The FBI confirmed on September 2, 2026, that it is investigating a report that digital scans of more than 153 million driver’s licenses from the United States and Canada surfaced for sale on a dark web marketplace. The disclosure, first reported by security journalist Brian Krebs of KrebsOnSecurity and picked up by Reuters, TechCrunch, and regional outlets including gvwire.com and Red Lake Nation News, points to a likely breach at IDScan.net, a Louisiana-based identity-verification company whose scanning technology sits behind ID checks at car rental counters, retailers, and dispensaries across North America.
A spokesperson for the bureau told Reuters the FBI is “looking into the incident” but declined further comment, citing the ongoing nature of the investigation. Krebs reported that the FBI’s New Orleans field office opened a formal inquiry after the marketplace, calling itself Nexus, began advertising documents on the Russian-language cybercrime forum Exploit. The story is still developing, and neither the FBI nor IDScan.net has confirmed the full scope of what happened.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What happened: the Nexus marketplace and its 153 million driver’s licenses
According to Krebs’s reporting, a service called Nexus appeared on the Exploit forum on August 31, 2026, advertising searchable scans of North American identity documents. The operator claimed the trove covered more than 170 million people, broken down as more than 153 million driver’s licenses, roughly 10 million other identification cards, about 3 million travel documents, at least 579,000 medical cards including cannabis dispensary cards, roughly 91,000 residence cards, and 77,000 employment authorization records, according to Krebs’s September 2026 reporting. The seller told Krebs the data had been “continuously exfiltrating for over a year,” and that in a single 24-hour window the license count on the site grew by nearly 400,000 records, a pace that suggests the pipeline feeding Nexus is still active rather than a one-time historical dump.
Krebs said he discovered the listing after the Nexus operator offered his own Virginia driver’s license as a free sample to prove the service worked. He and other reporters also found that licenses belonging to U.S. Defense Secretary Pete Hegseth and an FBI assistant director were listed on the site. Krebs said he confirmed the authenticity of the stolen images with at least nine affected individuals before publishing. Shortly after his article ran, the Nexus site went offline and was replaced with a single line reading “This service is no longer available,” according to his reporting.
Why investigators are looking at IDScan.net
No government DMV or federal agency has been named as a confirmed source of the leaked images, and Reuters has explicitly noted that the origin of the stolen data has not been conclusively established. But Krebs, working with security researcher Zach Edwards, traced the most likely source to IDScan.net, an identity-verification provider based in New Orleans, Louisiana. The company’s technology is used by businesses including Hertz, Target, FedEx, and Planet 13 dispensaries to scan and verify government-issued IDs, often using infrared and ultraviolet imaging to check for forgeries at rental counters, retail checkouts, and age-restricted point-of-sale terminals.
The infrared and ultraviolet scan artifacts found in the leaked images are consistent with the kind of captures produced by IDScan.net’s in-person reader devices rather than a scraped database of flat photo uploads, which is part of why researchers zeroed in on the company. A post on the Exploit forum promoting Nexus claimed the documents came from a “major identity verification company” and that new records were being added at a rate of roughly half a million per day, which would imply the attacker still had a live feed into the company’s systems as of early September.
IDScan.net has stopped short of confirming a breach of the scale claimed on Nexus, but the company said that on or around September 1, 2026, it detected unauthorized access to customer data and began an internal review. In a notice quoted by Krebs, the company said it is “working urgently to validate that information and determine whether any unauthorized access occurred, and the scope of such activity,” and that “at this time, we have not reached conclusions regarding the nature or scope of the incident, including what information was involved.” IDScan.net has indicated the exposed data may include full names along with driver’s license and other government ID numbers, though it has not released a fuller public statement beyond acknowledging it is investigating a “potential security incident.”
Timeline: how the story broke in 48 hours
| Date | Event |
|---|---|
| August 31, 2026 | Nexus marketplace appears on the Exploit cybercrime forum, advertising scans of North American identity documents; Brian Krebs discovers the listing. |
| September 1, 2026 | IDScan.net says it received information suggesting its systems may be implicated and begins an internal review. |
| September 1-2, 2026 | Krebs confirms the authenticity of leaked images with at least nine affected individuals, including licenses tied to Defense Secretary Pete Hegseth and an FBI assistant director. |
| September 2, 2026 | KrebsOnSecurity publishes “FBI Probes Service Selling 153M+ Drivers Licenses”; Reuters reports the FBI is “looking into the incident.” |
| September 2, 2026 | The FBI’s New Orleans field office opens a formal inquiry into the apparent leak. |
| September 2-3, 2026 | The Nexus site goes offline, replaced with a message reading “This service is no longer available.” |
Scale of the exposure, by document type
The numbers reported by Krebs and other outlets covering the Nexus marketplace break down across several categories of government and institutional identification. The driver’s license figure alone would represent roughly half of all licensed drivers across the U.S. and Canada combined, based on the scale claimed by the marketplace operator, though that claim has not been independently audited by any regulator.
| Document type | Volume claimed on Nexus |
|---|---|
| Driver’s licenses | More than 153 million |
| Other ID cards (state, provincial) | More than 10 million |
| Travel documents / international IDs | Approximately 3 million |
| Medical and dispensary cards | At least 579,000 |
| Reported daily growth rate | Roughly 400,000-500,000 new records per 24-hour period |
Why this breach is different from a typical database leak
Most large-scale identity breaches reported over the past few years, including incidents at healthcare and logistics firms, involve a static dump: attackers pull a database once, sell it, and the exposure is a fixed snapshot. What makes the Nexus case notable is the claim of near-real-time updates. If the daily growth figures reported by Krebs hold up, it suggests the attacker retained standing access to IDScan.net’s pipeline well past the initial compromise, rather than executing a single smash-and-grab. That distinction matters for incident response: a live feed means the exposure window is still open until the access point is found and closed, not just until the stolen files are deleted from a seller’s server.
It also matters for the kind of fraud the data can enable. Driver’s license scans captured through infrared and ultraviolet verification hardware are more valuable to criminals than a simple photo of an ID, because they can be used to defeat automated liveness and authenticity checks used by banks, exchanges, and gig-economy platforms during account opening. A verified-looking scan, paired with a name and date of birth, is closer to a master key for synthetic identity fraud than a stolen Social Security number alone.
Market impact and the identity-verification sector
IDScan.net is a privately held company, so there is no public stock reaction to track, unlike breaches at publicly traded firms. But the incident lands at a moment when identity-verification vendors have become critical infrastructure for a wide range of industries: car rental counters, age-restricted retail, cannabis dispensaries, financial onboarding, and increasingly AI-driven KYC (know-your-customer) checks. A confirmed breach at a vendor with Fortune 500 clients would raise the same kind of third-party risk questions that followed other vendor-side breaches this year, where the exposed company wasn’t the household name but the infrastructure quietly sitting behind dozens of household names.
Businesses that rely on IDScan.net’s scanning hardware and software, including Hertz, Target, FedEx, and dispensary operators like Planet 13, now face a familiar bind: they didn’t suffer the breach directly, but their customers’ scanned IDs may be sitting in the exposed dataset. That puts pressure on vendor-risk teams across retail, hospitality, and cannabis sectors to demand faster disclosure timelines from identity-verification suppliers, and it strengthens the case for treating ID-scanning vendors with the same scrutiny normally reserved for payment processors.
Competitive landscape: how identity-verification vendors handle breach response
The identity-verification market includes a range of players beyond IDScan.net, from large publicly traded firms to smaller regional vendors, each with different breach-notification postures. The table below outlines how the disclosed posture in this incident compares with typical industry practice, based on publicly reported vendor breach-response patterns from the past two years of coverage on this site.
| Response element | IDScan.net (as reported, Sept. 1-3, 2026) | Typical industry practice after a suspected breach |
|---|---|---|
| Initial public acknowledgment | Confirmed “potential security incident” within 24 hours of being alerted | Often 30-90 days after discovery, per past disclosures covered here (e.g. EY’s vendor breach ran an 81-day silence) |
| Root cause confirmed | Not yet determined publicly as of Sept. 3, 2026 | Usually disclosed only after forensic review, weeks to months later |
| Law enforcement involvement | FBI New Orleans field office opened a formal inquiry | Varies; not all breaches trigger a named federal field office investigation this quickly |
| Customer notification | Not yet detailed publicly | Legally required under most state breach-notification laws once scope is confirmed |
| Criminal marketplace still active | Reportedly taken offline shortly after press coverage | Marketplaces often persist for weeks after initial reporting |
Historical context: identity document breaches keep escalating
This incident follows a string of large-scale breaches this year that pushed cumulative victim counts into the hundreds of millions. Earlier in 2026, McKesson confirmed a breach tied to a 284-million-record claim and a ransom demand, while Manchester Airport Group disclosed a breach affecting 8.7 million customers. Health system Aesto disclosed a breach touching 9.5 million patients. Identity documents specifically had already had a rough year before Nexus surfaced: TechCrunch reported in July 2026 that AssuranceAmerica confirmed a breach exposing driver’s license numbers belonging to 6.9 million people. Cumulative reporting has tracked data breaches surpassing 471 million victims globally in the first half of 2026 alone. The Nexus/IDScan.net incident, if the 153-million-license figure holds up under FBI and company investigation, would rank among the largest identity-document exposures reported this year, distinguished less by raw record count and more by the type of document involved: government-issued photo IDs rather than account credentials or medical records.
Driver’s license data sits in a different risk category than an email-password pair. A license cannot be reset the way a password can. Once a scan of a physical government ID is circulating on a criminal marketplace, the document itself, and the person’s name, date of birth, address, and photo, remains usable for fraud until the individual proactively replaces the physical document with their state or provincial licensing agency, which is a slower and more expensive process than a password reset.
What consumers can do right now
Because there is currently no public consumer-facing lookup tool to check whether an individual’s license appears in the Nexus dataset, security researchers covering the story have recommended a defensive posture rather than waiting for direct notification. Steps consumers can take immediately include placing a fraud alert or credit freeze with the major credit bureaus, monitoring bank and card statements for unfamiliar account-opening activity, and treating any unsolicited request to “re-verify” identity documents with extra suspicion, since scammers often use breach news cycles to run follow-up phishing campaigns. The Federal Trade Commission’s IdentityTheft.gov portal remains the standard starting point for reporting suspected identity theft and generating a personalized recovery plan.
- Check whether your state or provincial DMV/motor vehicle agency offers a driver’s license “lock” or fraud-alert feature, if available.
- Freeze credit reports at all three major U.S. bureaus, which is free by federal law.
- Watch for account-opening notifications from banks, telecom carriers, or lenders you did not initiate.
- Report suspected identity theft at IdentityTheft.gov to get a tailored recovery checklist.
- Be skeptical of any email or text claiming to be from IDScan.net, a rental car company, or a retailer asking you to “confirm” ID details after this news broke, since these are prime phishing lures.
What businesses using ID-scanning vendors should do
For businesses that rely on third-party identity-verification vendors, this incident is a reminder that vendor risk doesn’t stop at the contract signature. Security teams should be asking scanning-technology vendors directly whether any of their own customer data touched IDScan.net’s infrastructure, either directly or through a subcontracted verification pipeline, since many retail and hospitality chains route ID checks through resellers rather than a named vendor. Companies should also review how long scanned ID images are retained after a transaction; if a vendor keeps raw scans indefinitely rather than discarding them once verification is complete, that retention policy becomes the single biggest driver of breach impact when, not if, a future incident occurs.
The FBI’s Internet Crime Complaint Center, IC3, is generally the appropriate first stop for organizations that believe their data has surfaced on a marketplace like Nexus, and its public service announcement archive regularly publishes guidance tied to active criminal marketplaces once law enforcement confirms details. Businesses looking to tighten their own defenses against similar vendor-side exposure can also review broader network segmentation practices against ransomware and lateral movement and general steps to protect against ransomware, since criminal marketplaces like Nexus and ransomware operators frequently draw on overlapping access-broker networks.
Analysis: what the FBI’s involvement signals
The FBI’s decision to open a field-office inquiry this quickly, within roughly 24 hours of Krebs’s story going live, is itself a signal about how seriously the bureau is treating the case, particularly after reports that a sitting cabinet official’s identification document was among those listed. Federal investigations into commercial vendor breaches don’t always move this fast; many of the incidents cataloged on this site over the past year took weeks before any law enforcement agency confirmed active involvement. The New Orleans field office’s early engagement suggests investigators see either a national-security angle tied to the officials named in the leak, or concern that the “continuously exfiltrating” access described by the marketplace operator represents an active, ongoing compromise rather than historical data for sale.
It is also worth noting what has not been confirmed. No court has convicted anyone in connection with this incident, IDScan.net has not confirmed it was the breached party, and the FBI has not named a suspect or attributed the marketplace to a specific criminal group. Readers should treat the IDScan.net connection as the leading investigative lead reported by Krebs and corroborated by researcher Zach Edwards, not as an adjudicated fact.
Predictions: where this story goes next
- IDScan.net will likely issue a more detailed public statement within the next one to two weeks once its internal forensic review identifies the access point, following the pattern seen in comparable vendor breaches this year.
- State attorneys general in at least a handful of the states with the highest concentration of exposed licenses are likely to open parallel inquiries or demand answers from IDScan.net, mirroring the multi-state probes seen after other 2026 breaches.
- Expect renewed scrutiny of infrared/ultraviolet ID-scanning hardware retention policies industry-wide, with rental car chains, retailers, and dispensary operators facing questions about how long they allow vendors to store raw scans.
- Additional criminal marketplaces will likely attempt to re-list portions of the Nexus dataset under new branding even after the original site went dark, a pattern seen repeatedly after other large criminal marketplace takedowns.
- Congressional or regulatory attention to identity-verification vendors as critical third-party infrastructure is likely to increase, given the scale of the claimed exposure and the reported involvement of a federal official’s identification document.
The bigger picture for identity verification
The Nexus/IDScan.net story arrives as identity-verification technology has quietly become one of the most sensitive categories of third-party data processing in the economy, sitting behind everything from car rentals to age-gated retail to financial account opening. Unlike a retailer breach, where the exposed data is typically limited to purchase history or payment tokens, an identity-verification vendor breach exposes the underlying document used to prove who you are in the first place. That is precisely why security researchers like Krebs and Edwards treat this category of vendor with the same urgency normally reserved for breaches at credit bureaus or password managers, and why the FBI’s rapid response here is likely to become a reference point the next time a similar vendor-side identity breach surfaces.
For now, the central facts remain: a dark web marketplace claimed access to scans of more than 153 million North American driver’s licenses, the FBI has confirmed it is investigating, and IDScan.net says it is working to determine whether it was the source and how far the exposure runs. Consumers and businesses alike are left waiting on a fuller accounting, while treating the exposure as real in the meantime given the volume of verified samples Krebs says he checked with affected individuals. It is the latest entry in a growing 2026 cybersecurity threat landscape that has also included large-scale vishing campaigns, such as the one behind the Abbott breach that exposed 10.9 million emails via ShinyHunters.
Frequently asked questions
What is Nexus, the dark web service selling driver’s licenses?
Nexus is a dark web marketplace that appeared on the Exploit cybercrime forum on August 31, 2026, advertising searchable scans of more than 153 million U.S. and Canadian driver’s licenses along with millions of other identification and travel documents. It was reported offline shortly after KrebsOnSecurity published its investigation.
Is IDScan.net confirmed as the source of the breach?
Not officially. Reuters and other outlets note the source has not been conclusively established. Brian Krebs and researcher Zach Edwards identified IDScan.net, a New Orleans-based identity-verification company, as the likely source based on technical evidence, but IDScan.net has only acknowledged investigating a “potential security incident” and has not confirmed a breach.
Is the FBI actually investigating this breach?
Yes. A Reuters-quoted FBI spokesperson confirmed the bureau is “looking into the incident,” and Krebs reported that the FBI’s New Orleans field office opened a formal inquiry on September 2, 2026.
How many driver’s licenses were exposed?
The Nexus marketplace claimed more than 153 million driver’s license scans from the U.S. and Canada, plus more than 10 million other ID cards, about 3 million travel documents, at least 579,000 medical cards, roughly 91,000 residence cards, and 77,000 employment authorization records. These figures come from the marketplace’s own listing as reported by Krebs in his September 2026 investigation and have not been independently verified by a regulator.
Can I check if my driver’s license was part of this leak?
As of this reporting, there is no official consumer-facing lookup tool to check individual exposure. Security researchers recommend proactive steps such as credit freezes and monitoring rather than waiting for direct confirmation.
What companies use IDScan.net’s technology?
Reporting names Hertz, Target, FedEx, and Planet 13 dispensaries among businesses that use IDScan.net’s identity-verification hardware and software for ID checks at rental counters, retail locations, and age-restricted sales points.
What should I do if my driver’s license may have been exposed?
Freeze your credit reports with the major bureaus, monitor financial accounts for unfamiliar activity, check whether your state or provincial licensing agency offers a fraud-alert feature, and use resources like IdentityTheft.gov to report suspected misuse and generate a recovery plan.
How does this compare to other 2026 data breaches?
The claimed 153-million-license figure would rank among the largest identity-document exposures reported this year, alongside incidents such as the McKesson breach tied to a 284-million-record claim, the Manchester Airport Group breach affecting 8.7 million customers, and AssuranceAmerica’s July 2026 breach of 6.9 million driver’s license numbers reported by TechCrunch. What sets this incident apart is the document type: government-issued photo IDs captured via verification hardware, rather than account credentials or payment data.


