{"id":79575,"date":"2026-09-03T03:56:34","date_gmt":"2026-09-03T07:56:34","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=79575"},"modified":"2026-09-03T03:56:34","modified_gmt":"2026-09-03T07:56:34","slug":"nexus-data-breach-idscan-fbi-79575","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/nexus-data-breach-idscan-fbi-79575\/","title":{"rendered":"FBI Probes Service Selling 153M+ Drivers Licenses"},"content":{"rendered":"<p>On Monday, the digital underground was shaken by the emergence of <strong>Nexus<\/strong>, a new identity theft service on the dark web advertising access to more than 153 million digital scans of drivers licenses from the United States and Canada. The service, which also claims to hold over 10 million identification cards, three million travel documents, and nearly 580,000 medical cards, has already prompted an official investigation by the New Orleans field office of the Federal Bureau of Investigation (FBI). The source of this massive trove of sensitive identity data appears to be a breach at <a href=\"https:\/\/idscan.net\" target=\"_blank\" rel=\"sponsored noopener noreferrer\" data-iacss-external=\"1\">IDScan.net<\/a>, a Louisiana-based identity verification company whose technology is used by major corporations, including Hertz, Target, and Caesars Entertainment.<\/p>\n<h2>The Scope of the Nexus Data Breach: More Than Just Drivers Licenses<\/h2>\n<p>The scale of the Nexus breach is staggering. A blank search within the service returns approximately 11.5 million pages of results, each displaying roughly 15 records. While the database encompasses records from both Canada and the United States, the overwhelming majority belong to Americans. A filtered search for Canadian drivers licenses alone yields approximately 1.1 million results, with the largest single concentration coming from Ontario at 473,673 records.<\/p>\n<p>The records extend well beyond standard state-issued drivers licenses. The dataset includes marijuana dispensary cards, and some entries list their source as &#8220;CDL,&#8221; presumably for commercial drivers licenses. More alarmingly, a source notation of &#8220;CAC&#8221; appears in some records, which likely refers to Common Access Cards \u2014 the government-issued identity documents used by military personnel and Department of Defense civilians to access secure buildings and classified systems. This suggests that the compromised data may include individuals with high-level security clearances, including, according to the investigation, the drivers license of the assistant director of the FBI itself. Remarkably, the records are not static; over a 24-hour period, the number of available drivers license scans increased by nearly 400,000, indicating a continuous, live exfiltration of data.<\/p>\n<h2>How the Service Works and What Information Is for Sale<\/h2>\n<p>Nexus is not merely a list of names and addresses. Each record in the service contains up to six image files: a standard scan of the front and back of the license, along with infrared and ultraviolet versions of the same images. These multi-spectral scans are a hallmark of advanced identity verification systems, which use specific wavelengths of light to detect forgery by revealing hidden features and security watermarks. The filenames of these images are appended with precise date and timestamps, which have proven critical in tracing the source of the leak.<\/p>\n<p>&#8220;Records are available to preview before purchase with pertinent information redacted,&#8221; the service&#8217;s operator wrote in an introductory post on the Russian-language cybercrime forum Exploit. &#8220;Customer photos are displayed if available.&#8221; The service offers a granular search interface, allowing buyers to locate individuals by name, state, or document type. The operator claims to have been &#8220;continuously exfiltrating new data for over a year,&#8221; suggesting that this is an ongoing operation rather than a one-time heist.<\/p>\n<p>What is the market value of such a dataset? For identity thieves, a drivers license is a master key. It is the single most common document used to verify identity when opening bank accounts, applying for credit cards, or renting property. With a license scan, an attacker can more easily bypass a company&#8217;s identity verification protocols. The inclusion of infrared and ultraviolet images makes these scans even more dangerous, as they could theoretically be used to create physical counterfeit IDs that are far more convincing than standard photocopies.<\/p>\n<h2>How Did the Investigation Trace the Source to IDScan.net?<\/h2>\n<p>The path to identifying the source of the breach was a meticulous process of elimination. The journalist behind the investigation, whose own Virginia drivers license was offered as a free sample in the Nexus sales thread, worked with more than a dozen friends and family members. Each person whose license was found in the database confirmed that the timestamp on their images matched a specific travel or rental car date.<\/p>\n<p>Initially, the theory pointed toward airport security checkpoints. However, several key details contradicted this. No passports were found in the Nexus database, even though many travelers use passports for air travel. Furthermore, one individual whose license was in the database had not flown at all, but had been renting a car from Hertz for several months. Two federal employees who <a href=\"https:\/\/overcentral.com\/en\/cbp-database-abuse-employees\/\" title=\"CBP Workers Used Government Databases to Spy on Exes and Colleagues\" data-iacss-internal=\"1\">used government<\/a>a-issued identification at airport security found their state drivers licenses in Nexus, with timestamps matching the precise time they rented vehicles from Hertz later that same day.<\/p>\n<p>The smoking gun came when the journalist and his mother searched for their licenses. The timestamps on their image files were only a few seconds apart. &#8220;According to my mom, the only place she gave her drivers license to that day was the rental car company,&#8221; the investigation noted. This pointed directly to a point-of-sale or identity verification device used at a car rental counter. The common thread was Hertz, a company listed as a client on the &#8220;trust&#8221; page of IDScan.net. Further investigation revealed that the timezone used for the timestamps was Greenwich Mean Time (GMT), a common setting for centralized server logs, rather than a local timezone tied to a specific airport or hotel.<\/p>\n<p>Zach Edwards, a security researcher who operates the <strong>DecryptAds<\/strong> service, also found his license in Nexus. The timestamp on his record matched a trip to Las Vegas for the DEFCON security conference where he visited <strong>Planet13<\/strong>, a marijuana dispensary chain. In 2022, Planet13 announced an exclusive identity verification agreement with IDScan.net. This was the second major client link. Edwards noted that while he shared his license at the airport, hotel, and dispensary, only the dispensary used a device to scan his ID.<\/p>\n<p>The convergence of evidence\u2014the presence of both Hertz and marijuana dispensary data, the use of infrared and ultraviolet scanning, the same GMT timestamps, and the corporate client list\u2014led directly to IDScan.net. The company processes ID verification at more than 20,000 locations globally, performing over 21 million verifications each month for clients that include, according to its website, FedEx, Motorola Solutions, and Jack Henry.<\/p>\n<h3>What Is the Connection Between Nexus and the FBI Investigation?<\/h3>\n<p>During the course of the research, word reached the FBI that an investigation was pointing toward a massive identity <a href=\"https:\/\/overcentral.com\/en\/safepal-data-breach-customer-records\/\" title=\"SafePal Data Breach Impacts 40,000 Customers\" data-iacss-internal=\"1\">data breach<\/a>. The catalyst may have been the discovery that the Nexus service was selling the drivers license information for the assistant director of the FBI. The journalist was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency&#8217;s cyber division. On that call, the FBI confirmed that its New Orleans field office had opened an official investigation into an apparent breach involving IDScan.net. This is a significant development, as it validates the investigative findings and marks the transition from private research to formal law enforcement action.<\/p>\n<h2>The Technical and Human Implications of the Breach<\/h2>\n<p>Larry Baldwin, principal intelligence researcher at the cybersecurity firm Cybera, whose own license was found in the database matching a Hertz rental date, outlined the dual threat of the Nexus service. &#8220;State-issued drivers licenses are commonly used as proof of one\u2019s identity when opening new lines of credit,&#8221; he said. The availability of high-quality scans makes it dramatically easier for criminals to commit new account fraud, tax refund fraud, and synthetic identity theft, where real personal information is mixed with fake data to create a new identity.<\/p>\n<p>Beyond financial fraud, Baldwin highlighted a more chilling consequence: the exposure of individuals who want to remain hidden. &#8220;This service could dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance, or at least not enough to fool today\u2019s AI-based image matching tools,&#8221; he said. This includes victims of domestic violence who have relocated, and even participants in the federal witness protection program. A drivers license photo, paired with facial recognition algorithms, could be used to track and locate these individuals.<\/p>\n<p>From a technical standpoint, the multi-spectral imaging (infrared and ultraviolet scans) suggests the breach exploited a backend system that stores images for quality assurance or fraud analysis, rather than a simple front-end device hack. This explains why the data appears to be continuously flowing: the attackers likely have persistent, unauthorized access to IDScan.net&#8217;s internal databases. The inclusion of marijuana dispensary cards also indicates a wide-ranging data collection practice that goes beyond simple age verification for alcohol sales.<\/p>\n<h2>What Steps Should Affected Individuals Take?<\/h2>\n<p>If you have used an ID scanning kiosk at a Hertz rental counter or a Planet13 dispensary in the last 18 months, your data may be at risk. Given the scale of the breach, it is prudent for any adult in North America to assume their data may have been compromised. Immediately place a fraud alert on your credit file with the three major credit bureaus: Equifax, Experian, and TransUnion. A fraud alert requires businesses to verify your identity before issuing new credit. For stronger protection, consider a credit freeze, which prevents any new credit from being opened in your name until you temporarily lift the freeze.<\/p>\n<p>Monitor your credit reports for unauthorized inquiries or new accounts. Services like annualcreditreport.com allow you to access your reports for free weekly. Be vigilant for phishing attempts that may reference the <a href=\"https:\/\/overcentral.com\/en\/idscan-net-breach-drivers-licenses-dark-web-identity-theft-79523\/\" title=\"IDScan.net Breach Exposes Driver\u2019s Licenses for Sale\" data-iacss-internal=\"1\">IDScan.net breach<\/a>, as attackers often use news of a data breach to trick victims into providing additional information. If you are a victim of domestic violence or have a protected identity, consider consulting with a security professional about the specific risks posed by your photograph being available in this database.<\/p>\n<h2>The Disappearance of Nexus and the Aftermath<\/h2>\n<p>Shortly after the story of the breach was published, the Nexus identity theft service vanished from the dark web. The login page was replaced with a single line of plain text: &#8220;This service is no longer available.&#8221; While this suggests the operators may have taken the service offline in response to the FBI investigation and media attention, it does not guarantee the data has been destroyed. The stolen images could easily have been copied, sold, or transferred to other criminal marketplaces. The takedown of a single site is a tactical victory, but the strategic threat of this massive data exposure remains.<\/p>\n<p>IDScan.net has acknowledged the investigation but has not yet provided an official statement or substantive answers to specific questions regarding the mechanism of the breach. Caesars Entertainment, which was listed as a client on IDScan.net&#8217;s website, has issued a statement clarifying that it has not been a client since February 2025, and that it did not authorize IDScan.net to retain its data. This highlights a critical vulnerability in the identity verification ecosystem: companies often retain scans of sensitive documents long after the initial transaction is complete, creating a rich target for attackers.<\/p>\n<p>Zach Edwards summarized the broader lesson from this incident: &#8220;This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids. These systems are putting sensitive data into more and more third-party vendors, and we don\u2019t have nearly the oversight to ensure they are safe.&#8221; The Nexus breach is not an isolated incident but a symptom of a system that collects vast amounts of biometric and identity data without adequate security guarantees, leaving millions of people vulnerable every time they rent a car, check into a hotel, or buy a product that requires age verification.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Monday, the digital underground was shaken by the emergence of Nexus, a new identity theft service on the dark web advertising access to more than 153 million digital scans of drivers licenses from the United States and Canada. The service, which also claims to hold over 10 million identification cards, three million travel documents, [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":83065,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/79575.png","fifu_image_alt":"FBI Probes Service Selling 153M+ Drivers Licenses","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-79575","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/79575.png","fifu_image_alt":"FBI Probes Service Selling 153M+ Drivers Licenses","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/79575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=79575"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/79575\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/83065"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=79575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=79575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=79575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}