FBI Probes IDScan.net Breach Exposing 153M+ Driver's License Scans Sold on Dark Web; Four Class-Action Lawsuits Filed
A dark web service called 'Nexus' on the Russian-language Exploit cybercrime forum offered scans of more than 153 million US and Canadian driver's licenses — plus 10M+ ID cards, 3M+ travel documents and 579,000 medical cards — traced by KrebsOnSecurity to an…
On 2026-09-03, KrebsOnSecurity first reported that a service called 'Nexus' on the Exploit cybercrime forum was selling searchable access to scans of more than 153 million US and Canadian driver's licenses, alongside over 10 million ID cards, 3 million travel documents and 579,000 medical cards; Krebs cited a figure of as many as 170 million North Americans potentially affected (per Infosecurity Magazine). KrebsOnSecurity traced the trove to New Orleans-based identity verification provider IDScan.net, matching record timestamps to IDScan.net scans captured at Hertz rental transactions and Planet13 dispensaries, which uses idscan.net nationwide. IDScan.net's B2B ID verification customers reportedly include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, Jack Henry and hundreds of US cannabis dispensaries. Nexus operators claimed exfiltration had been ongoing for over a year, with records growing by roughly 400,000 per day; the database reportedly included the licenses of US Defense Secretary Pete Hegseth, FBI personnel, and KrebsOnSecurity's Brian Krebs himself. The Nexus service went dark shortly after Krebs published his findings. The FBI's New Orleans field office opened a formal investigation and has formally requested information on the source of the images. IDScan.net says it is investigating, though as of 2026-09-04 CSO Online reported the company had not issued an official public statement. By 2026-09-07, at least four class-action lawsuits had been filed against IDScan.net in the US District Court for the Eastern District of Louisiana. Experts warn that, unlike passwords, stolen license data (date of birth, address, ID numbers) is immutable and cannot be changed, creating lifelong identity-fraud exposure; law firms are advising potential victims to document their ID scans and verify which verification providers they used. Note on figures: the 153 million count refers specifically to driver's license scans, while the 'up to 170 million' figure cited by Krebs via Infosecurity Magazine refers to North Americans potentially affected overall; the reports are consistent rather than contradictory, but the precise total has not been confirmed.
- Nexus, a service on the Russian-language Exploit cybercrime forum, offered 153M+ scanned US and Canadian driver's licenses plus 10M+ ID cards, 3M+ travel documents and 579,000+ medical cards
- KrebsOnSecurity (2026-09-03) cited as many as 170 million North Americans potentially affected; 153 million is the specific count of license scans
- Leak traced to New Orleans-based identity verification firm IDScan.net via record timestamps matched to scans at Hertz rentals and Planet13 dispensaries
- IDScan.net's clients reportedly include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, Jack Henry and hundreds of US cannabis dispensaries
- Nexus operators claimed exfiltration ran for over a year, with records growing by roughly 400,000 per day
- Reported victims include US Defense Secretary Pete Hegseth, FBI personnel, and KrebsOnSecurity's Brian Krebs
- Nexus went offline shortly after KrebsOnSecurity published its findings
- The FBI's New Orleans field office opened a formal investigation and formally requested information on the source of the images
Coverage timelineoldest first · each row is one article
- · 13d agoFBI Probes Possible Breach of 153 Million Driver’s Licenses
Infosecurity Magazine· 85
FBI investigates possible breach exposing up to 170M North American driver's licenses, data sold on Exploit forum via 'Nexus' service, linked to IDScan.net.