The Federal Bureau of Investigation has initiated a formal probe into what appears to be a significant data compromise at an identity verification provider. The breach involves a dark web service that emerged this week, offering access to digital reproductions of more than 153 million driver's licenses belonging to residents of the United States and Canada. Investigators at the FBI's New Orleans field office launched the inquiry after evidence pointed to IDScan.net, a Louisiana-based identity verification company, as the likely source of the compromised materials.

On August 31, a new user on the Russian cybercrime forum Exploit began advertising access to identity documents belonging to over 170 million people across North America. The marketplace, operating under the name Nexus, presented itself as offering comprehensive identity document collections. The proprietor of the service even included a sample—the Virginia driver's license of a security researcher—in the initial sales pitch to demonstrate the authenticity of the offering.

Nexus claims to maintain a substantial inventory beyond driver's licenses. The service advertises possession of more than 10 million identification cards, over three million travel documents and international IDs, and at least 579,000 medical cards. A search function returning approximately 11.5 million pages of results, with roughly 15 entries per page, suggests the 153 million driver's license figure may be accurate. Canadian records comprise approximately 1.1 million results, with Ontario accounting for 473,673 of those records.

The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.

The compromised documents include an unusual variety of identity materials. Alongside standard driver's licenses, the database contains marijuana dispensary cards. Some records are tagged with source designations such as "CDL" for commercial driver's licenses, while others carry "CAC," potentially referring to Common Access Cards—government-issued credentials that provide physical access to federal buildings and secure facilities.

The operators of Nexus claim the license images derive from an ongoing breach at "a major identity verification company" serving multiple Fortune 500 corporations. "We have been continuously exfiltrating new data for over a year into our private database," the service stated in its initial forum post. "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." The volume of available records has grown substantially, with nearly 400,000 additional driver's license entries added within a 24-hour period, indicating that fresh stolen data continues to be harvested and uploaded regularly.

Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames. Not all records include photos, and some that do feature photos do not display the associated filenames.

Investigation into the breach's origins began with detailed analysis of the compromised materials. Each of the researcher's license scans included six image files: three pairs showing front and back views, a standard scan, and both infrared and ultraviolet versions. Timestamps attached to each file corresponded to June 2025, aligning with a trip taken to attend a family funeral. When the researcher obtained permission from more than a dozen acquaintances to search for their licenses, nine individuals confirmed their records were present in the database, and each verified that the timestamps matched dates when they had traveled.

The timestamps appeared to use Greenwich Mean Time as the reference timezone. Initial theories about the breach's origin—such as involvement with airport security screening—were ruled out when no passports appeared in the dataset. Additionally, not all individuals whose licenses were found had displayed identification at airports. One person whose license appeared in Nexus had not flown recently but had rented a vehicle from Hertz during the relevant timeframe.

A significant breakthrough emerged when the researcher examined circumstances surrounding their own license capture. Despite traveling through Reagan National Airport in June 2025, the researcher had not presented their driver's license to TSA agents because they lacked a Real ID—the security-enhanced credential now mandated by the Transportation Security Administration for domestic flights. Instead, a U.S. passport was shown. However, the researcher and their mother both handed their driver's licenses to a Hertz rental car representative at the same time, and timestamps for both licenses in the Nexus database were separated by only seconds.

Security researcher Zach Edwards, who recently established DecryptAds to help individuals understand online advertiser tracking, also discovered his driver's license available for purchase on the service. The timestamp on his record corresponded to a trip to Las Vegas for the DEFCON security conference. Edwards recalled providing his license at a TSA checkpoint, at Planet13 marijuana dispensary, and at the Aria hotel. He confirmed that the dispensary was the only location that definitively scanned his ID using a scanning device.

Planet13 operates as a multi-state marijuana dispensary chain with locations in California, Florida, Illinois, and Nevada. In 2022, IDScan.net, based in New Orleans, announced an exclusive identity verification partnership with Planet13's dispensaries nationwide. IDScan.net processes identity verification for more than 1,000 marijuana dispensaries operating across 19 U.S. states. The company's client roster, according to its website, includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. IDScan.net's technology performs more than 21 million verifications monthly across more than 20,000 locations globally, utilizing both infrared and ultraviolet light scanning capabilities.

To enter Planet13’s weed dispensary in Las Vegas, one must pass through a red telephone booth. Image: Zach Edwards.

When contacted by the researcher, IDScan.net acknowledged it was investigating the matter but declined to provide a detailed official statement or substantive responses to specific inquiries. "At this point I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation," wrote Jillian Kossman, a marketing and operations leader at IDScan.net.

Image: idscan.net.

Word of the investigation reached federal authorities during the research phase. The FBI became aware of the breach inquiry after learning that Nexus had also obtained driver's license information for an FBI assistant director. The researcher was subsequently added to a conference call with approximately six FBI agents, including senior leadership from the agency's cyber division. During that call, the FBI disclosed that its New Orleans field office had opened an official investigation into the apparent breach at IDScan.net earlier that same day.

Edwards emphasized the broader implications of the breach for identity verification practices. "This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids," Edwards told the researcher. "These systems are putting sensitive data into more and more 3rd party vendors, and we don't have nearly the oversight to ensure they are safe."

Larry Baldwin, principal intelligence researcher at cybersecurity firm Cybera, found his own driver's license in Nexus with timestamps corresponding to a Hertz car rental during a recent vacation. Baldwin outlined multiple serious threats posed by the service, noting that state-issued driver's licenses serve as standard proof of identity when establishing new credit accounts. The breach also creates severe risks for individuals seeking to avoid detection, including those fleeing domestic violence and participants in the federal witness protection program, who cannot meaningfully alter their appearance enough to evade modern AI-based image matching systems.

"Just when it seems like we're making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised," Baldwin said.

Updates

September 8: IDScan.net released a statement indicating it had "determined that an unauthorized third party may have access and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers." The company stated it is notifying affected individuals and providing credit protection services.

September 2, 6:05 p.m. ET: A Caesars Entertainment representative clarified that the company has not been an IDScan.net client and discontinued use of VeriScan in February 2025, despite IDScan.net listing Caesars as a current client on its website. The representative stated Caesars maintained no active VeriScan accounts at the time of the incident, did not authorize IDScan.net to retain account data, and that IDScan.net indicated the breach should have no impact on Caesars Entertainment.

September 2, 8:56 p.m. ET: Shortly after publication, the Nexus identity theft service disappeared from the dark web. The login page was replaced with a plain text message stating, "This service is no longer available."

Source: Krebs on Security