The FBI is investigating the massive collection as questions remain about its source and consumers consider steps to protect their identities.
NEW ORLEANS, LA — The FBI is investigating after a dark-web identity theft service advertised access to more than 153 million driver’s license scans from the United States and Canada, a collection researchers have linked to identity-verification technology used by businesses across numerous industries.
The 153 million figure should not yet be treated as a confirmed count of people affected. The number came from the operators of a service called Nexus, and investigators have not publicly established how many unique people are represented in the collection or confirmed the full source of the records. Cybersecurity journalist Brian Krebs reported finding authentic license images in the database, including his own, and traced evidence surrounding several records to systems associated with New Orleans-based identity-verification company IDScan.net. The company told Krebs it was investigating but had not publicly confirmed that its systems were breached.
Nexus appeared on a Russian cybercrime forum in late August and promoted access to a much larger collection of identity documents. In addition to more than 153 million claimed driver’s license records, the service advertised millions of identification cards, travel documents, international identity documents and hundreds of thousands of medical cards. Krebs reported that a blank search of the service produced roughly 11.5 million pages of results with about 15 entries on each page, suggesting that the advertised scale was at least plausible. About 1.1 million of the driver’s license results appeared to be Canadian, with most of the records originating in the United States.
The material was more detailed than a typical database of names and identification numbers. Some driver’s license records contained multiple images of the same document, including front-and-back scans captured using visible, infrared and ultraviolet imaging. Krebs found timestamps attached to some files and compared those dates with the activities of people who agreed to have their records examined. Several timestamps corresponded with dates when the individuals had rented vehicles or used businesses where an identification document may have been scanned. Those findings helped point the investigation toward IDScan.net, although they do not by themselves establish that the company was the source of every document in the collection.
IDScan develops equipment and software used to authenticate government-issued identity documents. The company says its technology performs millions of identity verifications each month at thousands of locations. Krebs reported that IDScan has identified major companies as users of its services and has supplied identity-verification technology to businesses including car-rental operations and cannabis dispensaries. Caesars Entertainment later told Krebs it was no longer an IDScan customer when the suspected incident occurred and said IDScan had indicated the incident should not affect Caesars. The status of other companies and customers remains under investigation.
The FBI’s New Orleans field office has confirmed that it is examining the incident but has declined to provide details while the inquiry continues. IDScan had not publicly confirmed unauthorized access to its systems as of the latest reports. Multiple lawsuits have since been filed in Louisiana accusing the company of failing to adequately protect personal information. Those allegations have not been proven in court. The Nexus website also disappeared from the dark web shortly after the initial reporting, but its disappearance does not establish that copies of the data are no longer circulating.
For consumers, the uncertainty creates a difficult problem: there is no confirmed public list showing everyone whose license may be included. Federal identity-theft guidance says people whose driver’s license information has been exposed should contact their state motor vehicle agency. Depending on the state and circumstances, the agency may flag the license number or recommend obtaining a replacement. A replacement card does not necessarily erase all risks from a stolen scan because other information printed on a license, including a person’s name, birth date and address, may remain useful to someone attempting impersonation or fraud.
The Federal Trade Commission also recommends reviewing credit reports and considering a credit freeze after sensitive identity information is exposed. A freeze prevents prospective creditors from accessing a credit report, making it more difficult for someone to open a new credit account using stolen information. Credit freezes are free and must be placed separately with Equifax, Experian and TransUnion. Consumers can temporarily lift a freeze when they legitimately need to apply for credit. A fraud alert is another free option that instructs businesses to take additional steps to verify a person’s identity before extending new credit.
People concerned about misuse should also continue watching existing bank, credit-card and credit-report activity because a freeze is aimed primarily at new credit and does not stop fraud involving accounts that are already open. The FTC directs identity-theft victims to IdentityTheft.gov, which provides individualized recovery steps. If suspicious accounts, debts or transactions appear, consumers can document the activity, contact the affected company and report identity theft through the federal service. Those precautions are particularly important with identity-document exposure because a driver’s license cannot be changed as easily as a password.
The incident also highlights a broader risk created when businesses retain digital copies of identification documents collected for age checks, rentals, financial transactions and other verification purposes. A stolen password can usually be reset, while government-issued identity documents contain information that may remain valid for years. Researchers examining the Nexus collection said the presence of high-quality scans could make some forms of impersonation more convincing, especially when organizations rely heavily on document images as proof of identity.
The FBI investigation remains open, and IDScan has not publicly established the number of people affected or confirmed the full circumstances under which the records were obtained. Until investigators or affected companies provide verified notifications, the widely reported 153 million figure remains a claim about the number of driver’s license records offered through Nexus rather than a confirmed count of breach victims.
Author note: Last updated September 5, 2026.