Security journalist Brian Krebs discovered a database, advertised on a Russian cybercrime forum through a service called Nexus, that claimed to hold scans of more than 153 million U.S. and Canadian driver's licenses. According to Tom's Hardware, the same listing also claimed to include 10 million ID cards, 1.9 million travel documents, 1.3 million international driver's licenses, 579,000 medical cards, 429,000 common access cards, 91,000 residence cards, 77,000 employment authorization records, and 5 million other documents. Krebs noted that running a blank search on the site returned roughly 11.5 million pages of results at about 15 results per page, suggesting the 153 million figure was not exaggerated.
Krebs found his own driver's license in the database, along with a preview of Defense Secretary Pete Hegseth's information; the Defense Department is reportedly aware and investigating. Krebs worked with security researcher Zach Edwards, whose ID also appeared in the leak, to trace the source. Krebs believes his data was scanned during a Hertz car rental, while Edwards said his ID was scanned at a Planet13 marijuana dispensary. Both companies use third-party identity verification rather than handling authentication themselves, and both reportedly contracted the same vendor, IDScan.net, a Louisiana-based company. Time stamps on the leaked scans lined up with when Krebs and Edwards had used their IDs at those businesses, pointing to IDScan as the likely source.
IDScan.net confirmed it is investigating. A spokesperson identified in Tom's Hardware as Jillian Kossman told Krebs, "At this point I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation." A commenter on Krebs' report said their company had received a breach notification from IDScan dated September 1, stating that the company was working to validate reports of exposed information, had secured its systems, notified partner companies, engaged legal counsel, and started a third-party forensic investigation. The FBI is also investigating, with Tom's Hardware reporting that the bureau's New Orleans field office has opened a formal inquiry. Nexus went offline shortly after Krebs' report was published, though it could resurface under a different domain.
The breach raises broader privacy concerns. Tom's Hardware noted a similar incident at Discord, where a third-party provider's breach exposed 70,000 government IDs, and pointed to privacy advocates such as the EFF pushing back against online age-verification laws that require uploading ID documents. Tom's Guide similarly noted that the leak comes as governments worldwide roll out age-verification requirements for adult content, which privacy advocates warn put personal data at risk. Tom's Hardware added that leaked driver's licenses, often accepted for opening credit lines and bank accounts, could enable identity theft, and that exposure could be especially dangerous for vulnerable groups such as domestic violence survivors and people in witness protection.
Both outlets recommend precautions. Tom's Guide suggests asking businesses not to scan your ID when possible, watching for phishing and social engineering attempts, avoiding suspicious links or attachments, using strong unique passwords or a password manager, and considering identity theft protection services. Neither source confirmed whether Nexus will return under a new domain, and IDScan had not shared further details beyond acknowledging the investigation at the time of reporting.
