Dark-Web Marketplace Sold Scans of 153 Million Driver's Licenses
Journalist Brian Krebs traced the leaked scans to identity-verification firm IDScan.net, whose scanners sit behind ID checks at Hertz, Target and FedEx.
Estimated reading time: 5 minutes
TL;DR
A dark-web marketplace called Nexus was selling digital scans of more than 153 million US and Canadian driver’s licenses, along with millions more ID cards, travel documents and medical cards — complete with the infrared and ultraviolet layers scanners use to catch fakes. Security journalist Brian Krebs traced the data to IDScan.net, a company whose scanning hardware sits behind ID checks at Hertz, Target, FedEx and over 1,000 marijuana dispensaries. IDScan.net has confirmed only that it is investigating, not that it was breached or how. The FBI opened a criminal investigation the day Krebs published, and the marketplace went offline shortly after.
What happened
On August 31, 2026, a source tipped off security journalist Brian Krebs to a dark-web identity-theft service called Nexus, advertised on the Russian cybercrime forum Exploit, which included Krebs’s own Virginia driver’s license as a free sample.
Nexus was offering more than 153 million U.S. and Canadian driver’s licenses, over 10 million other ID cards, more than 3 million travel documents, and over 579,000 medical cards, including marijuana dispensary cards, as digital front-and-back scans, some with infrared and ultraviolet versions.
Krebs found that timestamps embedded in the leaked images dated back to at least June 2025, and that nearly 400,000 new driver’s license records were added in a single 24-hour period he observed, pointing to harvesting that was still active. The sellers claimed more in their own listing: “We have been continuously exfiltrating new data for over a year into our private database.”
Krebs traced the data to IDScan.net, a New Orleans-based identity-verification company, through circumstantial evidence: timestamps on leaked images matched dates and locations where named individuals had used ID-scanning devices at Hertz rental counters, the infrared and ultraviolet captures matched IDScan.net’s documented technology, and the company’s clients include Hertz, Target, FedEx and more than 1,000 marijuana dispensaries.
IDScan.net has not publicly confirmed unauthorized access or the scope of any compromise. Jillian Kossman, its marketing and operations leader, told Krebs the company could not share more beyond acknowledging an ongoing investigation: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.”
The FBI’s New Orleans field office opened an investigation on September 1, 2026, the day Krebs published, and senior leaders from the bureau’s cyber division joined a call with him. The Nexus service went offline shortly after, displaying a message that it was no longer available.
A Caesars Entertainment spokesman told Krebs the company had not been an IDScan.net client since February 2025, had no active VeriScan accounts during the breach period, and had not authorized data retention, adding that Caesars expects no impact on its operations.
Two outlets corroborated the scale independently. Malwarebytes reported the same figures — 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, 579,000 medical cards — and that IDScan.net said it was investigating. Reuters reported that IDScan.net did not return its repeated requests for comment, and that the FBI confirmed it is investigating. Biometric Update, combining all document categories rather than driver’s licenses alone, put the total at more than 170 million people affected.
What this means (and what it does not)
The exposed records are not just names and numbers. They are the full front-and-back scans, including the infrared and ultraviolet captures, that businesses rely on to tell a real ID from a fake one. Larry Baldwin, principal intelligence researcher at Cybera, framed the stakes this way: “Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised.” Zach Edwards, a security and privacy researcher, drew a policy lesson from it: “This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids.”
What does not follow is that IDScan.net has been confirmed as the source. Its own statements, through Kossman, stop at acknowledging an investigation — the company has not said it was breached, or how. The attribution to IDScan.net rests on Krebs’s circumstantial matching of timestamps, victim confirmations and scanning technology, not a company admission. And the “over a year” exfiltration timeline comes from the sellers’ own marketplace listing; Krebs’s own review of the leaked images reaches back only as far as June 2025.
What we still do not know
The technical cause of the breach — exposed credentials, misconfigured storage, a compromised account, or something else — has not been disclosed by any source reviewed. IDScan.net has not confirmed it is the breached company. It is also unclear how the breach was ever caught: the record shows it surfaced through a journalist’s tip about a criminal marketplace, not through IDScan.net’s own detection systems. The precise number of people affected is unsettled, since the 153 million figure covers driver’s licenses alone while the combined document count is reported elsewhere at more than 170 million, and one person can appear in more than one document. Whether any regulator beyond the FBI’s criminal probe — state attorneys general, the FTC, or Canadian privacy authorities — has opened its own inquiry is not established, nor is whether IDScan.net or its client companies plan to notify affected individuals directly.
Sources & Bylines
Every source cited in this article, gathered in one place.
- https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ — Brian Krebs
- https://www.usnews.com/news/us/articles/2026-09-02/fbi-says-it-is-investigating-report-that-millions-of-us-drivers-licenses-exposed-in-data-breach
- https://www.malwarebytes.com/blog/news/2026/09/dark-web-site-puts-153-million-drivers-licenses-and-millions-more-ids-up-for-sale — Pieter Arntz
- https://www.biometricupdate.com/202609/more-than-170m-id-scans-for-sale-on-dark-web-in-breach-allegedly-traced-to-idscan-net — Joel R. McConvey
Editorial check, counted automatically
- 4 sources cited
- 13 inline-linked claims
- 0 unsourced claims found
- 0 banned words found
- 0 numbers without context
Also available in Portugues (BR)