A California DMV sample driver's license bearing the fictional name and photo used for illustration
A sample California driver’s license issued by the state DMV for illustration. Scans of real licenses — front, back, infrared, and ultraviolet — were offered for sale this week on a dark-web service called Nexus. Image: California DMV, public domain, via Wikimedia Commons.

On Monday, August 31, a new user on the Russian-language cybercrime forum Exploit opened a sales thread with an unusual free sample: the Virginia driver’s license of investigative journalist Brian Krebs. The seller was advertising Nexus, a dark-web identity-theft service claiming digital scans of more than 153 million driver’s licenses from the United States and Canada — plus more than 10 million ID cards, 3 million travel documents, and at least 579,000 medical cards. Also in the catalog: the license of Defense Secretary Pete Hegseth, offered for $100, and the license of an FBI assistant director. Within 48 hours the FBI’s New Orleans field office had opened an official investigation, the prime suspect had emerged — New Orleans identity-verification vendor IDScan.net — and Nexus itself had vanished, leaving a plain-text message: “This service is no longer available.” This brief lays out what was for sale, how Krebs traced the apparent source, what a buyer can actually do with your license, and where the investigation stands — with every claim sourced at the bottom of the page.

What Nexus Was Selling

Krebs, who broke the story on KrebsOnSecurity, was able to examine the service before it went dark. His account and the follow-on reporting establish the scale:

  • The inventory claim is plausible. A blank search on Nexus returned roughly 11.5 million pages of results at about 15 records per page — consistent with the advertised 153 million. Canadian licenses accounted for about 1.1 million records, with the largest concentration from Ontario (473,673); the bulk were American.
  • The records are unusually rich. Krebs’s own record contained six image files: front-and-back photos of his license captured as a basic scan, plus infrared and ultraviolet versions of the same images, each with a date and timestamp. Many records also display the customer’s photo.
  • The data was still flowing. The number of license records grew by nearly 400,000 in a single 24-hour period. In their Exploit post, the operators claimed they had “been continuously exfiltrating new data for over a year” from “a major identity verification company” whose customers include multiple Fortune 500 companies.
  • Some records raise separate alarms. The dataset includes marijuana dispensary cards, records tagged “CDL” (apparently commercial driver’s licenses), and records tagged “CAC” — which may refer to Common Access Cards, the credentials that control physical access to government buildings and secure rooms. That reading of the tag is Krebs’s inference, not a confirmed fact.

Where the Data Appears to Come From

Krebs turned the dataset against itself, using the timestamps on the images as a forensic trail. He asked more than a dozen friends and family members for permission to search for their licenses. Nine were found — and every one confirmed having traveled on or very close to the date stamped on their images. The pattern that emerged points away from airports and toward a single vendor:

  • Krebs and his mother have timestamps seconds apart — the moment they handed their licenses together to a Hertz rental car representative. Krebs never showed his license at the airport that day; he used a passport at the TSA checkpoint.
  • Two federal employees in the dataset used other government IDs at airport security but handed their state licenses to Hertz at their destinations.
  • Security researcher Zach Edwards found his license with a timestamp from his DEFCON trip to Las Vegas. Of the three places he presented ID — TSA, his hotel, and a Planet 13 marijuana dispensary — only the dispensary definitely scanned it in a machine. Planet 13 has held an exclusive identity-verification agreement with IDScan.net since 2022.
  • Cybera intelligence researcher Larry Baldwin found front-and-back scans of his license timestamped to a Hertz rental on a recent vacation.

The ultraviolet and infrared images are the technical fingerprint. IDScan.net’s own documentation says its technology scans IDs under both kinds of light, and the company says it performs more than 21 million verifications a month at 20,000-plus locations. Its public “trust” page lists Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment as clients, and says it handles ID verification for more than 1,000 marijuana dispensaries in 19 states. IDScan.net has not confirmed a breach; the company told Krebs it is investigating and called his information “welcome, and helpful to our team’s investigation.” Caesars, for its part, told Krebs it has not been an IDScan client since February 2025, had no active accounts at the time of the incident, and never authorized IDScan to retain its data — despite appearing on the vendor’s client page. That denial opens a second question the FBI will likely pursue: how long the company keeps data after a customer relationship ends.

How the license scans appear to have reached the dark web Diagram tracing driver's license scans from rental counters and dispensaries through identity-verification scanners into a private database and onto the Nexus dark-web storefront, then to criminal buyers. You hand over your license Hertz rental counters · Planet 13 & 1,000+ dispensaries hotels, casinos, retailers — 20,000+ locations Identity-verification scanner captures front + back in visible, infrared & ultraviolet light evidence points to vendor IDScan.net — not confirmed apparent breach — exfiltration “for over a year” Private database — 153M+ licenses still growing: +400,000 records in 24 hours plus 10M ID cards, 3M travel docs, 579K medical cards Nexus — dark-web storefront preview before purchase · Hegseth’s license: $100 advertised on the Exploit forum, Aug 31, 2026 Buyers deepfake KYC fraud · counterfeit physical IDs · account takeover credit & tax fraud · stalking · espionage targeting FBI New Orleans field office opened an official inquiry Sept 2, 2026
The apparent path of the scans, reconstructed from timestamps on the images and the vendor’s own documentation. The IDScan.net breach remains suspected, not confirmed; the FBI’s New Orleans office opened its inquiry on September 2.

What a Buyer Can Do With Your License

Most breach fatigue is earned: another leak of names, addresses, and partial numbers. This one is different, because the stolen artifact is the document our entire identity system treats as proof. A front-and-back scan with infrared and ultraviolet layers, a face photo, and a home address is not a clue to your identity — for most verification systems, it is your identity. Security researchers and fraud-prevention firms describe five concrete abuse paths.

1. Deepfake-powered account opening. Banks, lenders, employers, landlords, and crypto exchanges increasingly onboard customers with a “photo of your ID plus a selfie” check. Fraud researchers report that deepfake toolkits costing as little as $20 can defeat document, selfie, and liveness checks — and that is with fabricated IDs. A genuine scan of a real license removes the easiest detection layer, document authenticity, leaving only the face match to beat; Nexus conveniently supplies the victim’s real photo for the deepfake to wear. The financial sector’s own coordinating council now teaches this exact scenario — a stolen identity paired with a deepfaked license passing a bank’s verification — as a baseline threat. The result is new credit cards, loans, and accounts in your name: new-account fraud alone hit 5.4 million Americans last year, according to Javelin’s 2026 Identity Fraud Study.

2. Counterfeit physical IDs that pass inspection. Real licenses carry UV-reactive security features precisely because counterfeiters usually miss them — IDScan.net’s own public guidance says so. This dataset hands a counterfeiter reference images of exactly what the ultraviolet and infrared layers of a genuine license look like. A physical fake built from that blueprint can survive the blacklight check at a bank, a car rental counter, or a traffic stop — a capability no text-based data dump provides.

3. Account takeover and SIM swapping. License number, date of birth, address, and an ID photo are what phone carriers, banks, and email providers ask for in “prove it’s you” recovery flows. With a genuine license image, an attacker can satisfy “upload a photo of your ID” challenges, hijack a phone number, and reset every account tied to it. Account takeover drove roughly $16 billion of the $27.2 billion in US identity-fraud losses Javelin counted for 2024.

4. Credit, benefits, and tax fraud at scale. Driver’s licenses are the default proof of identity for opening lines of credit. Fraud rings increasingly convert stolen identities into synthetic businesses to extract loans and launder money, and stolen-identity tax-refund fraud has cost the Treasury billions over the past decade. The FTC reports consumers lost a record $15.9 billion to fraud in 2025 — a figure that counts only what was reported.

5. Physical safety and national security. Each record pairs a home address with a current facial photograph. Cybera’s Larry Baldwin points out who that endangers most: people fleeing domestic violence, and witnesses in federal protection who were given new lives on the condition that their old ones stay buried — AI face-matching makes a leaked photo effectively permanent. The timestamps add a pattern-of-life layer, recording where and when a victim physically presented ID. And the storefront model allows targeted shopping: Hegseth’s license was priced at $100, and an FBI assistant director’s was listed too. For a foreign intelligence service, that is a ready-made spear-phishing and impersonation kit against specific officials — for the price of a nice dinner.

The Investigation So Far

The case moved fast once Krebs began asking questions. After he mentioned to a trusted source that Nexus was selling an FBI assistant director’s license, word reached the bureau; on September 2, Krebs was added to a conference call with a half-dozen agents, including senior leaders of the FBI’s cyber division, who disclosed that the New Orleans field office had that day opened an official investigation into an apparent breach involving IDScan.net. The company has acknowledged only that it is investigating. Hertz has not publicly responded. Hours after Krebs published, the Nexus site went dark — a routine move for such services, which often resurface on a new domain. Krebs also notes that FBI Director Kash Patel’s license was not found in the dataset.

Three Readings of the Breach

The same 153 million records are being read three different ways.

The Left: an unregulated data industry finally met its breach

On the left, the scandal is that a private vendor most Americans have never heard of was allowed to amass one of the largest identity databases on the continent — quietly, through rental counters and dispensary doors — with no meaningful federal oversight of what it collects, how long it keeps it, or how well it defends it. The Caesars denial, they note, suggests data may have been retained even after a client walked away. This reading reaches for structural fixes: a comprehensive federal privacy law with data-minimization rules, retention limits, mandatory security audits for identity vendors, and breach liability with teeth. As Zach Edwards put it, ID-check mandates “are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.” Their core claim: 153 million people never chose to trust IDScan.net — the choice was made for them, and the bill just came due.

The Right: government built the honeypot

On the right, the villain is not the vendor but the mandate. Real ID requirements, age-verification laws, and an ever-longer list of transactions that demand government ID are what funnel 21 million licenses a month through private scanners in the first place. Every new “show your ID” rule — many sold as protecting children or securing elections — deposits more sensitive data into more private databases, each one a target. This reading is skeptical that the answer to a breach caused by compulsory data collection is more compulsory data collection, and notes the irony that verification systems built to stop fraud have now handed fraudsters their best raw material in years. Their core claim: the less identity the system demands, the less there is to steal — repeal the mandates, shrink the honeypots, and let liability for negligent vendors run through the courts.

The Center: the document itself is now compromised

The center’s reading starts from what neither side disputes: the thing we redesigned our security around — the state-issued license, checked by machine — has been copied 153 million times, security features and all. Baldwin’s formulation is the headline: “Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised.” Centrists note that the practical agenda is the same regardless of ideology — retention limits, audit standards, and breach notification for identity vendors draw support in both parties — and that individuals can act now: a free credit freeze with the three bureaus blunts the most common monetization path. Their core claim: whether the fix is more regulation or fewer mandates, the era of treating a photographed license as proof of personhood ended this week.

What Happens Next

Four threads to watch. First, the FBI probe out of New Orleans: if agents confirm the IDScan.net vector, this becomes one of the largest identity-document breaches on record, and questions about retention practices and disclosure timelines will follow for the company and its marquee clients. Second, the storefront: Nexus’s disappearance is likely tactical, and the data — once sold — does not come back; expect the collection to circulate in criminal markets for years. Third, the policy fight: age-verification and ID-mandate bills are pending in Congress and multiple statehouses, and this breach will be Exhibit A for both sides of that debate. Fourth, the personal one: because the stolen items cannot be changed — you cannot reissue your face — the standard advice applies with unusual force: freeze your credit with Equifax, Experian, and TransUnion (free under federal law), place fraud alerts if you suspect misuse, and treat any “verify your identity” contact with new suspicion. For 153 million people, the driver’s license in the wallet is now, effectively, public.

A note on framing: this article summarizes published reporting — primarily Brian Krebs’s firsthand investigation — and public statements by the companies involved. The breach of IDScan.net is suspected and under FBI investigation, but has not been confirmed by the company or the government; the reading of “CAC” records as Common Access Cards is an inference, not an established fact. No company or individual named here has been accused of a crime. Positions attributed to political groups are summaries, not endorsements.

Sources

Image credits: sample California driver’s license — California Department of Motor Vehicles, public domain, via Wikimedia Commons.