Identity verification provider IDScan is investigating a suspected breach after more than 153 million U.S. and Canadian driver’s licenses appeared on a dark-web service called Nexus.
The FBI has opened an investigation into the apparent compromise.
Security journalist Brian Krebs and researcher Zach Edwards linked the records to IDScan by matching timestamps on stolen licenses with transactions where IDs had been scanned. Nexus claimed it had been extracting data from a major verification provider for more than a year. The service disappeared shortly after Krebs published his investigation.
Why It Matters: Identity verification can create lasting exposure when providers retain sensitive documents after they are checked. Government IDs are difficult to replace, leaving companies and their customers with risks that can persist long after a breach is contained.
- The Potential Breach Is Enormous: Nexus claimed more than 153 million driver’s licenses, plus millions of other identity documents. Krebs found evidence supporting the reported scale and confirmed his own license was searchable. Records belonging to senior government officials, including Defense Secretary Pete Hegseth, also appeared. Some entries contained front-and-back scans with infrared and ultraviolet images captured during verification.
- Evidence Links the Records to IDScan: Timestamps on several stolen licenses matched occasions when their owners had IDs scanned during Hertz rentals. Researcher Zach Edwards found a similar connection after visiting Planet 13, a dispensary that had partnered with IDScan. IDScan says its technology uses infrared and ultraviolet imaging, matching formats found in Nexus. The company said it was investigating and had not confirmed the source of the data in the reporting provided.
- The Attackers Claimed Persistent Access: Nexus said it had been extracting data from a major identity verification company for more than a year. Krebs watched the collection grow by nearly 400,000 driver’s-license records in 24 hours, suggesting the source may still have been feeding the service when he investigated it. If confirmed, the duration of the intrusion will raise questions about IDScan’s ability to detect unauthorized access and large data transfers.
- Stolen IDs Could Challenge Verification Systems: Some Nexus records included the same infrared and ultraviolet scans used to authenticate documents. Access to these source materials could make fraudulent submissions harder to distinguish from legitimate IDs, putting more pressure on verification systems to detect misuse without relying on document authenticity alone.
- Age Verification Is Expanding the Attack Surface: New age-check requirements are pushing more identity documents through verification vendors, increasing the amount of sensitive data these providers handle. The apparent IDScan compromise puts new scrutiny on whether ID-based age checks can expand without creating large repositories of reusable identity data.
Go Deeper -> FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security
It sure looks like hackers breached a major ID card verification service – TechCrunch


