The FBI opened an investigation on September 1 after a dark-web service called Nexus began offering scans of more than 153 million U.S. and Canadian driver’s licences for sale. A copied licence does not expire when its plastic card does: it gives a fraudster the name, address, date of birth and document images used to get through account-recovery and identity checks.
Nexus advertised its service on the Russian-language cybercrime forum Exploit on August 31, offering previews before purchase and using KrebsOnSecurity founder Brian Krebs’s own Virginia licence as a free sample. The FBI’s New Orleans field office confirmed it had begun an inquiry, but as of September 4, it had not identified the source, confirmed a breach, or established how many people were affected.
The apparent trail points toward IDScan.net, a Louisiana company whose VeriScan software is used by businesses to inspect government IDs. Krebs’s reporting found timestamp and image-format clues consistent with that system. That is a serious lead, not a confirmed compromise: BleepingComputer reported that it remained unclear whether IDScan’s systems had been breached.
The 153 million-record claim and the evidence behind it
Nexus claimed it held more than 153 million driver’s licences, 10 million other ID cards, three million travel or international-ID documents, and 579,000 medical cards. That adds up to more than 170 million documents, although those totals are assertions by the alleged criminal operators, not audited figures.
Krebs was able to test the broad scale of the collection. A blank Nexus search returned roughly 11.5 million result pages with about 15 records per page, or approximately 172.5 million displayed results from those two figures. That does not prove every record was unique or valid, but it does make the advertised inventory harder to dismiss as an empty sales pitch.
Canada accounted for about 1.1 million driver’s-licence results, including 473,673 records from Ontario. The bulk of the apparent licence collection therefore concerned Americans.

The records included more than the mundane IDs scanned at a bar or car-rental desk. Krebs found marijuana dispensary cards, entries tagged “CDL,” apparently for commercial driver’s licences, and some tagged “CAC,” a label that may refer to the government access cards used to enter secure facilities.
Nexus told prospective customers:
“We have been continuously exfiltrating new data for over a year into our private database.”, Nexus’s introductory Exploit post, quoted by KrebsOnSecurity
That claim is unverified. But Krebs matched files from his own June 2025 trip to the service and saw its displayed driver’s-licence count rise by nearly 400,000 in 24 hours. The collection therefore appears to contain material at least that old and may have been growing during 2026.
The most specific lead is IDScan.net’s VeriScan technology. Krebs asked nine people whose records appeared in Nexus to compare timestamps on their scans with their travel and car-rental histories. The dates lined up, including paired scans associated with Hertz rentals. The records also contained infrared and ultraviolet images, formats that IDScan documents as capabilities of its ID-verification products.

That evidence connects affected people, image formats and timestamps. It does not show how the data left IDScan, establish that IDScan itself was breached, or prove that every Nexus record originated there.
IDScan’s own documentation shows why the retention question matters. New VeriScan Cloud accounts default to collecting all data fields, including high-resolution front-and-back ID scans and live photos; Basic-plan customers cannot alter that collection setting. Its separate Screening Service allows customers to choose retention periods from eight hours to seven years and can export logs containing request and response data.
Those settings are configurable, so the documentation cannot reveal what any particular customer retained or supplied to Nexus. But it shows the practical danger of systems that treat an ID check as a momentary transaction while keeping the underlying scans around. That concern has already surfaced in the precedent for identity verification systems and in debates over government-ID and selfie access checks.
Caesars Entertainment, which appeared on IDScan’s public client roster, said on September 2 that it had stopped using VeriScan in February 2025, had no active account when the alleged incident occurred, and had not authorized IDScan to retain its account data. Replacing a physical licence would not erase a copied scan or the personal details embedded in it.
There is no citable evidence that anyone completed a Nexus purchase or used a record in a known fraud case. The service went offline after the reporting, although BleepingComputer reported that criminals still appeared to have access to the database.
The FBI investigation now has to answer the question the listings cannot: whether Nexus is selling a real, current cache from a compromised system, or a collection assembled through some other route. For the people whose documents appeared in its search results, that distinction will not make the scans any less reusable.
Key Takeaways
- The FBI opened an inquiry after Nexus advertised more than 153 million U.S. and Canadian driver’s-licence scans.
- KrebsOnSecurity observed roughly 11.5 million Nexus result pages, consistent with a collection of about 172.5 million displayed records.
- Timestamps and infrared and ultraviolet image formats point toward a possible connection to IDScan.net’s VeriScan technology.
- No investigation has yet confirmed an IDScan compromise, a victim count, or a completed Nexus sale.
- IDScan documentation describes configurable retention settings that can keep identity-verification data for as long as seven years.
Further Reading
- FBI Probes Service Selling 153M+ Drivers Licenses, KrebsOnSecurity’s investigation of Nexus’s listings, document counts and apparent IDScan connection.
- IDScan sued over alleged data breach affecting 153 million drivers, Independent follow-up on the FBI inquiry, lawsuits and unresolved breach claims.
- Caesars Denies Exposure as FBI Probes Theft of 153 Million Driver’s License Scans, Caesars’ response and the lasting risk of copied identity documents.
- How can I control what visitor data is collected and retained?, IDScan’s VeriScan Cloud collection and retention documentation.
- Screening Service Web Portal | IDScan.net, IDScan documentation covering logs, exports and retention settings.
