The FBI investigation into a dark-web service claiming to sell more than 153 million driver’s license scans should raise broader questions about how organizations collect and centralize identity documents. The immediate concern is obviously the scale of the alleged exposure, but the deeper security issue is that driver’s licenses are increasingly being captured by third-party identity-verification systems across hotels, rental-car companies, age-restricted businesses, financial services and online verification processes. Every additional organization scanning an identity document creates another copy, another integration and another environment in which that identity must remain protected. When one centralized verification provider suffers a serious compromise, information collected across many unrelated businesses can potentially become exposed through a single point of failure.

The service, known as Nexus, appeared on a Russian-language cybercrime forum and advertised access to an enormous collection of identity documents belonging primarily to people in the United States and Canada. Nexus claimed more than 153 million driver’s license records, over 10 million additional identification cards, more than three million travel or international identity documents and hundreds of thousands of medical cards. Those numbers originate from the criminal service itself and therefore should not automatically be treated as confirmed breach totals. However, KrebsOnSecurity examined the platform directly and found that the searchable database appeared broadly consistent with the advertised scale, including millions of pages of searchable records.

The service reportedly contained driver’s licenses belonging not only to ordinary citizens but also senior U.S. government officials. That dramatically illustrates the security implications of collecting identity documents indiscriminately. A driver’s license does not become less sensitive because the organization scanning it has only a temporary business purpose. Once captured and stored, it becomes a durable digital identity artifact that may remain valuable to criminals for years.

Unlike passwords, driver’s licenses cannot simply be changed after every breach. A person can reset a password, rotate an API key or replace a credit card. A legal name, photograph, date of birth and many physical characteristics remain substantially permanent. Even when a driver’s license number itself is reissued, a high-quality front-and-back image of the document can continue to support impersonation, social engineering and identity-verification bypass attempts.

That persistence makes identity-document breaches particularly serious. Criminals increasingly encounter verification systems that require users to photograph or upload an identity document before opening financial accounts, recovering accounts, accessing cryptocurrency exchanges or obtaining services. A database containing genuine driver’s license images can therefore become useful raw material for defeating exactly the identity-verification controls intended to prevent fraud.

The Nexus records are especially concerning because some apparently contain multiple image types rather than simple photographs. KrebsOnSecurity found records containing front and back images as well as infrared and ultraviolet scans of the same license. These additional imaging modes are commonly used by identity-verification equipment to examine security characteristics that may not be visible in ordinary photographs.

The existence of infrared and ultraviolet images provides an important clue about the likely data source because normal consumers do not routinely create those scans themselves. They are generated by specialized identity-verification equipment. KrebsOnSecurity compared timestamps associated with several exposed licenses against the individuals’ real-world activities and found strong correlations with occasions when those individuals had presented their licenses to businesses using identity-scanning systems.

One of the most interesting examples involved rental cars. Several people whose driver’s licenses appeared in Nexus reported that the timestamps on their scanned documents corresponded closely with car rentals. KrebsOnSecurity itself found that both the author’s and his mother’s licenses carried timestamps separated by only seconds, corresponding to a moment when both documents were handed to a Hertz representative during the same rental transaction.

Another example involved a security researcher whose license appeared in Nexus with a timestamp corresponding to a trip to Las Vegas. He had provided identification at several locations during the trip but recalled that a marijuana dispensary was the place where his license was definitely scanned electronically. That dispensary operates within a chain for which IDScan.net has publicly announced identity-verification services.

These observations led KrebsOnSecurity toward IDScan.net, a Louisiana-based company providing identity-verification technology across a large number of industries. The company says its technology processes more than 21 million identity verifications each month across over 20,000 locations worldwide. Its customer references include organizations operating in hospitality, rental cars, retail, financial services and other industries.

IDScan.net also documents technology capable of scanning identity documents using infrared and ultraviolet light, which aligns with the unusual image formats observed in some Nexus records. The FBI’s New Orleans field office subsequently opened an investigation into an apparent breach involving the company. IDScan.net has said it is investigating but, at the time of reporting, had not provided a detailed public explanation of what occurred.

It is important not to move beyond the available evidence. An FBI investigation into an apparent breach is not yet the same as a completed forensic finding showing that all 153 million documents originated from IDScan.net. The Nexus operators themselves claim the data came from an ongoing compromise of a major identity-verification provider, and the circumstantial evidence identified by KrebsOnSecurity points strongly in that direction, but the complete source, timeframe and scope still require confirmation.

The attackers’ claim that they had been continuously exfiltrating data for more than a year deserves particular attention. KrebsOnSecurity observed the Nexus database increase by almost 400,000 driver’s license records within approximately 24 hours. If the criminal service was genuinely receiving new records continuously, this would suggest something very different from a one-time database theft. It could indicate persistent attacker access to a live data pipeline or storage environment from which newly scanned identities were being collected.

Persistent exfiltration changes the incident-response problem substantially. In a conventional breach, investigators may identify a historical database snapshot that was stolen at one point in time. If attackers instead maintain continuing access, merely securing one server or resetting one account may not stop the leak. The organization has to identify and remove the attacker’s persistence mechanism, determine which systems feed the affected dataset and establish whether credentials or integration mechanisms remain compromised.

It also raises questions about monitoring. If hundreds of thousands or potentially millions of new identity scans were being extracted over an extended period, defenders need to understand why that activity did not generate obvious anomalies. Large data theft does not always look like one enormous outbound transfer. Attackers can copy records gradually, use legitimate cloud APIs or extract data through application-layer access that resembles ordinary usage.

This is why data-exfiltration detection needs context rather than simple bandwidth thresholds. A process or account retrieving newly scanned identity documents shortly after they enter the system may not generate extraordinary network volume at any one moment. The suspicious characteristic may instead be that one identity is reading records belonging to many unrelated customers or continuously exporting information to a destination that should never receive it.

Identity-verification providers therefore need particularly strong behavioral monitoring around bulk and cross-customer access. Their business model inherently centralizes highly sensitive identity information collected on behalf of many different companies. An account or application that can access records across all customers should be treated as a highly privileged identity and monitored accordingly.

The incident also raises a basic architectural question: why are complete identity-document images retained after verification has occurred?

In many business processes, the real requirement is to establish a small number of facts. The organization may need to know that a person is over a certain age, that a name matches a reservation or that an identification document appears legitimate. Retaining a permanent high-resolution copy of the entire document may provide operational convenience, but it also creates a much larger privacy and security liability.

Data minimization should therefore become a central principle in identity verification. If the business requirement can be satisfied by retaining a verification result, limited document attributes or a cryptographic reference, the full document image should not necessarily remain stored indefinitely.

The safest sensitive database is the one that does not exist.

This principle becomes even more compelling when dealing with infrared and ultraviolet document imagery. These scans may contain security features specifically intended to help distinguish legitimate identification from counterfeits. Providing criminals with a large library of genuine samples could potentially improve their understanding of document-security patterns and aid future forgery attempts.

The risk therefore extends beyond impersonating the individual whose license was stolen. A sufficiently large corpus of genuine identity-document scans could potentially become training material for tools designed to generate or modify fraudulent documents. Advances in image generation and computer vision make this concern increasingly relevant.

AI-assisted identity fraud does not require criminals to produce perfect physical counterfeits. Many identity-verification processes occur remotely through photographs or uploaded images. Attackers may combine genuine stolen identity images with manipulated photographs, synthetic faces or other data to defeat automated verification systems.

This creates an uncomfortable security cycle. Organizations respond to fraud by requesting more identity information. That information is centralized inside verification providers. Those providers become increasingly attractive targets. When the data is stolen, criminals gain better material for defeating future identity checks, encouraging organizations to collect even more verification data.

The security industry needs to avoid turning identity verification into an endless escalation of data collection.

Privacy-preserving verification technologies can help. In many scenarios, a service does not need a copy of somebody’s driver’s license. It needs an assertion that the person is over 18, holds a valid license or has successfully completed an identity check. Systems capable of providing verified attributes without distributing full identity documents would dramatically reduce the amount of sensitive data circulating between organizations.

The Nexus incident should therefore influence ongoing discussions around digital identity. Centralized identity systems can improve fraud prevention, but their design needs to assume that large repositories will eventually attract serious attackers. Security cannot depend solely on the proposition that identity-verification companies will never be compromised.

Tokenization is one potential control. Rather than repeatedly distributing raw identity information, a trusted verification provider could issue a limited token representing a verified attribute. Downstream businesses would receive only the fact they need rather than a permanent document image.

Strong retention limits are another. Identity images could be deleted automatically after a verification transaction unless a clear legal or business requirement requires longer storage. Retention should be measured according to necessity rather than storage cost.

Encryption obviously remains important, but encrypted storage alone does not solve the problem if attackers compromise an application or identity capable of legitimately decrypting the records. Encryption protects data from certain infrastructure failures, but authorization determines who can actually retrieve it.

Access controls therefore need to operate at several levels. Customer organizations should have access only to their own verification records. Internal support personnel should receive only the minimum visibility required for their role. Administrative identities capable of accessing multiple tenants should be extremely limited and continuously audited.

Privileged access should use phishing-resistant MFA and dedicated administrative devices. A compromised employee account should not become a route to hundreds of millions of identity documents.

Service identities and API keys deserve equivalent protection because machine credentials may access far more records than human users. Long-lived API keys should be replaced with short-lived workload identities where possible, and permissions should be restricted to specific operations and tenants.

Identity-verification APIs should also incorporate strong rate and volume controls. If an integration normally retrieves hundreds of records each day, suddenly accessing millions should trigger a security response regardless of whether the requests carry technically valid credentials.

Zero Trust principles are particularly applicable. A valid identity should not automatically imply unlimited trust. Access decisions should consider user role, device condition, source network, requested data volume and historical behavior.

The alleged breach also shows why third-party risk is ultimately data risk. A company may have excellent internal security but still send copies of customers’ driver’s licenses to an external identity-verification provider. Once that transfer occurs, the organization depends partly on the provider’s security controls and retention policies.

Contracts and compliance certifications are not enough. Organizations using identity-verification services should understand exactly what information the provider stores, how long it is retained, whether it is segregated by customer and how privileged access is monitored.

They should also ask whether the provider can accomplish verification without permanently retaining the image.

This question should become part of procurement rather than something discovered after a breach.

The apparent Hertz connection illustrates the complexity of these data flows. A customer may believe they are giving their license to a rental-car company. Behind the scenes, the document may be scanned by hardware or software operated by another identity provider, processed in cloud infrastructure and retained according to policies the customer has never seen.

Data supply chains are often nearly invisible to the person whose information is moving through them.

Organizations therefore need accurate data-flow maps showing which third parties process sensitive identity information. Without that knowledge, incident response becomes extremely difficult because a customer organization may learn about a breach before it even realizes the affected vendor held its customers’ documents.

The same issue appears in retail, hospitality, regulated cannabis, financial services and online age verification. A single identity-verification vendor can sit underneath dozens of recognizable brands, creating concentration risk that ordinary consumers cannot realistically evaluate.

This resembles software supply-chain risk in an unusual way. Many companies rely on one common software library and become simultaneously vulnerable when it is compromised. Here, many companies may rely on one identity-verification platform, and a compromise can expose documents collected across an enormous range of unrelated businesses.

The difference is that software can generally be patched.

A photograph of somebody’s identity cannot.

This is why breach response for identity-document exposure needs to look beyond password resets. Victims should be alert to fraudulent account openings, identity-verification attempts and highly targeted impersonation. Credit monitoring and credit freezes may be appropriate depending on the exposed information and jurisdiction.

However, even those controls have limitations. A driver’s license image may be used for services that do not interact with traditional credit bureaus. Cryptocurrency exchanges, telecom providers, rental platforms and other services may use document verification independently.

Organizations operating identity-verification systems therefore need mechanisms for identifying documents known to have been compromised. If a genuine driver’s license image appears in a major breach, future verification systems should not automatically treat possession of that same image as strong proof that the applicant is the legitimate holder.

Verification needs to incorporate liveness, contextual checks and evidence that the document is being presented by the actual person rather than simply uploaded from a stolen database.

Static documents are increasingly weak authenticators.

This incident therefore reinforces a fundamental distinction: identity evidence is not the same thing as authentication.

A driver’s license can help establish who somebody is, but possession of a photograph of that license should never be sufficient to prove that the person presenting it is the legitimate owner.

The same lesson already exists around Social Security numbers. These identifiers were historically treated almost like secrets, but decades of breaches made them widely available. Systems that still authenticate people simply because they know an SSN are fundamentally weak.

Driver’s licenses may be moving toward the same problem.

If tens or hundreds of millions of high-quality license images become available to criminals, systems relying heavily on document possession will need to adapt.

Government agencies may eventually need better mechanisms for revocation or digital verification of identity documents. Physical document numbers were never designed for an environment where perfect digital copies can circulate indefinitely.

The presence of sensitive government-related IDs in the Nexus database raises additional concerns. Some records reportedly carry labels that may correspond to Common Access Cards or commercial licenses. If government-issued identity information is exposed, agencies need to determine whether those records could support physical-access fraud or targeted impersonation.

That does not mean possession of an image automatically grants access to government facilities. Modern access systems use cryptographic smart cards, PINs and other protections. Nevertheless, document images can support reconnaissance and social engineering against government employees.

The disclosure that licenses belonging to high-ranking officials were apparently available also shows why high-profile individuals face amplified risk. Attackers can combine identity documents with publicly available information to produce extremely convincing impersonation attempts.

Executives and government leaders should therefore receive enhanced identity-protection controls around financial, telecom and account-recovery processes.

The potential impact on vulnerable individuals may be even more serious. KrebsOnSecurity notes that stolen identity information can threaten people escaping domestic violence or participating in witness-protection programs. Modern face-matching systems make it increasingly difficult for somebody to disappear simply by changing their name or location if a high-quality identity photograph remains publicly obtainable.

This turns an ordinary privacy breach into a potential physical-safety issue.

Organizations handling identity documents therefore need to understand that confidentiality is not merely about preventing financial fraud. For some individuals, exposure of identifying information can create direct personal danger.

The scale of the alleged Nexus database also illustrates the weakness of assuming that regulatory compliance automatically produces adequate security. Identity-verification companies may operate under numerous privacy, financial and industry requirements, yet the central architectural issue remains whether so much sensitive information needed to be retained in one place.

Compliance generally defines minimum controls.

Threat modelling should ask what happens when those controls fail.

A repository containing more than 150 million driver’s license images should be treated as extremely high-value infrastructure. Security architecture should assume that criminal groups will actively target it and that one compromised administrator or API credential could have enormous consequences.

Segmentation, strong privileged-access management, data-loss prevention, immutable audit logs and aggressive anomaly detection should therefore be baseline expectations.

Bulk data exports should receive special controls. Administrative users should not be able to download enormous datasets casually, and database queries crossing tenant or customer boundaries should be heavily monitored.

Sensitive records can also be tokenized or stored in separate repositories according to purpose, preventing one database compromise from exposing every representation of the document.

Forensics will be critical in determining what actually occurred. Investigators need to establish which systems were accessed, when the intrusion began, which records were retrieved and whether the attackers maintained continuing access.

They also need to understand why newly collected records apparently continued appearing in Nexus.

If that observation is confirmed, incident responders need to identify the compromised ingestion path rather than focusing solely on historical storage.

The FBI investigation may eventually clarify whether the full Nexus collection originated from one provider, several providers or a combination of old and ongoing breaches.

Until then, claims about 153 million definitively compromised IDScan.net records should be avoided.

What is already clear is serious enough: a criminal marketplace demonstrated access to a massive quantity of genuine identity-document imagery, investigators found strong correlations between those documents and real-world verification events, and the FBI has opened an inquiry into an apparent breach involving a major identity-verification provider.

The disappearance of the Nexus site shortly after publication does not eliminate the problem. Criminal services frequently disappear temporarily because of law-enforcement pressure, infrastructure changes or fear of exposure.

More importantly, once data has been copied it cannot be made to disappear simply because one website goes offline. Other criminals may already possess copies. The long-term issue is therefore not Nexus itself. It is the accumulation of reusable identity documents inside centralized verification ecosystems. 

The security industry has spent years moving away from passwords as the sole proof of identity because passwords can be stolen and reused. It would be unfortunate to replace them with scanned identity documents and then recreate the same problem on a far larger and more permanent scale.

Identity verification needs to prove attributes without unnecessarily distributing permanent identity artifacts. Organizations should collect less, retain less and share less. And when complete documents genuinely must be stored, those repositories should be treated as infrastructure whose compromise could affect millions of people at once. 

The most important lesson from the Nexus investigation is therefore not simply that a dark-web service claims to have 153 million driver’s licenses.  It is that identity verification creates a new form of concentration risk. The more businesses rely on a small number of third parties to scan and store identity documents, the more attractive those providers become to attackers. If a system designed to prove who people are becomes the place criminals obtain the documents needed to impersonate them, the security model has inverted.  That is the problem the industry now needs to solve.


A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

Source: FBI Probes Service Selling 153M+ Drivers Licenses via KrebsOnSecurity — published 01 Sep 2026.