News

153 Million Driver’s Licenses Showed Up on the Dark Web. Here’s the Full Story.

153 Million Driver's Licenses Showed Up on the Dark Web

You handed your driver’s license to a Hertz agent, a hotel front desk, or a dispensary door scanner. Routine stuff. You didn’t think twice about it. Neither did they.

Somewhere along the way, that scan ended up in a database. And last week, that database ended up on the dark web, available for purchase, with your face, your address, your date of birth, and three layers of ID-verification images attached.

The FBI has opened an investigation. The dark web service selling the records has since gone offline. But the data itself is still out there, and the scale of this leak is unlike almost anything we’ve seen for identity documents specifically.

Quick answer: A dark web service called Nexus appeared on August 31, 2026, selling digital scans of over 153 million US and Canadian driver’s licenses. It also had 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Cybersecurity journalist Brian Krebs traced the likely source to IDScan.net, a Louisiana-based identity verification company used at Hertz locations, dispensaries, hotels, and thousands of other businesses. The FBI’s New Orleans field office opened an official investigation. Nexus went offline hours after the story broke, but the data itself remains unrecovered.

How This Story Broke

On August 31, 2026, a new seller appeared on Exploit, a Russian-language cybercrime forum. To prove the product was real, they offered a free sample. The sample was Brian Krebs’s own Virginia driver’s license.

Krebs is one of the most well-known cybersecurity journalists in the world. Whoever was running Nexus apparently thought using his license as bait would get attention. They were right, just not in the way they planned.

Krebs verified the license was genuine and then did something none of the other articles covering this story fully explain: he spent hours figuring out exactly where the data came from. He didn’t just report that 153 million licenses were for sale. He reverse-engineered the timestamp evidence to identify the source.

How Krebs Found the Source

Every image file attached to a license in the Nexus database had a date and timestamp baked into the filename. Krebs asked more than a dozen people to let him check whether their licenses were in the database. Nine of them were.

Every one of those nine people confirmed they had been somewhere close to that timestamp on that date. The pattern that emerged wasn’t airports. It was car rental counters and dispensaries.

Krebs’s own timestamp traced back to a June 2025 flight, where he had shown his passport at TSA but then handed his state-issued driver’s license to a Hertz agent at the rental counter at his destination. His mother’s license showed up in the same database too, with timestamps just seconds apart from his, because they had handed their licenses to the same Hertz agent at the same moment.

Privacy researcher Zach Edwards found his own license in Nexus too. His timestamp matched a dispensary visit during DEFCON, Las Vegas’s annual security conference. The dispensary was Planet13, and in 2022, IDScan.net published a press release announcing an exclusive identity verification partnership with Planet13’s locations nationally.

That is how Krebs connected the dots to IDScan.net. The timestamps on individual records matched the real physical locations of a company’s clients. The infrared and ultraviolet scanning was a signature feature IDScan.net publicly documents in its own marketing material.

What Is IDScan.net and Who Uses It?

IDScan.net is a Louisiana-based company that specialises in identity verification for in-person businesses. Its systems don’t just take a basic photo of your ID. They scan both the front and back with regular light, infrared, and ultraviolet, because those extra wavelengths reveal the security features on a genuine government-issued ID that a phone camera can’t detect.

The company says it runs more than 21 million verifications every month across more than 20,000 locations. Its client list, published on its own website, includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment.

That list is worth pausing on. These are not niche businesses. These are the rental counter at almost every major airport, a national pharmacy chain, the check-in desk at major hotels. If you’ve rented a car, bought legal cannabis at a large dispensary chain, or checked into a hotel with your license in the last few years, there is a real possibility your information passed through a system like this.

As we covered earlier this year in our piece on supply chain attacks and dark web warning signs, this is exactly the pattern: the target isn’t you directly. The target is the trusted vendor that sits between you and dozens or hundreds of companies at once.

IDScan.net has not confirmed a breach, has not issued a formal statement, and has not explained what happened. The company told Krebs only that it was investigating and that the information provided had been “welcome and helpful” to their team. That’s the entire response from a company that may be the source of the largest identity document leak in US history.

What Was in the Nexus Database and Why It’s Worse Than a Password Leak

Most data breaches expose email addresses, passwords, or credit card numbers. All of those are annoying, but most of them are fixable. Change the password. Cancel the card. It’s a headache, not a permanent problem.

This is different.

The Nexus database contained six image files per license record: a basic scan of the front and back, plus infrared and ultraviolet versions of both sides. Those extra scans are what identity verification systems use to confirm a license is real. A criminal with all six of those images doesn’t just know what you look like. They have everything needed to pass automated ID checks, create convincing fake documents, and potentially defeat the same verification systems designed to catch them.

The collection also included marijuana dispensary cards, some records marked “CDL” (commercial driver’s license), and others labeled “CAC,” which may refer to Common Access Cards, the government-issued ID cards used to access federal buildings and secure facilities. If that interpretation is correct, the database may contain credentials for physical access to sensitive locations.

That’s not speculation about identity theft risk. That’s a direct physical security concern, and it’s one none of the major outlets covering this story have highlighted clearly enough.

Krebs security researcher Larry Baldwin put it plainly: driver’s licenses are used as proof of identity when opening new credit accounts, renting property, and verifying yourself in countless daily situations. But the specific risk he pointed to that most coverage missed is this: the database could expose people who cannot safely be found. Domestic violence survivors. People relocated under witness protection. Anyone whose home address must remain private.

Your password can be changed in thirty seconds. You cannot change your face, your birth date, your address history, or the physical measurements printed on your license.

The Scale Is Almost Impossible to Process

Running a blank search on Nexus, with no keywords, returned 11.5 million pages of results with roughly 15 records per page. That math lands at roughly 150 to 170 million records. The database was also still growing: in the 24 hours Krebs monitored it, the number of driver’s license records increased by almost 400,000. The operators claimed they had been “continuously exfiltrating new data for over a year.”

Only about 1.1 million of the driver’s licenses belong to Canadians, with Ontario holding the largest share at around 473,000. The vast majority are American.

Defence Secretary Pete Hegseth’s driver’s license was in there, listed for $100. So was the license of an FBI assistant director, which is reportedly what prompted the agency to make contact with Krebs directly and confirm the investigation within hours of him finding it.

This is exactly the kind of data that ends up in private channels on the dark web long before anyone realises it’s missing. It doesn’t just get listed once and disappear when the listing goes down.

The Site Went Down. The Data Didn’t.

Hours after Krebs published his investigation, Nexus went dark. Its login page was replaced with a plain message: “This service is no longer available.”

That’s the single piece of good news in this story, and it’s limited good news. Removing the storefront doesn’t recover the records that were already downloaded, copied, or sold before the shutdown. It doesn’t undo whatever breach allowed the data to leave IDScan.net’s systems in the first place. It just means one specific marketplace is no longer advertising them.

This follows the same pattern we saw in the AudiA6 crypto laundering takedown, shutting down the visible service is a win, but the underlying data, credentials, or criminal networks continue operating elsewhere. The Nexus operators may simply rebuild under a different name.

Caesars Entertainment, which IDScan.net listed as a client on its trust page, later clarified that it had not been an active client since February 2025 and had not authorized IDScan.net to retain data from its accounts. IDScan.net confirmed this should have no impact on Caesars. That’s one confirmed non-victim, but it doesn’t narrow the exposure much given the rest of the client list.

What to Do Right Now

There is no public lookup tool to check whether your specific license is in this database. Given the scale, 153 million records covering most American adults with a driver’s license, assuming your data may be affected is a more practical starting point than waiting.

Freeze your credit. Contact Equifax, Experian, and TransUnion separately and request a security freeze. It’s free, doesn’t affect your credit score, and blocks anyone from opening new accounts in your name using your information. You can lift it temporarily if you need to apply for credit.

Check your credit reports. Go to AnnualCreditReport.com, the officially authorized source. Look for accounts, addresses, or inquiries you don’t recognize.

Set up fraud alerts. You only need to contact one of the three bureaus to place a fraud alert. That bureau is required to notify the others. A fraud alert tells lenders to verify your identity more carefully before extending credit.

Watch your existing accounts closely. A credit freeze blocks new credit but doesn’t stop misuse of accounts you already have. Turn on real-time alerts for transactions, password changes, and new device logins on bank accounts, credit cards, and email.

Contact your state DMV. Ask whether your state can flag your license, issue you a new license number, or add a notation to your record. Policies vary significantly by state, so call directly rather than looking online.

For a full step-by-step on what to do when your data is already out there, and why removing it isn’t realistic, our dark web data removal guide explains exactly what’s possible and what isn’t.

Report it if fraud has already happened. If someone has already used your information, report it to the FTC at IdentityTheft.gov. You’ll get a personalised recovery plan and an official affidavit useful for disputing fraudulent accounts.

Canadians should freeze files with Equifax Canada and TransUnion Canada, and report suspected fraud to the Canadian Anti-Fraud Centre.

The Bigger Problem This Exposes

Driver’s licenses were never designed to be scanned in bulk and stored centrally by private companies. They were designed to be shown, glanced at, and handed back. What IDScan.net and similar companies built is something different: a centralised, searchable database of identity document images covering a substantial fraction of the adult population of two countries.

Every time a business requires your license for a routine transaction, checking into a hotel, picking up a package, buying legal cannabis โ€” you don’t know which third-party verification software they’re using, where that software stores the image, how long it keeps it, or what security standards the vendor actually meets. You just hand over the card.

Zach Edwards said it plainly after finding his own license in Nexus: “These systems are putting sensitive data into more and more third-party vendors, and we don’t have nearly the oversight to ensure they are safe.”

That oversight gap is the story underneath the story. The Nexus service is gone. The conversation about who gets to collect and keep permanent biometric documents on millions of people, and what security standards they’re actually held to, is only just starting.

Frequnetly Asked Questions

What is Nexus?

A dark web identity theft service that appeared on the Russian cybercrime forum Exploit on August 31, 2026, selling digital scans of over 153 million US and Canadian driver’s licenses. It has since shut down.

Where did the data come from?

Based on timestamp analysis by Brian Krebs, the data appears to come from IDScan.net, a Louisiana-based identity verification company. IDScan.net says it is investigating. No breach has been officially confirmed.

Is my driver’s license in the database?

There is no public lookup tool. Given the scale, 153 million records, taking precautionary steps now is more practical than waiting to find out.

What should I do?

Freeze your credit with all three bureaus, check your credit reports at AnnualCreditReport.com, set up fraud alerts, and monitor your existing accounts. Contact your state DMV to ask about additional protections for your license.

Is the data gone now that Nexus is offline?

No. Taking the marketplace offline removes one place the data was sold, but does not recover records already downloaded or copied.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted