Reports on alleged massive IDScan.net data breach: 153 million driver’s licenses for sale
Cybersecurity experts are finding their own driver’s licenses for sale on an illicit marketplace.

Image by Ground Picture | Shutterstock
- A new dark web platform Nexus posted 153 million driver’s license scans and millions of other identity and medical cards for sale.
- Nexus attributed the scans to ID verification platform IDScan.net, which has not yet confirmed unauthorized access or the incident’s scope.
- The FBI opened an inquiry, Nexus shut down the service shortly after Brian Krebs reported it.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A dark web marketplace is selling 153,000,000 American and Canadian driver's licenses, reportedly siphoned from idscan.net. This platform specializes in in-person identity (ID) verification and serves businesses such as Hertz, FedEx, Target, marijuana dispensaries, and many more.
Brian Krebs, an investigative reporter and cybersecurity expert who first broke the story, warns that the illicit marketplace, dubbed Nexus, sells scans of IDs on over 170 million people in North America.
The scans include 153 million driver’s licenses, 10 million ID cards, 3 million international travel cards, and 579,000 medical cards, including marijuana dispensary cards.
Nexus operators claimed to be siphoning images collected by a Louisiana-based identity verification company, IDScan.net.
Krebs claims that the Nexus service is “likely not exaggerating about that 153 million number.” A blank search returned 11.5 million pages of results with roughly 15 results per page. The records included the driver's license of US Defense Secretary Pete Hegseth, listed for sale for $100.
The illicit service advertised Krebs’ own Virginia driver's license as a free sample on a Russian cybercrime forum.
“The record that features my driver's license includes 6 image files – 3 pairs of photos of the license’s front and back — a basic image scan — as well as infrared and ultraviolet versions of the same images,” Krebs said.
IDScan hasn’t yet released any official information and only mentioned the “team’s investigation.” The FBI's New Orleans field office launched an official inquiry. Cybernews reached out to the company for a comment and will update the story with a response.
Cybernews can’t verify the claims. One of the commenters on KrebsOnSecurity said they received a notification from IDScan informing them about a potential security incident.
“We are working urgently to validate that information and determine whether any unauthorized access occurred, and the scope of such activity … At this time, we have not reached conclusions regarding the nature or scope of the incident, including what information was involved,” the cited message reads.
Shortly after Krebs’ report, the Nexus service was shut down, displaying only a message that it is no longer available.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
If the cybersecurity incident is real, the potential implications are devastating for millions of people who might be targeted by cybercriminals.
“It is a catastrophic data breach, probably one of the worst I've ever seen. If you’re in the US and have traveled, gotten a hotel, purchased marijuana or alcohol, there is a high probability you’re in this,” vx-underground, an anonymous threat analyst group, posted on X.
“This poses a significant threat to celebrities (musicians, YouTubers, streamers, adult entertainers, actors, etc), politicians, lawyers, wealthy people (CEOs, investors, people of public interest), Law Enforcement Officers, etc.”
Krebs asked several friends and family members and verified that the data was correct. Individuals had traveled on or very close to the dates in the timestamps attached to their images.
IDScan performs more than 21 million verifications monthly at over 20,000 locations worldwide. The company says it uses “adaptive AI to rapidly authenticate documents and continuously train our models to spot the latest fraud trends and deepfake identities.”