September 29, 2026

Massive Dark Web Breach Exposes Over 153 Million North American Driver’s Licenses Tied to Louisiana Verification Firm

massive-dark-web-breach-exposes-over-153-million-north-american-drivers-licenses-tied-to-louisiana-verification-firm

massive-dark-web-breach-exposes-over-153-million-north-american-drivers-licenses-tied-to-louisiana-verification-firm

By Global Cybersecurity Desk

A sprawling, highly organized identity theft marketplace has emerged on the dark web, offering digital scans of more than 153 million driver’s licenses and government-issued identification documents belonging to residents of the United States and Canada. Dubbed Nexus, the illicit service surfaced on Russian-language cybercrime forums, shocking the cybersecurity community with the sheer volume and granularity of its purloined data.

Investigative findings, corroborated by interviews with victims—including high-ranking U.S. government officials and prominent cybersecurity experts—strongly point to a massive, long-term data exfiltration event originating from idscan.net, a Louisiana-based identity verification company. The breach has triggered an official federal inquiry by the Federal Bureau of Investigation (FBI), raising urgent questions regarding the safety of third-party biometric and identity collection frameworks used across North America.


Main Facts: The Scale of the Nexus Operation

Launched in late August on the prominent Russian cybercrime forum Exploit, the Nexus service represents one of the largest single repositories of exposed identity documents ever cataloged on the dark web. According to the platform’s introductory marketing materials and backend metrics, the database includes:

  • 153 million+ driver’s licenses from the United States and Canada.
  • More than 10 million state and provincial identification cards.
  • In excess of 3 million international IDs and travel documents.
  • At least 579,000 medical and dispensary cards.

A preliminary technical audit of the service confirmed that these figures are not exaggerated. Running a blank search query across the Nexus database yields approximately 11.5 million pages of results, displaying roughly 15 distinct records per page. While the bulk of the victims are U.S. citizens, Canadian records are heavily represented, led by Ontario with over 473,000 compromised profiles.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

The sophistication of the harvested files sets Nexus apart from typical data dumps. Many individual records contain up to six distinct image files: front-and-back color scans, standard photographic renderings, and specialized infrared and ultraviolet (UV) light captures. Each file bears precise Greenwich Mean Time (GMT) timestamps. Furthermore, the repository includes sensitive specialty documents, such as commercial driver’s licenses (CDLs), marijuana dispensary identification cards, and Common Access Cards (CACs)—secure government credentials typically used to access military bases and federal facilities.


Chronology of the Discovery and Investigation

The exposure of the Nexus repository unfolded rapidly over a matter of days, driven by independent security researchers and investigative journalists who tracked the breach in real time.

  • Monday, August 31: A confidential source alerts security journalist Brian Krebs to a newly advertised service on the Exploit forum. Notably, the threat actor uses the journalist’s own Virginia driver’s license as a promotional "free sample" in the initial sales thread.
  • September 1 – September 2: Researchers cross-reference data points, comparing the embedded GMT timestamps on sample files with personal travel and rental histories. Multiple independent victims confirm that the precise timestamps on their exposed license scans match down to the minute when they presented their IDs at commercial service counters or restricted venues.
  • September 2 (Afternoon): As word of the investigation spreads, the New Orleans field office of the FBI launches an official criminal inquiry. Federal agents hold a conference call with researchers after discovering that Nexus is actively selling the credentials of senior U.S. government officials, including Defense Secretary Pete Hegseth and high-ranking members of the FBI’s own cyber division.
  • September 2 (Evening): Representatives for corporate entities listed as clients on idscan.net begin issuing disclaimers. Caesars Entertainment clarifies that it terminated its relationship with the verification firm in February 2025 and authorized no data retention.
  • September 2 (8:56 PM ET): Minutes after initial investigative reports are published, the Nexus dark web portal abruptly vanishes. Its login page is replaced with a stark, plain-text message: “This service is no longer available.”
  • September 8: idscan.net formally publishes a public data security incident notification, confirming that an unauthorized third party accessed and copied customer information, including full names and government-issued identification numbers.

Supporting Data: Connecting the Dots to IDScan.net

Determining the origin of the Nexus database required meticulous forensic tracking. Initially, investigators suspected airport security checkpoints. However, that hypothesis collapsed when researchers noticed a complete absence of U.S. passports in the dataset, alongside instances where victims had not flown recently.

The breakthrough came when researchers, including security expert Zach Edwards—founder of DecryptAds—analyzed the physical locations where they had recently presented their identification. Edwards discovered his driver’s license on the Nexus platform, bearing a timestamp that corresponded directly to a trip to Las Vegas for the annual DEFCON conference. While in Vegas, Edwards presented his ID at a TSA checkpoint, a hotel, and a commercial marijuana dispensary called Planet13.

Of those locations, only Planet13 utilized an electronic card reader to scan his ID. Public records confirm that Planet13 maintains an exclusive national identity verification partnership with idscan.net, a company headquartered in New Orleans, Louisiana.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

idscan.net’s technology is deeply embedded across various commercial sectors. The company’s corporate documentation boasts that its systems process over 21 million verifications monthly across more than 20,000 global locations. Its client roster and integration partners have historically included major brands such as Hertz, Target, FedEx, Motorola Solutions, and financial services giant Jack Henry.

Crucially, idscan.net’s verification hardware is explicitly designed to capture specialized imaging—including infrared and ultraviolet light scans—matching the exact technical format of the six-file bundles discovered inside the Nexus repository. For instance, multiple victims whose licenses appeared in the breach shared a common denominator: they had rented vehicles through Hertz on the exact day and time recorded by the Nexus timestamps, handing their physical licenses over to counter staff who retained them for processing.


Official Responses and Corporate Fallout

As the magnitude of the breach became clear, affected corporations and regulatory bodies scrambled to respond.

IDScan.net’s Acknowledgment

Initially offering cautious statements while internal reviews were conducted, Jillian Kossman, a marketing and operations leader at idscan.net, acknowledged the gravity of the researcher’s findings, noting that the external intelligence provided helpful metrics for their internal probe. On September 8, idscan.net released a formal compliance statement admitting that an unauthorized third party infiltrated its infrastructure, compromising sensitive customer parameters, full names, and government identification records. The company initiated direct notifications to impacted parties, offering complimentary credit protection services.

Caesars Entertainment Denies Association

In a swift corrective statement issued on September 2, a spokesperson for Caesars Entertainment pushed back against idscan.net’s public marketing materials, which had listed Caesars as an active client. The gaming and hospitality conglomerate stated that it ceased using idscan.net’s VeriScan software in February 2025, maintained no active accounts at the time of the breach, and never authorized the retention of guest identification data.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

Federal Law Enforcement Intervention

The FBI’s involvement underscores the national security implications of the breach. Because the database contains credential scans belonging to federal employees, military personnel, and cabinet-level officials—including Defense Secretary Pete Hegseth—the incident transcends typical commercial identity theft, prompting a high-priority counter-cybercrime investigation led by the bureau’s New Orleans field office.


Implications: The Crisis of Mandatory Digital Identity Scans

The sudden rise and disappearance of the Nexus marketplace has ignited a fierce debate regarding the systemic risks of corporate identity harvesting. Cybersecurity professionals warn that the breach shatters the foundational trust required for modern digital and physical authentication systems.

Larry Baldwin, principal intelligence researcher at cybersecurity firm Cybera, emphasized the profound dangers posed by leaked driver’s licenses. "State-issued driver’s licenses are the gold standard used to establish trust when opening new lines of credit, verifying banking accounts, and authenticating individuals remotely," Baldwin explained. "When hundreds of millions of these records are compromised in high-fidelity formats, the authentication framework crumbles."

Furthermore, Baldwin highlighted the grave physical and personal safety implications for vulnerable populations. Standard identity databases expose individuals who actively maintain anonymity for safety reasons, including victims fleeing domestic violence and individuals protected under the federal witness protection program. Because modern artificial intelligence-based image-matching tools can easily bypass minor physical alterations, static image scans present an unmitigated stalking and identification hazard.

Zach Edwards argues that the incident must serve as a regulatory wake-up call. Across retail, hospitality, and entertainment sectors, consumers are increasingly forced to surrender physical identity documents under the banner of safety, age verification, or fraud prevention.

FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security

"This episode should strengthen the resolve of people fighting back against online ID schemes that require countless providers to harvest driver’s licenses under the guise of protecting children," Edwards said. "These systems funnel sensitive personal data into the hands of third-party vendors, yet we lack the oversight and regulatory enforcement necessary to ensure they are safe."

Although the Nexus dark web portal pulled its infrastructure offline following public exposure, security analysts warn that the 153 million records have likely already been mirrored, traded, or downloaded by malicious actors worldwide. As the FBI’s investigation continues, the fallout from the idscan.net breach will likely cast a long shadow over the identity verification industry, forcing a painful re-evaluation of how corporations collect, process, and retain our most sensitive personal documents.