- The FBI is investigating a data breach that leaked over 153 million U.S. and Canadian driver’s licenses and other identity documents to a dark web marketplace called Nexus.
- Nexus is selling not only driver’s licenses but also millions of other identification cards, travel documents, medical cards, and marijuana dispensary membership cards, with high-resolution scans and customer photos included in the listings.
- The breach likely originated from IDScan.net, a company that provides identity verification services to major businesses, potentially exposing individuals to identity theft and other risks, prompting experts to advise monitoring credit reports and considering placing a credit freeze.
The FBI’s has opened an investigation into a data breach that appears to have supplied a dark web marketplace with scans of more than 153 million U.S. and Canadian driver’s licenses, along with millions of other identity documents. The marketplace, a Russian cybercrime forum listing called Nexus, launched in late August.
Security journalist Brian Krebs discovered Nexus on August 31 after its operator offered up Krebs’s own Virginia driver’s license as a free sample to prove the service worked. Krebs reported that licenses belonging to Defense Secretary Pete Hegseth and an FBI assistant director are also available through the service. And in a sign the underlying breach may still be ongoing, Nexus added roughly 400,000 new records in the 24 hours after Krebs first wrote about it.
Beyond the 153 million driver’s licenses, Nexus is selling more than 10 million identification cards, nearly 2 million travel documents, and more than 579,000 medical cards, along with marijuana dispensary membership cards. The listings include high-resolution scans captured under infrared and ultraviolet light (imaging businesses use to check whether an ID is genuine), along with timestamps and, in some cases, photos of the customers who submitted them.
In tracking down a potential source for the breach, Krebs began with own license. He determined the license had been scanned during a car rental transaction more than a year earlier, in June 2025. Cross-referencing this information with data received from others he contacted about their stolen credentials, he determined the leak was likely to have originated at IDScan.net, a Louisiana-based company that provides identity verification services to businesses. IDScan.net verifies IDs for major companies including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment, as well as more than 1,000 marijuana dispensaries.
IDScan.net’s Jillian Kossman told Krebs that the company isn’t able to share additional information but called his reporting “welcome, and helpful to our team’s investigation.” Hertz did not respond to a request for comment before Krebs’ publication.
The type of data found in this breach is a boon for identity thieves. Larry Baldwin, a principal intelligence researcher at cybersecurity firm Cybera, warned that a stolen driver’s license scan is enough to open a fraudulent credit line in someone else’s name. More concerning, he also cautioned that the same data can be used to identify people in witness protection or track down domestic violence survivors who have relocated.
There’s no consumer-facing lookup tool to check whether your own license is in the Nexus data, and the FBI investigation is still in its early days. If you’ve rented a car, checked into a hotel, bought from a dispensary, or gone through a TSA checkpoint in the past couple of years, there’s a reasonable chance your license was scanned by a system like IDScan.net’s. It’s worth pulling your credit reports at annualcreditreport.com and watching for accounts you don’t recognize. Placing a credit freeze with the three major bureaus is free and reversible if you want a stronger block against new accounts being opened in your name.
Read next: How to freeze your credit to stop identity theft
Techlicious and Yahoo may earn commission from links in this article.
