Massive Dark Web Breach Exposes Over 153 Million North American Driver’s Licenses Tied to Identity Verification Firm

By Cyber-Security Investigations Desk
Published September 2026
Main Facts
A newly surfaced dark web service known as “Nexus” has rattled the cybersecurity landscape by offering digital scans of more than 153 million driver’s licenses belonging to citizens in the United States and Canada. Launched quietly on Russian cybercrime forums, the database does not merely traffic in basic personally identifiable information (PII); it provides high-resolution, multi-spectral image files—including standard, infrared, and ultraviolet scans—complete with precise timestamps.
Investigations into the data repository, spearheaded by veteran security journalists and corroborated by independent researchers, indicate that the leak originates from an active, large-scale compromise of a major Louisiana-based identity verification provider, IDScan.net. The stolen trove includes approximately 153 million U.S. and Canadian driver’s licenses, over 10 million identification cards, 3 million international travel documents, and nearly 579,000 medical and specialized dispensary cards.
The gravity of the breach escalated quickly as investigators discovered that records within Nexus belong to high-ranking officials, including U.S. Defense Secretary Pete Hegseth, prominent privacy researchers, and federal employees. The Federal Bureau of Investigation (FBI) has since launched an official inquiry into the breach, shining a harsh spotlight on the systemic vulnerabilities embedded within the booming digital identity verification ecosystem.
Chronology of the Discovery
The unfolding crisis began on Monday, August 31, when a trusted industry source alerted security analysts to a newly registered user advertising an aggressive identity theft service on Exploit, a prominent Russian-language cybercrime forum. The threat actor claimed to house the digital documents of more than 170 million North American individuals. To prove the legitimacy of the database, the proprietor listed a prominent cybersecurity journalist’s Virginia driver’s license as a free promotional sample.

By Tuesday, September 1, the scale of the repository became fully apparent. A blank query on the Nexus platform generated roughly 11.5 million pages of results, averaging 15 entries per page. Independent checks on the data revealed that records were being dynamically updated; within a single 24-hour window, nearly 400,000 new driver’s license records were uploaded to the portal, demonstrating automated, semi-regular exfiltration from the source.
As researchers began spot-checking records against personal travel logs, a pattern emerged linking the precise timestamps of the stolen images to real-world interactions at car rental counters and specialized retail establishments. By the afternoon of September 2, word of the probe reached the federal level. Following inquiries that involved the exposure of records tied to assistant directors of the FBI, senior bureau leadership convened an emergency conference call with researchers. By the close of that day, the FBI’s New Orleans field office formally opened a criminal investigation into the intrusion at IDScan.net.
The operational lifecycle of the Nexus service proved short-lived yet devastating. Shortly after the initial findings were published online, the Nexus dark web portal abruptly went offline, replacing its interactive login interface with a terse plain-text message declaring, "This service is no longer available." Days later, on September 8, IDScan.net officially acknowledged the security incident, confirming that an unauthorized third party had accessed and potentially exfiltrated sensitive customer records.
Supporting Data and Evidence
The technical depth of the Nexus leak separates it from standard credential-stuffing dumps or scraped public records. A comprehensive breakdown of the database reveals a staggering accumulation of physical identity documents:
- Driver’s Licenses: Over 153 million records spanning the United States and Canada. This includes roughly 1.1 million Canadian entries, with the highest concentration originating from Ontario (473,673 records).
- State and Federal Identification Cards: More than 10 million IDs, including notations indicating commercial driver’s licenses (CDLs) and potentially Common Access Cards (CACs) used for secure physical building access.
- Travel and International Documents: Over 3 million passports and international IDs.
- Specialized Records: At least 579,000 medical marijuana dispensary cards and alternative state-issued permits.
Forensic analysis of the image files underscores the sophistication of the data collection. Many affected individuals discovered that their records contained up to six distinct image files: front-and-back pairs captured under normal white light, basic digital scans, and specialized infrared and ultraviolet captures. These advanced spectral images are typically generated only by professional-grade ID verification hardware, such as the multi-spectral scanners manufactured by IDScan.net and deployed across thousands of commercial storefronts worldwide.

Cross-referencing timestamps on the files with personal travel itineraries revealed a striking correlation. Multiple individuals—including journalists, privacy experts, and federal workers—confirmed that the timestamps appended to their stolen files matched the exact window during which they presented their physical identification at commercial hubs. For instance, researchers who rented vehicles through major providers like Hertz found that their file timestamps aligned down to the minute with their counter transactions, where staff retained physical possession of licenses for manual processing or machine reading.
Official Responses and Corporate Finger-Pointing
As the fallout from the breach rippled across corporate America and federal agencies, impacted entities scrambled to issue statements, distance themselves from the compromised vendor, or initiate internal reviews.
IDScan.net, the focal point of the investigation, initially maintained a cautious posture. Jillian Kossman, a marketing and operations leader at the company, acknowledged receipt of researcher inquiries, noting that the intelligence provided was "helpful to our team’s investigation." On September 8, IDScan.net published a formal notification admitting that an unauthorized third party may have accessed and copied customer information, including full names, driver’s license numbers, and other government-issued identifiers. The firm stated it was beginning the process of notifying affected parties and providing credit protection services.
The ripple effects also hit companies previously listed as corporate clients on IDScan.net’s promotional materials. Caesars Entertainment moved quickly to distance itself from the controversy. A spokesperson for Caesars stated that the hospitality giant had not been a client of IDScan.net and had ceased using their VeriScan software package in February 2025. According to Caesars, no active accounts existed at the time of the incident, and the company never authorized the retention of consumer data, asserting that the breach should have zero operational impact on its patrons.
Meanwhile, representatives for Hertz, Target, FedEx, and other major brands heavily integrated with digital verification workflows faced mounting questions regarding third-party data retention policies. Federal authorities, led by the FBI’s New Orleans field office, continue to probe the exact mechanisms utilized by threat actors to siphon data from IDScan.net’s infrastructure over a reported period exceeding 12 months.

Implications for Privacy, Security, and Public Policy
The Nexus breach represents a watershed moment for modern digital identity management, exposing the profound risks inherent in the widespread collection and storage of sensitive biometric and identification data by private vendors.
Cybersecurity experts point out that state-issued driver’s licenses serve as the foundational root of trust for modern financial systems, enabling bad actors to open fraudulent credit lines, secure loans, and bypass remote know-your-customer (KYC) checks with relative ease. Furthermore, the inclusion of multi-spectral scans creates a clear pathway for sophisticated, AI-driven injection attacks capable of spoofing modern facial recognition and liveness detection algorithms.
The human cost of such a sweeping data loss extends far beyond financial fraud. Larry Baldwin, principal intelligence researcher at Cybera, highlighted the severe physical danger posed to vulnerable populations whose identities cannot be easily modified. This includes individuals escaping domestic violence situations and persons integrated into federal witness protection programs. For these groups, the exposure of a permanent, high-resolution driver’s license scan can compromise personal safety in ways that standard password leaks never could.
Finally, the incident has reignited a fierce debate over the legislative push to mandate age-verification and identity-checking schemes across the internet. Lawmakers and privacy advocates argue that policies requiring everyday citizens to surrender driver’s licenses to countless third-party websites—often under the guise of child safety or online security—inevitably create massive, centralized honeypots of high-value data.
As Zach Edwards, privacy researcher and creator of DecryptAds, summarized:

"This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses… These systems are putting sensitive data into more and more third-party vendors, and we don’t have nearly the oversight to ensure they are safe."
With the Nexus portal currently offline but its underlying database likely archived in the hands of sophisticated cybercrime syndicates, the true impact of this historical breach will likely take years to fully quantify, fundamentally altering how consumers and regulators view the trade-off between digital convenience and personal privacy.
