FBI Investigates Dark Web Sale of 153 Million US Driver’s Licenses
- A dark web service called Nexus is selling digital scans of more than 153 million driver’s licenses from the US and Canada, and the total keeps climbing by hundreds of thousands a day.
- The FBI’s New Orleans field office opened an investigation after researcher Brian Krebs traced the leak to identity verification firm IDScan.net, whose clients include Hertz, Target and FedEx.
- Drivers who rented a car, visited a cannabis dispensary or scanned an ID at certain retailers in the past year face real exposure and should freeze their credit and check IdentityTheft.gov.
A Rental Car Counter, Not an Airport, Looks Like the Source
A criminal marketplace on the dark web is selling front-and-back scans of more than 153 million American and Canadian driver’s licenses, along with infrared and ultraviolet copies of the same documents. The FBI has opened a federal investigation into the source of the leak, and the number of exposed licenses grew by nearly 400,000 in a single 24-hour stretch this month.
Security journalist Brian Krebs broke the story on September 1 after a source flagged a new listing on the Russian cybercrime forum Exploit. The seller, operating a service called Nexus, offered Krebs his own Virginia driver’s license as a free sample to prove the data was real. Nexus claims more than 153 million driver’s licenses, 10 million identification cards, 3 million travel documents and 579,000 medical cards for people across North America. A blank search on the site returned roughly 11.5 million pages of results.
How Investigators Traced the Leak
Krebs asked more than a dozen friends and family members for permission to search Nexus for their own records. Nine were found, and each person confirmed traveling on or near the date stamped on their scanned license. The pattern pointed away from airport security and toward rental car counters. Krebs found his own license scan carried a timestamp matching a Hertz rental from a trip in June 2025, and his mother’s license, handed to the same Hertz clerk seconds apart from his, carried nearly identical timestamps.
A separate case pointed to a Las Vegas cannabis dispensary. Security researcher Zach Edwards found his own license in the Nexus database with a timestamp from a trip to the DEFCON security conference. Edwards said he handed his license to a TSA agent, a hotel front desk and Planet13, a multi-state dispensary chain, on that trip. Only the dispensary scanned his ID into a machine.
The Common Link: IDScan.net
Planet13 has an exclusive identity verification agreement with a Louisiana company called IDScan.net, which scans government IDs using infrared and ultraviolet light, the same imaging formats found in the stolen Nexus records. IDScan.net’s own marketing materials list Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment among its clients, and the company says it performs more than 21 million identity verifications a month at over 20,000 locations. IDScan.net told Krebs it is investigating but has not confirmed a breach. Caesars Entertainment said it stopped using IDScan.net’s VeriScan product in February 2025 and had no active accounts when the leak occurred.
Federal Officials Among the Exposed
Krebs said Nexus also lists a driver’s license belonging to Defense Secretary Pete Hegseth and, separately, an assistant director of the FBI. Word of Krebs’ research reportedly reached the bureau before he published his story. On September 1, the FBI’s New Orleans field office opened an official investigation into the apparent breach at IDScan.net. Within hours of the story going live, the Nexus site vanished from the dark web, replaced with a message reading, “This service is no longer available.”
Why This Breach Is Different
State driver’s licenses now function as a default identity document at car rental counters, cannabis dispensaries, hotels and age-restricted retailers, well beyond their original purpose of proving a person can legally drive. Privacy researcher Larry Baldwin, whose own license appeared in the Nexus data from a Hertz rental, said the exposure is especially dangerous for people who do not want to be found, including domestic violence survivors and people in witness protection. A stolen license with a clear photo is also enough for a criminal to open new lines of credit in someone else’s name. Lenders routinely accept a scanned ID as proof of identity, with little else standing in the way.
What To Do If You Rented a Car or Visited a Dispensary Recently
Anyone who handed a driver’s license to a rental car clerk, an age-verification kiosk or a dispensary in the past 12 to 18 months should treat their identity as potentially exposed. The Federal Trade Commission recommends a specific sequence of steps.
First, place a free fraud alert with one of the three major credit bureaus, Equifax, Experian or TransUnion. Under federal law, that bureau must notify the other two, and the alert makes it harder for anyone to open new accounts using your name for one year.
Second, pull free credit reports from all three bureaus at annualcreditreport.com and scan them for accounts you did not open.
Third, request a credit freeze, which blocks lenders from accessing your credit file entirely until you lift it. Freezes and unfreezes are free by law and can be requested online, by phone or by mail from each bureau separately.
Fourth, report the exposure at IdentityTheft.gov, the FTC’s dedicated portal, which generates a personalized recovery plan and an official Identity Theft Report that can help dispute fraudulent accounts later.
Fifth, contact your state’s motor vehicle agency to flag your driver’s license number. Many states can note a compromised license number in their system, which helps clerks catch anyone trying to use a cloned copy to rent a car, board a plane or make a purchase.
The investigation into IDScan.net is active, and Krebs has said he will update his reporting as new information comes in. Until investigators confirm the exact source and scope, security researchers are advising drivers to assume any ID handed over at a rental counter or scanning kiosk in the recent past could be part of the exposed dataset.
Sources: