A sophisticated new identity theft service operating on the dark web has emerged as a significant threat to the privacy of over 153 million individuals across the United States and Canada. The service, known as "Nexus," is currently offering digital scans of drivers’ licenses and other government-issued identification for sale, raising alarms among cybersecurity experts and federal authorities alike. Preliminary investigations suggest the data was siphoned from a Louisiana-based identity verification company, prompting an official inquiry by the Federal Bureau of Investigation (FBI).
The scale of the exposure is staggering. The service claims to hold more than 153 million drivers’ licenses, alongside 10 million identification cards, three million international travel documents, and at least 579,000 medical cards. These figures appear to be grounded in reality; a blank search query on the Nexus platform returns roughly 11.5 million pages of results, with 15 records per page. While the dataset encompasses both U.S. and Canadian citizens, the overwhelming majority of the victims are American. Canadian records are also present, with the largest concentration originating from Ontario.
The breach has reached the highest levels of the U.S. government. Notably, the repository includes the driver’s license of U.S. Defense Secretary Pete Hegseth. The presence of such high-ranking government officials’ credentials among the millions of records for sale underscores the severity of the incident.
Origins of the Breach
The service first appeared on the Russian cybercrime forum "Exploit" on Monday, August 31. The proprietor of the service initially offered a free sample to potential buyers: a digital scan of the driver’s license belonging to the author of this report. This, combined with further investigation, revealed a disturbing pattern in the data: the images are not merely flat files, but comprehensive scans including infrared and ultraviolet versions of the documents, complete with precise timestamps.

These timestamps appear to be set to Greenwich Mean Time (GMT) and are tied to specific, real-world events. Researchers and volunteers who examined their own records in the Nexus database discovered that the timestamps corresponded almost perfectly to moments when they had provided their physical identification for processing—typically at rental car counters or, in one instance, at a marijuana dispensary.
The evidence points toward a widespread compromise of idscan.net, a New Orleans-based company that provides identity verification services for a vast array of businesses. Idscan.net’s technology is used by over 1,000 marijuana dispensaries across 19 states and serves major commercial entities, including Hertz, Target, FedEx, Motorola Solutions, and Caesars Entertainment. The company’s own promotional materials confirm that its systems utilize infrared and ultraviolet light to scan documents, matching the specific, high-fidelity files found on the Nexus platform.
A Pattern of Data Collection
The methodology of the theft appears to be rooted in the routine verification processes that consumers encounter daily. For many, the "lightbulb moment" occurred when comparing their own travel histories to the metadata attached to their leaked documents.
In one instance, a researcher and his mother found their licenses in the database with timestamps mere seconds apart. Both individuals recalled handing their licenses to a Hertz rental car representative at the same time during a trip. Because the representative held the documents behind the counter for several minutes to process paperwork, it is highly probable that the IDs were scanned through a device connected to a compromised backend system.

Another subject of the investigation, privacy researcher Zach Edwards, found his license in the Nexus database with a timestamp corresponding to his visit to a Las Vegas dispensary. Edwards confirmed that he visited Planet13, a chain that maintains an exclusive identity verification agreement with idscan.net. The dispensary requires customers to pass through a specialized entrance where identification is scanned, suggesting that the point of collection for this massive trove of data is likely the very hardware and software meant to ensure security.
Regulatory and Security Implications
The fallout from this breach is significant. Federal investigators, including senior leadership from the FBI’s cyber division, have confirmed that the New Orleans field office has launched an official probe into the breach at idscan.net. The inclusion of sensitive identification, including Common Access Cards (CAC)—government-issued IDs that grant physical entry to secure facilities—presents a national security risk that extends far beyond individual identity theft.
Industry experts emphasize that this incident exposes a dangerous trend: the outsourcing of identity verification to third-party vendors who are not being held to sufficiently high security standards. Larry Baldwin, a principal intelligence researcher at the cybersecurity firm Cybera, warns that the compromise of these databases undermines the entire concept of secure identity verification.
"Just when it seems like we’re making some headway in improving authentication controls through driver’s license verification systems, this happens, and the very thing those improvements are dependent on are compromised," Baldwin said. He noted that the availability of this data provides criminals with everything needed to open fraudulent lines of credit or impersonate individuals who are attempting to maintain privacy, such as those fleeing domestic violence or individuals in sensitive government programs.

The reliance on such systems is often justified under the guise of child safety or fraud prevention, yet the result is the centralization of millions of sensitive documents in databases that are clearly vulnerable to sophisticated actors. As Edwards noted, the lack of oversight regarding how these third-party vendors store and protect the data they collect is a systemic failure that leaves the public exposed.
Corporate Responses and Platform Shutdown
Following the initial reports, idscan.net issued a brief notice confirming a "data security incident." The company stated that an unauthorized third party may have accessed and copied customer information, including full names and government-issued identification numbers. They indicated that they are in the process of notifying affected individuals and offering credit protection services.
The corporate ecosystem surrounding idscan.net has also begun to distance itself. A spokesperson for Caesars Entertainment stated that the company has not been a client of idscan.net since February 2025 and had no active accounts at the time of the breach. They maintained that they did not authorize the retention of any data by the vendor and that the incident should have no impact on their customers.
Shortly after the publication of initial reports regarding the breach, the Nexus identity theft service vanished from the dark web. The login page, which previously facilitated the sale of millions of records, was replaced with a plain text message: "This service is no longer available."

While the platform is currently offline, the damage is already done. The exposure of 153 million records—ranging from everyday citizens to high-ranking officials—highlights the fragility of modern digital identity infrastructure. For the millions of people whose information is now circulating in the criminal underworld, the long-term consequences of this breach, including potential financial fraud and identity impersonation, are only just beginning to manifest. The FBI’s investigation into the source of the leak and the practices of idscan.net remains ongoing, as victims are left to navigate the aftermath of one of the largest identity data breaches in recent history.

