In early September 2026, security researcher Brian Krebs reported discovering a new dark web service called Nexus offering digital scans of more than 153 million driver’s licenses belonging to people in the United States and Canada. The collection reportedly also includes more than 10 million other identity documents, roughly 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards. Krebs said he was able to confirm the authenticity of the data by cross-checking scans with nine different individuals whose licenses appeared in the trove, including his own.

The FBI confirmed on September 2 that it was investigating the report, though a bureau spokesperson said it couldn’t comment further “due to the ongoing nature of the investigation.” If confirmed at the scale being advertised, security experts describe this as potentially one of the largest single exposures of government-issued identity documents in North American history.
Tracing the Breach Back to a Familiar Source
The advertisement for the stolen data claimed the group behind it had “persistent access to a major identity verification company and its customers, which includes multiple Fortune 500 companies.” Within days, that source was narrowed down. Krebs reported that the breach traces back to IDScan.net, a New Orleans-based identity verification provider that, among other services, scans customer IDs at Hertz rental car counters and helps marijuana dispensaries across the US verify customer ages. IDScan.net told Krebs it was investigating the matter but did not respond to repeated requests for further comment from Reuters.
Following further analysis, the total number of exposed records was revised down slightly from the original 160 million figure to approximately 153 million, though that’s still an enormous scope for a single breach. The data skews heavily toward American records — a search of the dataset for Canadian licenses alone returned roughly 1.1 million results, with the largest concentration, 473,673 records, tied to Ontario.
A Detail That Amplified the Story
Part of what pushed this breach into wider public attention was the discovery that the exposed records reportedly included a scan of Defense Secretary Pete Hegseth’s driver’s license, which the sellers advertised alongside the rest of the collection. That detail underscores a point security researchers have been making about this kind of breach for years: identity verification databases don’t discriminate by who submits an ID, meaning a system built to protect against fraud can end up exposing exactly the kind of people — including senior government officials — whose personal information carries the highest security stakes when compromised.
Notably, the dark web site offering the data went offline shortly after Krebs published his initial report, though experts caution that doesn’t mean the underlying threat has passed. James E. Lee, president of the Identity Theft Resource Center, told TIME magazine that “this data set will continue to have massive value to the cybercriminal community for many years,” and Krebs echoed that assessment, predicting a similar service using the same stolen data is likely to reappear on the darknet in some form.
Why This Particular Kind of Breach Is So Damaging
A stolen password can be changed. A stolen driver’s license, in a meaningful sense, cannot — the underlying document, complete with a person’s real name, address, date of birth, license number, and photograph, doesn’t change just because it was exposed. That’s what makes ID verification breaches particularly valuable to criminals and particularly difficult for victims to fully remediate. According to reporting on similar past incidents, stolen government ID scans are frequently used to open fraudulent accounts, pass identity checks at other services, or lend false legitimacy to other scams, since a matching photo ID makes a fraudulent claim far more convincing to a human reviewer or an automated verification system.
Security researchers have also used this incident to raise a broader concern about the identity-verification industry as a whole. Krebs noted that as more everyday services — from age-restricted purchases to age-restricted websites, framed as protecting minors — increasingly require uploading a government ID, more of that sensitive data ends up sitting with third-party vendors that face far less regulatory oversight than the institutions, like banks or government agencies, that traditionally handled ID verification directly.
What’s Confirmed and What’s Still Unclear
It’s worth being precise about the state of this story. The FBI’s investigation is confirmed and ongoing. The link to IDScan.net is based on Krebs’s reporting and remains under investigation by the company itself, rather than a confirmed statement of fault from IDScan.net. The exact number of affected individuals, the full scope of what data each record contains, and how the breach actually occurred have not been officially detailed by IDScan.net, the FBI, or an independent forensic investigation as of this writing.
What You Should Do If You’ve Had a License Scanned Recently
Given the breadth of services now requiring an ID scan — car rentals, dispensaries, age-verification systems, and various online services — it’s difficult for most people to know with certainty whether their own driver’s license is part of this specific breach. The most useful practical steps apply broadly regardless: monitor your credit reports and bank statements for unfamiliar activity, consider placing a fraud alert or credit freeze with the major credit bureaus if you’re concerned, and be especially skeptical of any unexpected communication that references your real name, address, or ID details, since that kind of personalized detail makes phishing attempts significantly more convincing. If you’ve recently rented a car from Hertz or visited a dispensary that used IDScan.net’s verification service, it’s reasonable to treat your information as potentially exposed and act accordingly.