More than 153 million driver licences have appeared for sale on a Russian cybercrime forum, days before a major identity services provider confirmed it was investigating a security incident.
In a post on underground forum ‘Exploit’, a new user advertised an identity theft service that sold digital scans of driver's licences from victims in the US and Canada.
Named ‘Nexus’, the service reportedly claimed to have more than 153 million driver licences, more than 10 million identification cards, more than three million travel documents or international IDs, upwards of 579,000 medical cards, and roughly 600,000 ‘Common Access Cards’, employment authorisations or residence cards.
The Nexus hackers said the data was continuously exfiltrated over the course of a year from a “major identity verification company” that services numerous Fortune 500 companies.
“Records are available to preview before purchase with pertinent information redacted,” a forum user wrote.
“Customer photos are displayed if available.”
At the time of writing, the Nexus dark web platform has inexplicably disappeared – its former login page replaced with the message “this service is no longer available”.
All roads lead to IDScan
Security researcher Brian Krebs of KrebsOnSecurity was first to suggest the incident may be linked to New Orleans identity hardware and software provider IDScan.
After searching the leaked Nexus data for details of consenting friends and family, Krebs traced multiple cases where victims had provided ID documents to third parties – such as car rental provider Hertz and cannabis dispensary Planet13 – around the time their details were compromised.
He determined both Planet 13 and Hertz were apparent clients of IDScan – which is known for offering ID scannings services using both infrared and ultraviolet light.
Notably, Krebs found his own listing in the Nexus system included three pairs of photos of the licence’s front and back, a basic image scan, as well as “infrared and ultraviolet versions of the same images”.

A screenshot of Krebs listed on the Nexus database. Source: KrebsOnSecurity
IDScan since confirmed it was investigating a security incident, though it did not name Nexus or confirm the amount of data potentially impacted.
“IDScan.net has determined that an unauthorised third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud,” the company wrote on 4 September.
“The types of information contained within the affected data may include full names and driver’s licence or other government-issued identification numbers.”
FBI launches investigation
Nexus advertised for sale the IDs of US Defence Secretary Pete Hegseth and an assistant director for the Federal Bureau of Investigation (FBI).
Krebs was later told the FBI’s New Orleans field office had opened an official investigation into an “apparent breach” involving IDScan.
The FBI confirmed to Information Age it was "looking into the incident", though it declined to comment further when asked whether Australian data had been impacted.
Law firm Markovits, Stock and Demarco has also launched investigations for potential class-action litigation related to the incident, with the firm noting IDScan has notified “at least some” affected business customers of an incident.
Notably, IDScan seemingly removed a list of big-name clients from its ‘About Us’ page following news of the reported incident.

Before the reported incident, IDScan listed numerous popular global brands on its website. Source: Wayback Machine.
Clients previously listed by IDScan include 7 Eleven, Shell, Hertz, Target, FedEx – all of which have been contacted for comment but did not respond prior to publication.
Are Australians affected?
Information Age asked IDScan whether any Australian clients were affected, but did not receive a statement prior to publication.
Craig Costello, professor in the School of Computer Science at Queensland University of Technology, said although there was currently “no evidence to confirm” Nexus had compromised any Australian licences, organisations should take precautions.
“Australian organisations using the platform should urgently establish whether Australian documents were processed or stored and assess their notification obligations,” said Costello.
“Outsourcing the processing overseas does not necessarily outsource the Australian organisation’s privacy responsibilities.”
Kash Sharma, managing director for Asia-Pacific at cybersecurity firm BlueVoyant, meanwhile said Australians had “reason for caution”.
“The Nexus dataset also reportedly includes over 3 million ‘travel document or international ID’ records – meaning passports,” said Sharma.
“If an Australian travelled to the US and had their passport scanned at any of these locations – such as renting a car at Hertz, checking into a casino or hotel, shipping something at FedEx, or buying age-restricted goods – that scan could plausibly be in the exposed data.”
If the numbers add up, it’s a historical breach
Sharma pointed out that while Nexus claimed to have stolen over 153 million licences for people primarily in the US, the US only has approximately 240 million licensed drivers.
“If the claim holds up, this single breach would touch well over half of every driver's licence in the country,” he said.
“That's a strikingly high penetration rate for one vendor's dataset.”
He added that third-party breaches can reach further than a direct breach of any single company.
“You never signed up with IDScan.net,” said Sharma.
“You rented a car, bought beer, or shipped a package, and the front-desk clerk or self-checkout kiosk happened to route your ID scan through IDScan's system.”
Costello noted although the Nexus marketplace was no longer online, that doesn’t mean the data had disappeared.
“Affected organisations need to identify the actual records involved, notify people clearly, fund replacement credentials and help licence issuers invalidate compromised details,” said Costello.