FBI Investigates Dark-Web Operation That Exposed Over 153 Million Licenses

Nexus continued expanding after Krebs’s initial report, adding about 400,000 new records in the 24 hours that followed.
Each license entry on Nexus was accompanied by six image files — visible-light scans plus infrared and ultraviolet versions, for both the front and back.
Beyond licenses, Nexus listings included more than 10 million ID cards, roughly 3 million travel documents, and about 579,000 medical cards.
A specific link to a real-world location emerged: one researcher noted a license was scanned during a Las Vegas visit to a Planet 13 dispensary, which is tied to IDScan via a partnership.
Nexus was advertised on the Exploit Russian-language hacking forum by a new user, highlighting its access to a broad cybercriminal audience.
The FBI is investigating Nexus, a dark-web marketplace selling scans of 153 million U.S. and Canadian driver's licenses, along with millions of other identity documents. KrebsOnSecurity confirmed the breach's authenticity using samples, including journalist Brian Krebs's own Virginia license. Investigators identified IDScan.net, a New Orleans ID-verification firm serving Hertz, FedEx, and Caesars Entertainment, as a potential source of the stolen data.
Nexus continued harvesting data even after public exposure, adding roughly 400,000 new records within 24 hours of KrebsOnSecurity's initial report. The dark-web site went offline shortly after, but the scale of exposure poses severe risks to millions of individuals' identities and raises urgent questions about corporate access to verification systems.
Each Nexus listing contained six image files for every license: standard visible-light scans plus infrared and ultraviolet versions of both the front and back. TechSpot reported that beyond 153 million driver's licenses, Nexus advertised 10 million ID cards, 3 million travel documents, and 579,000 medical cards. The detailed imaging made the documents highly valuable for identity theft and forgery.
Nexus listings included licenses belonging to U.S. Defense Secretary Pete Hegseth and an FBI assistant director, according to KrebsOnSecurity's investigation. Researchers found specific ties to real transactions: one license was scanned at a Las Vegas Planet 13 dispensary, a location partnered with IDScan.net. KrebsOnSecurity also used his own license as a free sample to test the service's authenticity.
Investigators identified IDScan.net, a New Orleans-based identity-verification provider, as the likely source of the breach. The firm serves major companies including Hertz, FedEx, Caesars Entertainment, and other major corporations. KrebsOnSecurity reported that many license records were captured during Hertz rental transactions, with image timestamps matching those business interactions.
Nexus was advertised on Exploit, a Russian-language hacking forum, by a new user seeking to reach a broad cybercriminal audience. KrebsOnSecurity noted that Nexus operators claimed the data had been exfiltrated for over a year, with continuous additions to their inventory. The dark-web site went offline after the investigation gained public attention, but the FBI continues pursuing leads into the breach and its connections to identity-verification infrastructure.
Publishers
23
Articles
77
Reach
100