. Jillian Kossman, a marketing and operations leader at the firm, acknowledged the information provided by researchers was "welcome and helpful" to their internal inquiry. However, the situation escalated rapidly when the FBI became aware of the breach. Because the database contains the driver’s licenses of high-ranking government officials, including U.S. Defense Secretary Pete Hegseth and an assistant director of the FBI, the agency moved quickly to intervene. Federal agents from the cyber division confirmed that the New Orleans field office had opened an official probe into the breach of the idscan.net infrastructure.

The implications of this breach extend far beyond standard identity theft. Security experts warn that the exposure of front-and-back scans of government-issued IDs creates a massive risk for financial fraud, particularly in the opening of new lines of credit. Moreover, the availability of such data poses a life-altering threat to vulnerable populations, including victims of domestic violence and individuals in federal witness protection programs, whose safety relies entirely on the secrecy of their identities. Because modern AI-based image matching tools are highly effective at identifying individuals even if they alter their appearance, the permanent, public availability of these scans removes a crucial layer of security for those trying to remain hidden.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

"Just when it seems like we’re making some headway in improving authentication controls through driver’s license verification systems, this happens, and the very thing those improvements are dependent on are compromised," noted Larry Baldwin, a principal intelligence researcher at the cybersecurity firm Cybera. Zach Edwards, a privacy researcher who also found his own license on the site, argued that the incident underscores the danger of the "over-collection" of sensitive data. "These systems are putting sensitive data into more and more third-party vendors, and we don’t have nearly the oversight to ensure they are safe," Edwards said, criticizing the trend of requiring physical IDs for low-stakes online services under the guise of child protection.

As the situation unfolded, the company began to take formal steps to address the incident. On September 8, idscan.net published a brief notice acknowledging that an "unauthorized third party may have accessed and/or copied certain customer information, including full names and driver’s license or other government-issued identification numbers." The company stated it is currently in the process of notifying affected individuals and providing credit protection services.

Complications emerged regarding the scope of the affected clients. A spokesperson for Caesars Entertainment stated that the company has not used idscan.net since February 2025 and did not authorize the retention of their customer data, suggesting that the breach may involve legacy data or unauthorized data storage practices. Shortly after these details surfaced, the Nexus website abruptly went dark. The login page, which previously hosted the massive database, was replaced with a plain, text-based message: "This service is no longer available." While the removal of the site offers some temporary relief, the data has likely already been copied or sold, leaving millions of individuals to grapple with the long-term consequences of one of the largest identity breaches in recent history.

Share:

rifanmuazin writes for Tech Maze.

Leave a comment