The Federal Bureau of Investigation has opened an official investigation into a massive data breach involving more than 153 million driver’s license scans being sold on the dark web, marking one of the largest exposures of government-issued identity documents in North America.
The dark web service, called Nexus, advertised its stolen data on a Russian cybercrime forum called Exploit beginning August 31, according to independent cybersecurity journalist Brian Krebs. The service claims to have 153 million U.S. and Canadian driver’s licenses, along with millions of other identification cards, travel documents, and medical records.

The New Orleans field office of the FBI launched its formal inquiry after Krebs’ reporting alerted the agency to the breach. In a brief statement, the bureau said it was “looking into the incident” but could not comment further “due to the ongoing nature of the investigation,” according to Reuters.
The stolen license scans include high-resolution images with infrared and ultraviolet versions, along with photos and personal information. Krebs confirmed the authenticity of the data by working with nine individuals whose licenses appeared in the database, matching timestamps to dates when they rented vehicles from Hertz or visited marijuana dispensaries. The evidence points to Louisiana-based identity verification company IDScan.net as the likely source of the breach.
IDScan.net processes identity verification for more than 1,000 marijuana dispensaries across 19 U.S. states and serves major clients including Hertz, Target, FedEx, Motorola Solutions, and Jack Henry, according to its website. The company confirmed it was investigating the matter but has not released a detailed statement.
Cybersecurity researchers described the breach as unprecedented in its scope. Zach Edwards, a threat researcher at Infoblox, told Reuters that “there’s never been a breach of driver’s licenses at this scale,” and warned that the ongoing extraction of fresh data “means that this attack created legitimate national security risks for high-profile individuals.” The database includes driver’s license information for U.S. Defense Secretary Pete Hegseth, according to Krebs’ reporting.

The Nexus service claims to have been continuously extracting data for over a year from “a major identity verification company.” The number of driver’s license records available increased by nearly 400,000 in just 24 hours, suggesting fresh data is being harvested and uploaded on a regular basis. Within hours of Krebs publishing his report, the Nexus service disappeared from the dark web, replaced with a message stating “This service is no longer available.”
The breach dwarfs previous major identity theft incidents. The 2017 Equifax data breach, which exposed personal information of approximately 147 million Americans, remains one of the largest ever recorded. However, the current driver’s license breach is notable because it involves government-issued identity documents with high-resolution biometric images, creating heightened risks for identity fraud and potentially endangering individuals in witness protection programs or those fleeing domestic violence, according to cybersecurity experts.
The incident underscores vulnerability in third-party identity verification services that collect sensitive data on behalf of major corporations. Security researchers and privacy advocates have raised concerns about the proliferation of identity verification requirements across online and offline services, arguing that each additional vendor collecting driver’s license images increases the risk of a catastrophic breach.
Sources
- Krebs on Security — Detailed investigation of the Nexus service, confirmation of stolen data authenticity, identification of IDScan.net as the source, timestamps and methodology, ongoing data extraction, and service disappearance.
- Reuters — FBI confirmation of investigation, statement on ongoing nature, Zach Edwards’ quote on unprecedented scale and national security risks, Krebs’ initial discovery and reporting.











