Sep 03, 2026 · 6 min read
Nexus Sells 153 Million Stolen Driver's Licenses
A dark web service called Nexus surfaced on a Russian language crime forum on 31 August 2026 advertising more than 153 million US and Canadian driver's licenses, over 10 million other ID cards, 3 million travel documents and 579,000 medical cards. Evidence gathered by KrebsOnSecurity points at IDScan.net, a New Orleans identity verification firm that says only that it is investigating. The FBI opened an inquiry the next day.
The sample image the seller used to advertise the service was Brian Krebs's own Virginia driver's license. He had not uploaded it anywhere. He had rented a car.
Key Takeaways
- Nexus surfaced on the Russian language cybercrime forum Exploit on 31 August 2026 offering identity documents belonging to more than 170 million people, according to KrebsOnSecurity.
- The advertised inventory covered 153 million US and Canadian driver's licenses, over 10 million ID cards, more than 3 million travel documents and at least 579,000 medical cards including marijuana dispensary cards.
- Timestamps matching real ID checks, plus infrared and ultraviolet capture layers, point at identity verification vendor IDScan.net, which has confirmed only that its team is investigating.
- The FBI's New Orleans field office opened an investigation on 1 September 2026, and Nexus went dark shortly after Krebs published on 2 September.
- A license number, date of birth and address cannot be rotated the way a password can, which makes this exposure permanent rather than something you fix and move on from.
What Was Nexus Actually Selling?
Nexus sold searchable access to scans of government issued identity documents, not a static dump. The operators told the Exploit forum they had been "continuously exfiltrating new data" for over a year before going public, and Krebs watched the record count climb by roughly 400,000 in a single 24 hour window.
Put the headline number against a denominator. The Federal Highway Administration counted 237,655,885 licensed drivers in the United States in 2023. The Nexus figure spans the US and Canada and almost certainly repeats scans of the same people, so it is not a clean 64% of American drivers.
For scale: the AssuranceAmerica breach that exposed 6.9 million driver's licenses in July 2026 was the largest we had covered. Nexus advertised twenty two times that volume eight weeks later.
What Links the Data to IDScan.net?
Two pieces of circumstantial evidence, both reported by Krebs, neither confirmed by the company. The first is timing: timestamps on sample licenses matched the moments those people had handed an ID to a business. Krebs's own record lined up with a Hertz car rental, and researcher Zach Edwards's with a Las Vegas dispensary visit during DEF CON. Hertz and the dispensary chain Planet13 both appear on IDScan.net's client list. The second is the file format: the records carry infrared and ultraviolet capture layers, a niche signature that IDScan.net's own marketing describes.
Treat the attribution as strong but unconfirmed. IDScan.net told Krebs it could not share more while its investigation ran, and its chief executive did not respond to TechCrunch either. No breach has been formally acknowledged.
Why Is a Scanned ID Worse Than a Leaked Password?
Because there is no reset button on a date of birth. Malwarebytes put it cleanly: you can reset a password, you cannot easily replace your face, date of birth, address, or license number, particularly when they arrive attached to high resolution images of the document itself.
The infrared and ultraviolet layers are the part most coverage skipped, and they change the threat category. Those layers capture the covert security features a state prints into a card so a scanner can tell a real license from a fake. A dump containing them is not just a list of personal details. It is a reference library for producing documents that pass the same automated checks.
Downstream that feeds know your customer bypass at banks, synthetic identities blending a real image with an invented profile, and social engineering against anyone who asks you to "send a photo of your ID". The last reaches ordinary people fastest.
The Age Check Boom Built This Honeypot
Nobody set out to build a 153 million record archive of ID scans. It accumulated one bar door and one dispensary counter at a time, because the cheapest way to satisfy an age check is to outsource it to a vendor who scans the card. NIST's identity proofing guidance, SP 800-63A, sets out how to validate evidence at enrolment. Nothing in it obliges a retail vendor to delete the image afterwards, and retention is where the risk lives.
This is the concrete cost of the architecture privacy researchers have objected to for two years. Discord had already lost 70,000 users' ID photos before asking for more of them, and Apple's UK age verification rollout pushes the same pattern onto a much larger population. Every mandate that says "verify age" without saying "and never store the document" produces another vendor holding a pile like this one.
What This Means for Your Inbox
Your email account is the recovery path for everything else you own, and a scanned license is the strongest possible prop for talking a support agent into resetting it. Recovery flows are built to be forgiving. A caller who recites your license number, date of birth and home address, then produces a matching image on request, leaves the human on the other end little to disbelieve.
Expect that effect in your inbox before you see any credit fraud. A message opening with your real address and the last digits of your real license number clears a plausibility bar generic spam never does. The FTC logged 6.5 million consumer reports and $12.5 billion in reported fraud losses during 2024, before a corpus of this size was on sale.
Treat any unsolicited email asking you to "verify your identity" as hostile, including one that appears to come from an ID vendor telling you about this breach. Go to the service directly.
What Should You Do Right Now?
There is no notification list, because no breach has been confirmed and no vendor is writing to anyone. Assume exposure if you have ever handed a physical ID to a scanner at a rental counter, dispensary, casino or large retailer.
- Freeze your credit at all three bureaus. A freeze is free and must be placed separately with Equifax, Experian and TransUnion. The FTC's guide to freezes and fraud alerts explains the difference: a freeze blocks new accounts, a fraud alert only asks lenders to check with you first.
- Harden your email recovery path. Remove stale recovery phone numbers, keep a recovery address published nowhere, and turn on a passkey or hardware key so a support agent's judgement is not the last line of defence.
- Ask the vendor, not the shop. When a business scans your ID, ask whether the image is stored, for how long, and which vendor holds it. Several state privacy laws give you a deletion right against that vendor, worthless if you never learn its name.
- Watch for document based fraud, not password fraud. New accounts, unfamiliar loan enquiries and mail addressed to strangers are the signals here. IdentityTheft.gov generates a free recovery plan if any of them appear.
- Prefer age checks that do not take the card. Where a service offers a token based age signal instead of a document upload, use it. The scan you never gave cannot leak.
Nexus going offline is not resolution. The operators claim over a year of quiet collection before they advertised, buyers from that window still hold what they bought, and the vendors still hold the originals.