A trove of more than 153 million US and Canadian driver’s licenses and other identity documents reportedly surfaced for sale on the dark web, prompting an official FBI investigation. The material, offered through a service called Nexus, appeared briefly before going offline, but not before drawing scrutiny from security researchers who confirmed the data looked authentic.
According to the listing, Nexus claimed to hold 153 million driver’s licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579,000 medical cards, 429,000 common access cards, 91,000 residence cards, 77,000 employment authorization records, and 5 million additional documents. The collection was allegedly sourced from an ID-authentication provider based in Louisiana.
How the Breach Was Traced to a Verification Vendor
The service was promoted on the Russian cybercrime forum Exploit. Whoever advertised it posted a well-known cybersecurity journalist’s own driver’s license as a free sample, which is how the leak first came to attention. A preview of US Secretary of Defense Pete Hegseth’s information also appeared in the database, an alarming exposure given the sensitivity of his role.
Investigators verified the data by checking records of friends and family members who consented to the search. A common thread emerged: everyone found in the database had rented a vehicle through Hertz. A separate case involving privacy researcher Zach Edwards pointed elsewhere. Edwards had not recently rented a car but had used an ID at a Planet13 marijuana dispensary. Time stamps on the scanned images matched the moments victims presented their IDs at those businesses, identifying them as the points of exposure.
Neither Hertz nor Planet13 performs identity checks in-house. Both contract the work to a verification vendor, IDScan. The evidence gathered so far centers the leak on that company. When contacted, IDScan said it was investigating. “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” said Jillian Kossman, a marketing and operations leader at idscan.net.
Renewed Scrutiny Over ID Collection and Age Verification
The FBI’s New Orleans field office has opened a formal investigation into the breach. The incident echoes a similar case at Discord, where a compromised third-party provider exposed roughly 70,000 government IDs.
Breaches of this scale have intensified concern among privacy advocates over the growing push for online age verification requirements, which often depend on collecting and storing sensitive identity documents. The Electronic Frontier Foundation has urged the California governor to veto legislation mandating such checks, citing risks to privacy and First Amendment rights. Exposure of documents like driver’s licenses also raises the likelihood of identity theft and related fraud.
The Nexus listing has since been taken down, but the underlying data was available long enough for researchers to confirm its authenticity across multiple verified individuals.
Source
Image: tomshardware.com