FBI Investigates 153 Million Licenses That Just Hit the Dark Web

FBI probes idscan.net after dark-web seller exposed IR and UV scans of 153 million licenses over 14 months

Al Landes Avatar
Al Landes Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • Nexus dark-web marketplace offered 153 million driver’s license scans traced to idscan.net.
  • Timestamp evidence linking records to specific ID-scanning moments cracked breach attribution.
  • AI image-matching makes leaked ID photos more dangerous than compromised passwords.

A three-second transaction at a rental car counter may have cost 153 million people their most sensitive identity document. That moment — multiplied across every Hertz counter, dispensary checkout, and hotel desk in North America — is now apparently sitting in a dark-web database. A marketplace called Nexus surfaced on a Russian cybercrime forum on Aug. 31, offering searchable scans of drivers licenses, ID cards, travel documents, and medical cards for people across the U.S. and Canada. The FBI’s New Orleans field office has opened a formal investigation into a suspected database leak at identity verification firm idscan.net.

A Live Breach, Not a One-Time Dump

This wasn’t a static data dump — Nexus was actively growing, record by record, even as investigators closed in.

Advertised on the forum Exploit by a new user, Nexus claimed over 170 million North American records — 153 million+ drivers licenses, 10 million+ ID cards, roughly 3 million travel documents, and 579,000 medical cards. The operator stated the data had been “continuously exfiltrating for over a year.” In a single 24-hour window, the license count grew by nearly 400,000. Shortly after KrebsOnSecurity published its investigation, Nexus went dark, replaced by one line: “This service is no longer available.”

Key details that made investigators take notice:

  • Six image files per license: visible light, infrared, and ultraviolet scans, front and back
  • Records tagged “CAC” suggest government Common Access Cards may be included
  • Timestamps in filenames correlate directly with real-world ID-scanning events
A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale. Image: KrebsonSecurity

The timestamp evidence is what cracked the attribution. Reporter Brian Krebs and his mother found records separated by mere seconds — matching the exact moment they handed licenses to a Hertz representative. Security researcher Zach Edwards found his license timestamped to a DEFCON trip, with Planet13 dispensary the only venue that definitively scanned his ID. idscan.net — which reportedly processes 21 million+ verifications monthly at 20,000+ locations for clients including Hertz, Target, FedEx, and Caesars Entertainment — uses the same IR/UV imaging profile found in Nexus records, according to KrebsOnSecurity’s analysis.

“These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.” — Zach Edwards, security researcher

The People Who Can’t Just Get a New ID

For some victims, this breach isn’t an inconvenience — it’s a physical safety crisis.

Unlike a breached password, you can’t rotate a face. Larry Baldwin, principal intelligence researcher at cybersecurity firm Cybera, warned that front-and-back ID scans are the keys to opening new lines of credit — and that AI image-matching makes a leaked photo far more dangerous than a leaked password. For domestic violence survivors and federal witness protection participants, whose safety depends on controlling their likeness, this breach is a genuine threat. A surveillance app used for identity-tracking illustrates just how dangerous exposed biometric data can become in the wrong hands. idscan.net spokesperson Jillian Kossman told KrebsOnSecurity the company was investigating but provided no further detail.

The real question isn’t whether your license is in that database. It’s why a single ID-verification vendor reportedly became the master key to 170 million identities — and nobody noticed the lock was allegedly broken for over a year. Readers concerned about their personal data exposure can stay safe by reviewing how and where their information is being scanned and stored.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →