A Massive New Identity Theft Marketplace
A new dark web identity theft service called Nexus launched this week, offering digital scans of more than 153 million drivers licenses from individuals in the United States and Canada. Beyond drivers licenses, the service also claims to hold over 10 million identification cards, more than 3 million travel documents and international IDs, and at least 579,000 medical cards.
The service surfaced after a new user on the Russian-language cybercrime forum Exploit began advertising access to scans of more than 170 million identity documents. Journalist Brian Krebs verified the scale of the claim: a blank search on Nexus returns roughly 11.5 million pages of results at about 15 results per page.
Likely Source: An Identity Verification Vendor
Based on interviews with individuals whose licenses appear in the database, the data appears to be siphoned from a widely used identity verification company based in Louisiana, identified as idscan.net. That company processes ID scans on behalf of major corporations, including:
- Hertz
- Target
- FedEx
- Caesars Entertainment
Multiple people whose licenses were found in the Nexus database confirmed they had shared their IDs with Hertz or marijuana dispensaries around the dates matching entries in the leaked data — strongly suggesting the images were captured during routine ID-verification checks rather than obtained through a direct breach of the affected companies themselves.
What's Exposed
The stolen records reportedly include high-resolution scans of drivers licenses, in some cases with infrared and ultraviolet imaging used for authenticity verification, alongside timestamps matching when individuals rented vehicles, visited dispensaries, or passed through security checkpoints. This level of detail makes the data valuable not just for identity theft, but for tracking individuals' movements and activities over time.
Notably, records for several high-ranking U.S. government officials were found for sale on the service, including a drivers license belonging to U.S. Defense Secretary Pete Hegseth.
FBI Investigation
KrebsOnSecurity has learned that the New Orleans field office of the FBI has launched an official inquiry into the source of the leaked images, given idscan.net's Louisiana base of operations. The investigation is focused on determining how the identity verification data ended up on a criminal marketplace and the scope of companies and individuals affected.
Why This Matters
| Risk | Detail |
|---|---|
| Identity fraud | High-resolution scans with security features enable convincing fake IDs and account takeover |
| Physical tracking | Timestamped records reveal patterns of movement and location history |
| Targeting of public figures | Inclusion of government officials raises personal security and targeted-attack concerns |
| Third-party risk exposure | Companies relying on ID verification vendors inherit that vendor's security posture |
Recommended Actions for Individuals
- If you have used ID verification with a rental car company, dispensary, casino, or similar service recently, monitor your identity closely for signs of fraud.
- Consider a credit freeze with all three major credit bureaus.
- Watch for phishing attempts that reference personal details plausibly sourced from a leaked ID scan.
- Report suspected identity misuse promptly to reduce the window for fraudulent account creation.
Recommended Actions for Organizations
- Review third-party identity verification vendor contracts for data retention practices — verification data is often retained far longer than necessary.
- Require vendors to demonstrate encryption at rest and strict data minimization for scanned ID images.
- Include identity-verification vendors explicitly in third-party risk assessments and incident response planning.