Dark Web Service Sells 153M+ US and Canada Driver’s Licenses; FBI Investigates

An identity theft service launched on the dark web this week is offering digital scans of over 153 million driver’s licenses, primarily from the United States and Canada. The New Orleans field office of the Federal Bureau of Investigation launched an official inquiry into the source of the leaked images, which appear to originate from an active breach at Louisiana-based identity verification provider IDScan.net.

The Anatomy of the Nexus Breach and Dark Web Exposure

The identity theft operation, dubbed Nexus, surfaced on the Russian cybercrime forum Exploit on Monday, August 31. The threat actor advertised access to digital identity documents covering more than 170 million North Americans. According to KrebsOnSecurity, the initial sales thread featured a free sample belonging to the author, who verified that his Virginia driver’s license scan matched a file containing front and back images alongside infrared and ultraviolet captures.

The scale of the database quickly became apparent during initial vetting. Running a blank search query across the Nexus platform yielded approximately 11.5 million result pages with roughly 15 records per page. The repository encompasses 153 million-plus driver’s licenses, more than 10 million identification cards, over 3 million travel documents and international IDs, and at least 579,000 medical cards. Canadian records account for roughly 1.1 million entries, with Ontario representing the largest concentration at 473,673 files. Researchers also identified marijuana dispensary cards, commercial driver’s licenses labeled as “CDL,” and Common Access Cards designated as “CAC”—government-issued credentials granting physical access to secure facilities.

Threat actors behind Nexus claimed data exfiltration had been ongoing for over a year into a private database. Over a 24-hour window, the catalog of available driver’s license records expanded by nearly 400,000, pointing to automated harvesting or continuous ingestion pipelines.

Tracing the Vector: From Airport Terminals to Car Rental Counters

Investigating the provenance of the scraped files required cross-referencing timestamps embedded in the metadata. Security researcher Zach Edwards, whose driver’s license appeared on Nexus, noted that his file’s timestamp mapped directly to a trip to Las Vegas for the DEFCON security conference last month. Edwards identified Planet13, a cannabis dispensary utilizing identity verification tech from IDScan.net, as a likely vector given their hardware-based ID scanning practices.

Other independent checks revealed a distinct operational pattern tied to physical transit and automobile rentals. The author and his mother found their respective records featuring timestamps separated by mere seconds—the exact window during which they handed physical identification cards to a Hertz rental car counter representative. Multiple individuals assisting with the investigation confirmed that their timestamps aligned precisely with vehicle rentals or physical ID checks handled by third-party vendors utilizing IDScan.net’s architecture.

IDScan.net provides identity verification services spanning more than 1,000 marijuana dispensaries across 19 U.S. states. Corporate documentation lists prominent enterprise clients including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. The underlying systems process over 21 million verifications monthly across more than 20,000 global locations using optical, infrared, and ultraviolet sensor arrays.

Federal Intervention and Enterprise Fallout

As independent verification efforts uncovered high-profile records—including the driver’s license of U.S. Defense Secretary Pete Hegseth and an assistant director of the FBI—federal authorities mobilized. Senior leaders from the FBI cyber division and agents from the New Orleans field office opened an official investigation into IDScan.net’s data handling practices.

Corporate responses followed swiftly as the breach exposed third-party vendor dependencies. A spokesperson for Caesars Entertainment stated that the hospitality giant had not been a client of IDScan.net and had not operated VeriScan software since February 2025. Caesars confirmed that no active accounts existed during the incident window and that IDScan.net lacked authorization to retain historical account data.

TOP US POLITICAL HEADLINE: Fbi Probes Dark-Web Breach Of 153M Driver'S Licenses — ArthIntel #Shorts

Cybersecurity analysts emphasized the severe downstream risks associated with compromised state-issued credentials. Larry Baldwin, principal intelligence researcher at Cybera, noted that driver’s licenses serve as primary authentication factors for opening financial lines of credit. Furthermore, the permanent nature of biometric data and facial scans poses severe risks for vulnerable populations, including individuals fleeing domestic violence or participants in federal witness protection programs whose physical features cannot easily bypass modern AI-based image matching tools.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin observed.

Shortly after public reporting and the initiation of the federal probe, on September 2, the Nexus dark web portal went offline, replacing its authentication gateway with a static text string declaring the service defunct.

Digital scans of more than 153 million driver's licenses leaked to the dark web | Channel 8 #Shorts
Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

IndyCar Announces New Driver Licensing and Qualification Criteria for 2027

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.