Start with Identity
← Blog
News

A service sold 153 million driver's licenses scraped from an identity verification vendor

Nexus, advertised on a Russian cybercrime forum, sold access to more than 153 million US and Canadian driver's licenses that its operators say they exfiltrated from IDScan.net over more than a year. The FBI opened an investigation.

By SWI Community TeamSep 1, 2026Updated Sep 14, 2026

Brian Krebs reported that a service called Nexus, advertised on the Russian-language cybercrime forum Exploit, was selling lookups against more than 153 million US and Canadian driver's licenses and other identity documents. Its operators claimed to have been "continuously exfiltrating new data for over a year" from IDScan.net, a Louisiana identity verification provider that processes over 21 million verifications a month for customers including Hertz, Target, FedEx, and cannabis dispensaries. The New Orleans FBI field office opened an investigation. IDScan.net confirmed on September 8, 2026 that an unauthorized third party may have accessed and copied certain customer information. Nexus went offline shortly after Krebs published.

Why it matters

Identity verification vendors sit in an uncomfortable position: to prove a document is genuine they must collect it, and to handle disputes they tend to retain it. The result is a concentration of exactly the data that makes downstream identity fraud work, held by a company most of the affected people have never heard of and never chose.

A driver's license image is not a password. It cannot be rotated, it stays valid for years, and it is the knowledge base behind the identity questions that help desks still use to verify callers. That is the operational link back to help desk social engineering: a caller who can recite a license number, an address history, and a date of birth passes verification procedures at a great many organizations right now. Every large identity document dump makes knowledge-based verification worse, permanently.

Two things follow for practitioners. If you buy identity verification, the vendor's retention policy is part of your risk, so ask what is kept after a successful check and for how long. And if your help desk still verifies callers with facts a data broker can sell, move it to something the caller must hold rather than know, such as a push to an enrolled device or a verified manager callback. See the McKesson breach for where the other path ends.

Source: KrebsOnSecurity

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.