Skip to main content

Morning Overview

153 million driver’s licence scans are up for sale and the FBI is on it

A dark-web identity service called Nexus spent the past year quietly building a catalog of scanned identification documents, and by early September it was advertising more than 153 million driver’s licenses for sale, along with millions of additional ID cards, travel documents and medical cards. The scale of the offering drew the attention of a security journalist who traced the source, and then the FBI, which opened a field investigation within days of the reporting going public. The company at the center of it, an identity-verification provider called IDScan, now faces both a federal inquiry and multiple lawsuits.

What Nexus Was Advertising

The service, operating under the name Nexus, listed more than 153 million U.S. and Canadian driver’s license scans as its core offering. Alongside those licenses, the same catalog included roughly 10 million ID cards, 3 million travel documents and 579,000 medical cards, according to figures reported in coverage of the listing.

Nexus reportedly claimed the documents came from a live breach at a “major identity verification company” and said it had been pulling in new records continuously for more than a year before the listing surfaced publicly. Reporting on the marketplace describes an operation built around ongoing access to a verification pipeline rather than a single one-time theft of an existing archive.

Driver’s license scans carry more identifying detail than most people realize once they leave the counter where they were captured. A typical scan captures a full-resolution image of the front and often the back of the document, including a photograph, physical address, license number, date of birth and, on many U.S. licenses, a barcode encoding all of that data in machine-readable form. That combination makes a stolen license scan considerably more useful to a fraudster than a bare list of names and numbers would be.

How a Security Journalist Traced the Data to IDScan

Security researcher and journalist Brian Krebs reported the Nexus listing on September 1, after reviewing samples the service made available. Krebs verified the material was genuine by searching the database for his own records, and for records belonging to other individuals who had agreed to be checked as part of the verification process.

That search work is what connected the listing to a specific company. Krebs’s original reporting describes tracking the movements tied to his own and other identified victims’ records back to IDScan, a New Orleans-based identity-verification provider, rather than to any of the businesses that had actually used IDScan’s service to check a customer’s identification.

Krebs has covered dark-web marketplaces and large-scale data breaches for close to two decades, and his reporting has previously led directly to companies acknowledging breaches they had not yet disclosed publicly. That track record is part of why the Nexus listing moved quickly from an obscure dark-web post to a story that drew a federal investigation within days rather than sitting unnoticed the way many smaller criminal marketplace listings do.

Where the Scanned Documents Came From

IDScan’s systems are not something most consumers interact with directly. The company’s ID-verification technology is built into the checkout or check-in process at a range of businesses, including car rental companies, retailers, gun shops, financial institutions, cannabis dispensaries and hospitality businesses, any setting where a business is required or chooses to confirm a customer’s age or identity by scanning a government-issued document.

That structure means the people whose documents ended up in the Nexus listing were never IDScan’s customers in any direct sense. They were customers of car rental counters, stores, banks and similar businesses that happened to use IDScan behind the scenes to process the identity check at the point of service.

That reach is part of what makes a breach at a single identity-verification vendor so consequential. A customer who rented a car, bought a firearm, checked into a hotel or visited a cannabis dispensary at any point while that business relied on IDScan’s systems could have had a document scanned and stored, often without much visibility into which back-end vendor was actually processing the check behind the counter or kiosk they interacted with directly.

The FBI Opens an Investigation

The FBI’s New Orleans field office, the jurisdiction covering IDScan’s home base, opened an investigation into the apparent breach and confirmed to reporters that it was actively looking into the incident. A federal investigation of this kind typically examines both how the data was obtained and whether it is still being actively distributed, rather than focusing solely on the original point of compromise.

Neither IDScan nor federal investigators had, as of the reporting, publicly detailed the technical method used to pull data out of IDScan’s systems over the claimed one-year period, leaving open questions about how a breach of that duration went unnoticed internally for so long.

Lawsuits and the Marketplace Going Dark

IDScan is now facing multiple lawsuits filed by parties alleging the company failed to adequately protect the scanned documents it processed on behalf of its business clients. The legal filings add a civil track running alongside the federal investigation, a common pattern following large-scale identity-document exposures where affected individuals or advocacy groups pursue damages separately from any criminal inquiry.

The Nexus service itself reportedly went offline not long after the reporting was published, a shift researchers have observed before in similar cases, where public attention prompts an operator to shut down a listing rather than risk further exposure of its own infrastructure. Whether the underlying data continues to circulate through other channels remains unclear.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.



More from Morning Overview