Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On August 31, 2026, a dark web platform named Nexus posted a database on the Russian-language Exploit forum claiming 153 million U.S. and Canadian driver's licenses, 10 million ID cards, and 3 million travel documents. The records include front-and-back scans in visible, infrared, and ultraviolet imaging, with timestamps matching car rentals and marijuana dispensary visits. An investigation by the FBI's New Orleans field office is underway, and vendor IDScan.net has confirmed it is "investigating the matter."
- Nexus claims 153 million U.S. and Canadian driver's licenses, with an increase of roughly 400,000 records in 24 hours indicating ongoing data collection.
- KrebsOnSecurity empirically verified 9 of 15 individuals contacted: timestamps in the records align with real-world events such as Hertz rentals and visits to the Planet13 dispensary.
- Scans include multi-spectral imaging (infrared/ultraviolet) using technology documented exclusively on IDScan.net devices, which has confirmed an internal investigation.
- The FBI's New Orleans field office has opened an official inquiry; IDScan.net has not released a full statement on the compromise vector.
How Nexus Works and Why the Numbers Are Verifiable
Nexus monetizes access via a preview model: buyers can view records with sensitive data redacted, including holder photos when available. The empirical verification by KrebsOnSecurity went beyond simple identity matching. The 9 confirmed subjects out of 15 contacted showed timestamps aligning with documented events in their travel itineraries.
One sample shows GMT timezones associated with Hertz transactions and entries at Planet13, a dispensary chain with an exclusive agreement with IDScan.net. The record structure is uniform: six files per document, with front-and-back imaging in visible, infrared, and ultraviolet. This spectral triplication is not standard for generic document readers but is documented in IDScan.net's commercial materials.
The total volume is estimable through the platform's empty search function: it returns roughly 11.5 million pages with about 15 results each. Ontario records alone total approximately 473,673 results. The 153 million figure derives from the seller's claim and KrebsOnSecurity's inductive calculation, not from an exhaustive verification of the entire dataset.
The IDScan.net Chain: 21 Million Checks a Month, No Bank-Grade Regulation
IDScan.net processes over 21 million identity verifications monthly, with a network of more than 20,000 global locations and over 1,000 marijuana dispensaries across 19 U.S. states. Clients include Fortune 500 companies such as Hertz, Target, FedEx, and Caesars Entertainment. The operational model is B2B: the vendor supplies scanning hardware and software to service points, which collect documents for age verification and compliance purposes.
KrebsOnSecurity's research systematically excluded airports and aviation security checks as the primary source. Passports do not appear in the dataset, and some verified subjects had presented their licenses only in third-party contexts — car rentals, dispensaries, hotels — never to the TSA. This negative correlation strengthens the hypothesis that the collection point lies in the commercial verification chain rather than the governmental one.
The technical collection mechanism is passive: devices capture full scans during routine operations, apparently stored or replicable by the central vendor. It is unconfirmed whether GMT timestamps are generated at the device level or aggregated in a central system, nor whether the failure point resides in IDScan.net, a specific client, or a supply-chain integrator.
Why This Matters
The dossier documents no specific remedial measures or a defined technical perimeter of the compromise. IDScan.net, through marketing and operations leader Jillian Kossman, limited its response to a verbal confirmation of an internal investigation: "At this point I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation."
The brief does not specify the nature of exposed data beyond document images. It is unknown whether the dataset includes geolocation metadata, transaction logs, or correlations between timestamps and identities. The dossier also does not document the initial access vector — exposed API, compromised credentials, supply chain, or insider — nor has it determined whether the 153 million records are all unique or include duplicates and renewals.
Data permanence is a structural constraint: a driver's license is not "resettable" like a password. Once exposed, the compromise is permanent for the holder, who cannot revoke the document or alter its serial numbers, biometric features, or barcodes. This asymmetry between commercial collection and individual protection is the core risk the incident exposes.
Who Is in the Database and What the FBI Says
Among verified records is that of Pete Hegseth, the current U.S. Secretary of Defense. The presence of high-profile government figures in the verified sample heightens the institutional relevance of the incident, though it does not alter its technical nature. The FBI's New Orleans field office confirmed to KrebsOnSecurity it has "launched an official inquiry," without detailing progress or jurisdictional scope.
Nexus stated in its Exploit posts: "We have been continuously exfiltrating new data for over a year into our private database." The increase of roughly 400,000 records in 24 hours, verified by KrebsOnSecurity through direct platform observation, corroborates the claim of continuous exfiltration. The seller also offers redacted previews with holder photos when available: "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available."
"At this point I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation"
— Jillian Kossman, IDScan.net
Frequently Asked Questions
Why is the GMT timezone in timestamps significant?
GMT timestamps correspond to real events verified by the subjects involved, but it is unconfirmed whether they are generated by IDScan.net devices or client systems. Consistency with Hertz rentals and Planet13 accesses supports the hypothesis of centralized collection in the vendor's chain.
Has IDScan.net confirmed it was breached?
No. IDScan.net has confirmed only that it is "investigating the matter." The dossier does not establish whether the failure point lies with the vendor, a specific client, or an integrator, nor does it document the initial access vector.
Are all 153 million records verified?
No. The figure derives from Nexus's claim and is partially verifiable through the platform's empty search function. KrebsOnSecurity empirically confirmed 9 of 15 individuals contacted, with timestamp matches to real events. It is undetermined whether the total includes duplicates or renewals.
The incident raises a broader governance question: age verification systems for ordinary services — a car rental, a dispensary entry — build de facto government archives that operate outside regulations intended for public institutions. The convenience of instant verification translates into centralized document retention managed by private vendors without the biometric data protection standards that would apply to an equivalent government database. The difference is regulatory, not technical: the risk is identical, the protection is not.
Information is based on the cited advisory and current as of publication.
Sources
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.