FBI Opens Probe After 153 Million Driver’s Licenses Surface on Dark Web
The breach is linked to IDScan.net, an ID verification vendor; the dark web site vanished hours after journalist Brian Krebs published his findings Tuesday.

The FBI confirmed Wednesday it has opened an investigation into a dark web identity theft service that claims to be selling digital scans of more than 153 million driver's licenses belonging to residents of the United States and Canada — a breach that, if confirmed at its stated scale, would rank among the largest exposures of government-issued identification documents in history. Among the data found in the database: the personal identification records of Defense Secretary Pete Hegseth.
The bureau's New Orleans field office is leading the investigation. In a brief statement, the FBI said it was "looking into the incident" but declined to comment further "due to the ongoing nature of the investigation." The agency did not confirm or dispute the scale of the breach as described by the journalist who first reported it.
That journalist was Brian Krebs of KrebsOnSecurity, one of the most closely watched cybersecurity reporters in the United States. Krebs said he was alerted to the dark web service — operating under the name Nexus — after it was advertised on a Russian-language cybercrime forum called Exploit. The method of the advertisement was striking: whoever was promoting the service posted Krebs's own driver's license as a free sample to establish credibility. Krebs pulled the thread.
What he found was a service claiming to hold more than 153 million U.S. and Canadian driver's licenses, more than 10 million identification cards, over three million travel documents and international IDs, nearly 580,000 medical cards, and an additional store of marijuana dispensary membership cards. The license scans were not ordinary photographs — they included front and back images captured in visible light, infrared and ultraviolet imaging, the full suite of techniques used by law enforcement and financial institutions to detect forgeries. The same technology designed to prevent identity fraud was being sold as a tool for it.
Krebs searched the database for information belonging to friends and family members who had given their consent, and confirmed that their records were present. He also worked with security and privacy researcher Zach Edwards, who found their own data in the Nexus database despite not having recently rented a vehicle — but had used their ID at a Planet 13 marijuana dispensary. The common thread was visible: everyone whose data Krebs could confirm had either rented a car through Hertz or submitted identification at a cannabis dispensary. The timestamps on the scanned images appeared to match the times the individuals had presented their licenses at those businesses.
That pattern points toward a specific suspect in the supply chain. Krebs contacted IDScan.net, a company that provides identity verification services to businesses including rental car companies and dispensaries — contexts where customers are routinely asked to submit a government-issued ID for scanning. IDScan.net told Krebs it was "investigating the matter" and that the information he had provided had been "welcome, and helpful" to its internal team. The company has not publicly disclosed the scope of any breach, confirmed whether its systems were compromised, or identified how the data may have been exfiltrated. The FBI's New Orleans office — the bureau's primary cyber investigations hub for the Gulf Coast region — is now involved.
The presence of Hegseth's data in the database adds a national security dimension that goes beyond the immediate consumer privacy implications. The secretary of defense holds one of the most sensitive positions in the U.S. government, with access to classified information, classified systems and classified facilities. The appearance of his driver's license in a commercial dark web database raises questions about what other personal information about senior government officials may be embedded in commercial identity verification pipelines — and what exposure those pipelines represent. The breach did not appear to be specifically targeted at Hegseth; his data appears to have been collected through the same consumer-facing identity submission process that affected millions of ordinary license holders.

The disclosure raises a specific and immediate question about the Pentagon's own security protocols. Senior officials in classified roles are typically subject to periodic background reinvestigations and security awareness briefings that include guidance on minimizing personal data exposure. Whether Hegseth had used Hertz or a cannabis dispensary — the two consumer channels most strongly associated with the breach — or whether his data entered the IDScan.net pipeline through a different client integration is not known. The Defense Department did not respond to requests for comment Wednesday. What the breach illustrates, regardless of the access vector, is that government officials at the highest levels of national security are consumers of the same commercial identity verification infrastructure as the general public — and are exposed to the same risks when that infrastructure fails.
The Nexus site itself is no longer accessible. It vanished from the dark web shortly after Krebs published his investigation Tuesday, a pattern consistent with operators who anticipate law enforcement attention following public exposure. Whether the data remains in circulation through other channels or has been distributed to third-party buyers is unknown. Krebs noted that the database appeared to be growing — approximately 400,000 records were added in the 24-hour period he observed — suggesting active ongoing data collection at the time of the site's disappearance.
The breach arrives against a backdrop of intensifying debate about online identity verification requirements. Privacy advocates including the Electronic Frontier Foundation have raised concerns about legislation in multiple states that would require users to submit driver's licenses to access certain online platforms or age-restricted services — precisely the kind of broad identity submission infrastructure that, if compromised, could expose license data at the scale now under investigation. Security researcher Zach Edwards framed the breach in those terms explicitly: "This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for driver's licenses in order to access services under the guise of protecting kids."
For consumers whose licenses may be in the Nexus database, the immediate practical options are limited. There is currently no public-facing notification system, no breach disclosure by IDScan.net, and no confirmed victim list. The FBI has not provided guidance on what affected individuals should do. Standard identity protection advice applies — credit monitoring, fraud alerts with the major bureaus, and heightened vigilance about identity-related financial activity — but the specific exposure of high-resolution front-and-back license scans, including security features, creates risks that extend beyond standard financial fraud. Physical document forgery, biometric data abuse, and identity impersonation at the point of physical verification are all plausible downstream risks that digital-only fraud protection does not address.
The investigation is at its earliest stages. Whether IDScan.net is the source of the breach, or whether a client, integrator or other party in its supply chain is the point of failure, has not been established. What is established is that 153 million government-issued identity documents — roughly half the adult population of the United States — appear to have been in the hands of people selling them on a Russian cybercrime forum as of Tuesday evening.
Originally published on HNGN
© {{Year}} HNGN, All rights reserved. Do not reproduce without permission.





















