A three-second transaction at a rental car counter may have cost 153 million people their most sensitive identity document. That moment — multiplied across every Hertz counter, dispensary checkout, and hotel desk in North America — is now apparently sitting in a dark-web database. A marketplace called Nexus surfaced on a Russian cybercrime forum on Aug. 31, offering searchable scans of drivers licenses, ID cards, travel documents, and medical cards for people across the U.S. and Canada. The FBI’s New Orleans field office has opened a formal investigation into a suspected database leak at identity verification firm idscan.net.
A Live Breach, Not a One-Time Dump
This wasn’t a static data dump — Nexus was actively growing, record by record, even as investigators closed in.
Advertised on the forum Exploit by a new user, Nexus claimed over 170 million North American records — 153 million+ drivers licenses, 10 million+ ID cards, roughly 3 million travel documents, and 579,000 medical cards. The operator stated the data had been “continuously exfiltrating for over a year.” In a single 24-hour window, the license count grew by nearly 400,000. Shortly after KrebsOnSecurity published its investigation, Nexus went dark, replaced by one line: “This service is no longer available.”
Key details that made investigators take notice:
- Six image files per license: visible light, infrared, and ultraviolet scans, front and back
- Records tagged “CAC” suggest government Common Access Cards may be included
- Timestamps in filenames correlate directly with real-world ID-scanning events

The timestamp evidence is what cracked the attribution. Reporter Brian Krebs and his mother found records separated by mere seconds — matching the exact moment they handed licenses to a Hertz representative. Security researcher Zach Edwards found his license timestamped to a DEFCON trip, with Planet13 dispensary the only venue that definitively scanned his ID. idscan.net — which reportedly processes 21 million+ verifications monthly at 20,000+ locations for clients including Hertz, Target, FedEx, and Caesars Entertainment — uses the same IR/UV imaging profile found in Nexus records, according to KrebsOnSecurity’s analysis.
“These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.” — Zach Edwards, security researcher
The People Who Can’t Just Get a New ID
For some victims, this breach isn’t an inconvenience — it’s a physical safety crisis.
Unlike a breached password, you can’t rotate a face. Larry Baldwin, principal intelligence researcher at cybersecurity firm Cybera, warned that front-and-back ID scans are the keys to opening new lines of credit — and that AI image-matching makes a leaked photo far more dangerous than a leaked password. For domestic violence survivors and federal witness protection participants, whose safety depends on controlling their likeness, this breach is a genuine threat. A surveillance app used for identity-tracking illustrates just how dangerous exposed biometric data can become in the wrong hands. idscan.net spokesperson Jillian Kossman told KrebsOnSecurity the company was investigating but provided no further detail.
The real question isn’t whether your license is in that database. It’s why a single ID-verification vendor reportedly became the master key to 170 million identities — and nobody noticed the lock was allegedly broken for over a year. Readers concerned about their personal data exposure can stay safe by reviewing how and where their information is being scanned and stored.





























