The FBI is investigating reports that a dark web service called Nexus was selling scans of more than 153 million driver’s licenses from people in the United States and Canada. The figure comes from Nexus and has not been independently confirmed.
Nexus was advertised on the Russian cybercrime forum Exploit and offered digital scans of driver’s licenses, ID cards, travel documents and medical cards. The database also reportedly contained marijuana dispensary cards and other government-issued identification.
The FBI’s New Orleans field office opened an investigation as cybersecurity journalist Brian Krebs was examining the apparent breach. In a statement to Reuters, the bureau said it was “looking into the incident” but could not comment because of the “ongoing nature of the investigation.”
Clues point to an identity verification vendor
The strongest clue came from timestamps attached to the license images. Krebs found his own license in the database, including front and back images and infrared and ultraviolet scans. The timestamp corresponded with a June 2025 trip during which he and his mother presented their licenses at Hertz. Other people who consented to searches also found their licenses, with timestamps corresponding to occasions when they had presented their IDs to businesses.
Security researcher Zach Edwards found his license too. His timestamp matched a Las Vegas trip during which he presented his ID at a Planet13 dispensary.
IDScan.net says it provides identity verification technology to thousands of locations and advertises relationships with businesses including Hertz and Planet13. The company told Krebs it was investigating.
“At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” Jillian Kossman, a marketing and operations leader at IDScan.net, told KrebsOnSecurity.
Nexus disappeared from the dark web shortly after Krebs published his report. Reuters said the source of the stolen data had not been independently established.
The incident exposes a weakness in a system that is becoming increasingly common: businesses outsource identity checks to specialized vendors, while consumers often have little visibility into where their identification data ultimately goes.
That creates a difficult accountability gap. A customer may trust a car rental company, hotel, dispensary or website, but the company actually handling the most sensitive information may be a third-party provider operating largely out of sight. As age verification and other identity checks expand, that distinction matters even more. Every additional provider that receives or retains identity data creates another potential point of exposure.
What consumers should do
People who believe their information may have been exposed should watch for phishing attempts, account-recovery scams and fraudulent credit applications. A credit freeze can also help prevent criminals from opening new credit accounts using stolen identity information.
For businesses, the incident is a warning that outsourcing identity verification does not outsource security responsibility. Companies collecting government IDs should know what data their vendors receive, how long it is retained, who can access it and how those systems are protected.





