A dark web marketplace called Nexus claimed to be selling more than 153 million driver’s license records from people across the United States and Canada, along with over 10 million identification cards, more than 3 million travel documents and at least 579,000 medical cards. The FBI confirmed on Sept. 2 that it is looking into the matter but declined to give further details, citing the ongoing investigation.
The 153 million figure comes from Nexus itself and has not been independently confirmed as the number of unique people affected, since some records contained duplicate images of the same license. But researchers say the database held enough real driver’s licenses to warrant federal attention, and Reuters reported the breach, if confirmed at that scale, could rank among the largest exposures of government-issued identity documents in North America.
Cybersecurity outlet KrebsOnSecurity reported that Nexus surfaced on the Russian-language cybercrime forum Exploit on Aug. 31, advertising identity documents covering more than 170 million people in North America. A blank search on the service returned roughly 11.5 million pages of results at about 15 records per page. While that does not prove 153 million distinct individuals were exposed, the collection appears massive – and it was still growing. The driver’s license count rose by nearly 400,000 records in about 24 hours while Krebs examined the service. The operators claimed they had been continuously collecting data for more than a year, a claim investigators have not verified.
A Virginia reporter finds his own license for sale
Krebs discovered his own Virginia driver’s license listed as a free promotional sample for the service, including front and back images along with infrared and ultraviolet versions. He then checked with friends and family – nine people whose licenses turned up in Nexus said the timestamps closely matched dates they had presented ID in real life, undercutting theories that the leak traced back to a single source like airport security.
In one case, Krebs used his passport at airport security, then later that same day handed his driver’s license to a Hertz rental car agent along with his mother’s license. The Nexus timestamps for both licenses were seconds apart.
The Las Vegas connection
Security researcher Zach Edwards found his own license in the database with a timestamp matching a trip to Las Vegas. He recalled presenting ID at several stops during that trip, but specifically remembered having his license scanned at Planet 13, a marijuana dispensary. That detail led researchers to Louisiana-based identity verification company IDScan.net, which announced a partnership with Planet 13 in 2022. IDScan.net’s scanners capture IDs using ultraviolet, infrared and white light – matching the extra image types found in the Nexus records.
IDScan.net has acknowledged a security incident, saying an unauthorized third party may have accessed or copied customer account information stored in its cloud, potentially including full names and government-issued ID numbers. The company says it is notifying affected people and offering free credit monitoring, but it has not confirmed that the Nexus collection came from its systems or that the 153 million figure represents 153 million unique people.
Shortly after Krebs published his findings, the Nexus site went dark, its login page replaced with a notice that the service was no longer available. That does not mean the data is gone – anyone who bought or downloaded records before the shutdown may still hold copies.
What’s actually at risk
A driver’s license typically carries a full name, address, date of birth, license number, photograph and signature. Unlike a stolen credit card number, that information cannot simply be canceled and reissued. A high-quality scan also gives a criminal something to present as physical proof of identity during in-person or remote verification.
The Federal Trade Commission recommends a credit freeze as one of the strongest defenses against someone opening new accounts in your name. Freezes are free, do not affect your credit score, and require contacting Equifax, Experian and TransUnion separately. A freeze won’t stop misuse of existing accounts, so the FTC also recommends regularly reviewing credit reports for unfamiliar accounts or inquiries, turning on bank and card transaction alerts, and securing your primary email account with a strong password and multifactor authentication.
If you discover fraud, the FTC recommends reporting it through IdentityTheft.gov, which builds a recovery plan based on the type of fraud involved. Victims of license misuse should also contact their state motor vehicle agency, since replacement procedures vary by state, and should keep copies of all reports and case numbers.