Advertisement
Advertisement
Advertisement
2 September 2026ยท7 min readยทBy Sloane Meyer

FBI Probes Service Selling 153M Drivers Licenses

FBI probes Nexus, a dark web service selling 153M drivers licenses, possibly sourced from idscan.net breach.

FBI Probes Service Selling 153M Drivers Licenses

FBI Probes Nexus Identity Theft Service After 153M License Leak

The FBI has launched probes this week into a dark web service called Nexus, which claims to sell digital scans of more than 153 million drivers licenses from the United States and Canada, a staggering haul that would represent one of the largest breaches of personal identification data ever reported. The New Orleans field office of the Federal Bureau of Investigation (FBI) today opened an official inquiry into the source of those images. But that's just the beginning. Investigators can't yet verify Nexus's claims, and they're now racing to determine whether the scans are real, stolen, or fabricated, a task made harder by the service's encrypted infrastructure and anonymous operators who've left few digital footprints. That's the challenge. So the bureau's cyber unit is coordinating with Canadian authorities, while agents in New Orleans begin subpoenaing payment processors and tracing the cryptocurrency wallets linked to Nexus, hoping to identify the sellers before the data spreads further. It's a race against time.

The service appeared on the Russian cybercrime forum Exploit on Monday, when a source flagged it to security journalist Brian Krebs. The proprietor offered Krebs's own Virginia drivers license as a free sample in the initial sales thread. That personal touch set off a chain of investigation that would eventually pull in the FBI, expose a major corporate data breach, and end with the entire service vanishing from the dark web within hours of going public.

The Scale of the Data Dump

Nexus claims to hold more than 153 million drivers licenses for people in the United States and Canada. The numbers get worse from there. The service also lists more than 10 million identification cards, over three million travel documents or international IDs, and at least 579,000 medical cards.

A blank search of the Nexus database returns roughly 11.5 million pages of results, with about 15 records per page. Canadian licenses account for approximately 1.1 million records, with the largest concentration from Ontario at 473,673. The bulk of the stolen data belongs to Americans.

Some records carry puzzling source notations. The label "CDL" likely refers to commercial drivers licenses. Another notation, "CAC," may point to Common Access Cards, the government-issued identity cards that grant physical access to secure buildings and rooms.

The identity theft service also holds marijuana dispensary cards. That detail would become a key clue.

Fresh Data, Continuously Harvested

The people behind Nexus claim they have been "continuously exfiltrating new data for over a year" into their private database. The numbers support that boast. Over a single 24-hour period, the count of available drivers license records jumped by nearly 400,000.

Each record can include six image files: three pairs of photos showing the front and back of the license. These include a basic image scan plus infrared and ultraviolet versions of the same documents. Every image file carries a date and timestamp appended to its filename.

Those timestamps became the key to unraveling where the data was coming from.

Tracking the Source Through Travel Records

Krebs asked more than a dozen friends and family members for permission to search for their licenses in the Nexus database. Nine people came back with matches. Every single one confirmed having traveled on or very close to the dates embedded in their image timestamps.

FBI Probes Service Selling 153M Drivers

The timezone appeared to be Greenwich Mean Time, based on cross-referencing car rental records from several volunteers. At first, airports seemed like the obvious culprit. But that theory collapsed when the investigation revealed there were no passports in the dataset. Only some of the volunteers said they had shown their drivers license at airport security on their travel day.

One person in the dataset had not flown at all recently but had been renting a car from Hertz for several months around the timestamp date. Two federal employees who helped with the research said they used other forms of government identification at airport security. Both later rented vehicles from Hertz at their destinations.

Krebs found his own mother's license in the service as well. Her image timestamps were just seconds apart from his. They had handed their licenses to the same Hertz rental car representative at the same time.

A Dispensary Connection Emerges

Security researcher Zach Edwards found his license in the Nexus database. The timestamp matched the middle of a trip to Las Vegas for the DEFCON security conference. Edwards did not rent a car in Vegas. He did hand over his license at the TSA checkpoint, at a marijuana dispensary, and at his hotel.

Edwards said only one of those three locations scanned his ID in a device. That was Planet13. But that's a multi-state dispensary chain with stores in California, Florida, Illinois, and Nevada, so it's hardly a small operation, and we can't overlook the fact that its reach spans four states.

In 2022, idscan.net published a press release announcing an exclusive identity verification agreement with Planet13's dispensaries nationally. The company processes ID verification for more than 1,000 marijuana dispensaries across 19 states.

Idscan.net Under Investigation

Idscan.net's trust page lists major clients including Hertz, Target, Fedex, Motorola Solutions, financial services firm Jack Henry, and Caesars Entertainment. The company's own documentation states that its technology scans IDs with both infrared and ultraviolet light, matching the image types found in the Nexus records.

Idscan.net says its systems perform more than 21 million verifications monthly at over 20,000 locations worldwide.

Contacted about the breach, idscan.net said it was investigating the matter. Jillian Kossman, a marketing and operations leader at the company, offered little in the way of answers.

High-Ranking Officials Caught in the Breach

The stolen data includes drivers licenses for U.S. Defense Secretary Pete Hegseth and the assistant director of the FBI.

The timestamps matched a recent Hertz car rental during a vacation.

Baldwin warned that the service poses serious threats beyond financial fraud. State-issued drivers licenses are commonly used as proof of identity when opening new lines of credit. But the exposure goes deeper for people who cannot meaningfully change their appearance.

That category includes those fleeing domestic violence and individuals in the federal witness protection program, people who have been assigned entirely new identities after agreeing to cooperate with federal authorities in racketeering and conspiracy investigations.

"Just when it seems like we're making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised," Baldwin said.

The Service Vanishes

It's gone. Within hours of the story breaking, the Nexus identity theft service vanished from the dark web, its familiar login page replaced by a stark, plain text message that read simply, "This service is no longer available," leaving users and investigators to wonder what had actually happened behind the scenes. But they're not expecting an answer.

The investigation remains active. The FBI probes continue, and idscan.net has yet to provide a substantive statement about how the breach occurred or how many of its clients may be affected.

For the millions of people whose license scans are now in the hands of criminals, the damage may already be done. The data is out there. The question now is what the FBI probes will uncover about how it got out, and whether the companies that collected this sensitive information will ever be held accountable.

Frequently Asked Questions

What is the FBI probing according to the article?

The FBI probes a dark web service called Nexus that claims to sell digital scans of over 153 million drivers licenses from the US and Canada. The New Orleans field office opened an official inquiry into the source of these images, and the investigation is ongoing.

How did the FBI begin investigating the Nexus service?

The FBI's cyber unit coordinated with Canadian authorities while agents in New Orleans began subpoenaing payment processors and tracing cryptocurrency wallets linked to Nexus. They aimed to identify the sellers before the data spread further.

What evidence did security researcher Zach Edwards provide that pointed to a specific company?

Edwards found his license in Nexus, and the timestamp matched a Las Vegas trip. He recalled only one location scanned his ID with a device - Planet13, a dispensary chain. This led to investigating idscan.net, which had an exclusive identity verification agreement with Planet13.

Who are some of the high-ranking individuals whose data was stolen according to the article?

The stolen data included licenses for U.S. Defense Secretary Pete Hegseth and the assistant director of the FBI. Their timestamps matched a recent Hertz car rental during a vacation.

What happened to the Nexus service after the story broke?

Within hours of the story breaking, the Nexus service vanished from the dark web. Its login page was replaced with a message saying, "This service is no longer available," leaving users and investigators wondering what happened.

Sloane Meyer
Written by
Cybersecurity Editor

Sloane Meyer covers cybersecurity, privacy and the threats facing individuals and organisations online. She explains how attacks happen and what can be done to stay protected.

๐Ÿ’ฌ Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement