threat_intelligence3898 wordsRead on Arc Codex

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images. On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit. The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards. A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records). Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards. Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.” Other records carry the source notation of “CAC,” which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms. The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies. “We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.” Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis. The record that features my drivers license includes six image files — three pairs of photos of the license’s front and back — a basic image scan — as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral. Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT). At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp. Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz. After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport. Here’s where it gets interesting: I was able to find my mother’s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That’s notable because we both handed our licenses to the Hertz rental car representative at the same time. According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don’t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply. Zach Edwards is a well-known security and privacy researcher who recently launched a service called DecryptAds to help people better understand how online advertisers are tracking them. A scan of Edwards’s drivers license is available for purchase on this identity theft service, and Edwards said the timestamp on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference. Edwards told KrebsOnSecurity that although he did not rent a car in Vegas, he did hand over his license at the TSA checkpoint, at a marijuana dispensary in Vegas, and at his hotel (the Aria). But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary. Edwards said the dispensary he visited that day was Planet13, a multi-state chain with stores in California, Florida, Illinois and Nevada. In 2022, the New Orleans-based identity provider idscan.net published a press release announcing an exclusive identity verification agreement with Planet13’s dispensaries nationally. IDScan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states. The “trust” page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, Target, Fedex, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment. And as idscan.net’s own documentation states, the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world. Contacted by KrebsOnSecurity, idscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email. “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” wrote Jillian Kossman, a marketing and operations leader at idscan.net. During the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft service’s data. Probably they were tipped off when I shared with a trusted source that Nexus also is selling the drivers license information for the assistant director of the FBI (I did not find FBI Director Kash Patel’s license in Nexus). Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net. Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard. “This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.” Larry Baldwin is principal intelligence researcher at the cybersecurity firm Cybera. Baldwin said a front and back scan of his drivers license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation. Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools). This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities. “Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said. Update, Sept. 2, 6:05 p.m. ET: A spokesperson for Caesars Entertainment said Caesars has not been a client of IDScan.net and has not used VeriScan since February 2025, despite IDScan.net listing them as a client on their website. That person said Caesars had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from its accounts, and that IDScan.net said the incident should have no impact on Caesars Entertainment. Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.” This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp. Love the way you connected the dots to identify the source. Given the companies named, I am probably in that list too. What is a safe method to determine if my identity card was compromised in this breach? Assume it was. asshat reply Considering the site offering the scans is now offline, the only other alternative for now is to assume it wasn’t. Or don’t, nobody’s making you do anything. It’s wild how much your username and comment are reflecting you, mr asshat redditor Scans of personal driver’s licenses appears to be a de rigueur part of checking in at Labcorp locations and various medical facilities, as I can attest from multiple experiences in the last couple of years. When checking in at Quest, you can choose to decline scanning your ID, and check in with your phone number, which is not validated via SMS. Good job everyone I’m very proud of you keep up the good work Great article. Next question/leak: What private/secret information does Real ID and new Passports contain and how long\, if not already this information is compromised. It’s a bit late to hold ID vendors to a higher security standard, when the ID data has been exfiltrating for over a year. IDscan is so concerned about it, they sent a marketing person to talk to you. Surely, the next step is for IDscan to issue a press release saying “your security is our top priority”. … and to show we’re sincere, here’s a year’s free identity theft protection service, etc. IDscan.net sent us the message below on Wed 9/2/2026 12:55 AM UTC. Our company was considering doing business with them. Don’t believe we will be anymore. Message: We are writing to inform you of a potential security incident that we are actively investigating. Our relationship with our customers is extremely important to us, and we wanted you to hear about this directly from us at an early stage, even though our investigation is still preliminary. Earlier today, September 1, we received information suggesting that certain information may have been exposed and that IDScan.net may be implicated. We are working urgently to validate that information and determine whether any unauthorized access occurred, and the scope of such activity. Upon learning this information, we immediately initiated our incident response procedures, including: 1. Taking steps to secure potentially affected systems and investigate possible points of access; 2. Notifying our cyber insurance carrier and activating incident response protocols; 3. Engaging outside legal counsel; 4. Beginning the engagement of an independent forensic firm; 5. Coordinating with law enforcement; and 6. Preserving relevant logs and system data. At this time, we have not reached conclusions regarding the nature or scope of the incident, including what information was involved. However, based on the information available to us at this stage, we believe it is important to notify our clients promptly while we continue our investigation and work to determine the relevant facts. We are committed to keeping you informed as we learn more. You may reach out to privacy@idscan.net with any questions. Until some actual malice is shown, this seems like a good thing for them to have done, and the responsible actions of a company that actually is concerned about it. That’s the bar now? The bare minimum? You have to inform people their data is compromised – it is the law in all 50 states. Why is breaking it becoming so normalized? It makes sense for the people that have millions of dollars, but for people commenting on articles like this? Why are we fellating these companies when they do the smallest amount required of them? How about they use the time and effort that they are paid for to secure our private data we are forced to trust them with? So concerned their first three steps were protecting themselves. The fact there IDPS did not pick this up in the first place, vibe coded horrible site, we need more regulations on security for storing documents. First rule of Fight Club? Same first rule of security, don’t discuss your security, and sure as heck do not allow an identity provider to list you on their website as a customer. Operational security ring a bell? It’s worth noting that multiple local, state, and federal agencies utilize ID scanning for identity verification — I’m not naming vendors to not muddy the water — and tie your identity back to card data, biometrics, health data, tax data, etc. These platforms, for the most part, are not goverment owned but simply licensed for government and commercial use, and deployments can vary widely depending on the technical acumen of staff, budget, GRC, ethical behavior, etc. So, while it is easy to blame the vendor, you have to take a hard look at each deployed environment (public cloud, private cloud, hybrid, and on-premises) in addition to the software vendors. Great coverage nonetheless. opsec level: opera gx Take a look at cities that have setup Night Life or Night Economy managers and you’ll see a ton of these similar devices and mandates to use them, along with Youtube and Instragram endorsement videos. Patronscan is another really bad one. The bitter irony here is that the scans appear to come from identity verification vendors – the companies paid to establish trust are the ones that became the breach. A leaked license image plus a selfie cannot be rotated like a password, so victims carry this forever. Concentrating that much verified PII in a few IDV platforms creates honeypots that will keep getting hit; retention-minimization rules would do more long-term than takedowns. Thanks for chasing the sourcing instead of stopping at the headline number. thanks claude stfu clanka Great work Brian. I wonder if this company will be sending letters to each individual along with what info was lost. TBH I imagine it won’t happen without a well deserved class action lawsuit. So basically you are not safe and your privacy isnt protected. The world has lost its purpose to the human race. Fingerprint and eye scan probably will be the only option to keep one single human from being actually cloned, and voilated. The government owes me trillions of bucks now i want it all… Brian, Thank you for your security work and article. I have found this article to be very insightful and leaving me hopeful for the pursuit to resolve. It also leaves me alarmed now they have moved on to build another sight. I will be following your journalism. Thank you for all you do and your cooperation with the agencies to get this on record. Meridianlink is listed on idscan.net’s website. They are the data broker that provides services for 100’s of background check companies that in turn service 1,000’s of companies. “If” idscan is indeed confirmed to be the source this will have a huge blast radius. Great job Brian. First time you’ve deployed your mother to crack open a case? The only comment here. If he were Letterman. The real bone chiller is these types of services which can be breached are used by prediction markets and betting sites, as well as places like id.me, stored debit card sites, studentloans.gov, and their ilk. Weird you focus on the reuse and purchase and not the fact that it should not be possible. The government has tools such as zero days; but just don’t have the jurisdiction to use them. I also, think that hackers from other countries (Such as Russia) are hardest to capture, because laws are different. We need to start putting people in the dirt Criminals of this caliber are scum There is no recourse for victims I am sick of hearing about breaches every week At least cut off some fingers…. Why dub them Nexus? You know the name of the service, tell us? The name of the service is/was Nexus. You can see the name Nexus in the first screenshot. Great investigative work Brian, I see this as just proof that giving people your identity to scan for proof just means trusting a series of entities to protect that information. As we keep pushing more and more personal data onto servers. We have to expect a bad link along the way. Unfortunately we deal with this always after the barn door is left open and all the horses are long since gone. In Canada it is illegal to copy/scan/photograph Government issued I.D. Protected under the Privacy Act. But since there is no enforcement, unless the potential victim knows the Law, businesses keep doing it. Getting a cell phone account? Under CRTC rules, the company can not get your License number nor Social Insurance number, yet they do anyway. Keep a piece of tape over your number, easy to remove when actually needed (legitimate police interaction), to when showing your I.D. , the service agent does not see the number and type it in. Credit check is ‘name’ and ‘current address’. Nothing more. Always keep your I.D. in your hand. Don’t let it wander off. Next up, lets get the Credit Reporting agencies to delete a lot of their collected information. Businesses have been known to get missing information from them, from that time you submitted protected information and did not know the Law. @Fed Up, do you have a link to a source saying it’s illegal to copy/scan/photograph Government issued I.D. in Canada? Never heard of that and can’t find anything with a google search. Thanks! Fedex scans my driver’s license when I receive alcohol. Does anyone know if Garret Langley’s driver license is on there as well? I’m curious This hack was too perfect—it had to be an inside job. They probably only went public because negotiations broke down, otherwise they would’ve just kept copying data. An IT worker who wasn’t even on that team found the glitch a long time ago and used their own personal external setup to break in. Class action lawsuit (should be) coming in 3.2.1… Whoever let it get out into the wild can figure it out. It’s not my problem and am not spending my mental energy on stuff like this. Great work investigating this. I escaped violence and do absolutely everything I can to not be found, but there’s nothing I can do to prevent required ID scans from leaking. It’s a scary digital world we live in. Incidents like these happen every day, but “we” only increase our reliance and trust in third parties to keep sensitive information safe. I’m happy I lied about my weight on my driver’s license. Is there any reason that idscan.met retains this information past the lifetime of the transaction? One basic security rule is that simply don’t keep information that you no longer need. The identity verification service that my employer just signed up with states that any scanned data is deleted after 30 days. Whether it is, whether they get rid of backups, etc. is another matter, but at least they have that policy. I don’t know anything about how long IDScan retains records (yet). But if a company that collects data gets breached, then the data they’re collecting is also very likely at risk. What this means is that it’s entirely possible for both things to be technically true at the same time: They can both have and possibly even follow a strict data retention rule of deleting scans after they are made, and be compromised by malware or active attackers in a way that captures any scanned card data, saves it to a file and periodically zips up those files and sends them to the ID theft service. People always assume that the breached company was storing data when it shouldn’t have, and that might be the case here, I really don’t know. But when Target got breached, a lot of readers got mad, thinking hey why are they even storing all this data in the first place? They weren’t. The cybercriminals had just installed malware on every point of sale across each store nationwide, and were constantly snarfing up newly swiped cards in real time. From what I’m seeing on other media channels, the HERTZ – Chief Information Security Officer (CISO) just moved onto/into a Global hotel CISO role…. timely knowledge? The trust.idscan.com site no longer shows any companies. Maybe your reporting revealed IDScan was incorrectly sharing companies names who don’t utilize their services and it’s been corrected

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.