Dark Web Service ‘Nexus’ Claims to Sell 153 Million Stolen Driver’s Licence Scans

Dark Web Service 'Nexus' Claims to Sell 153 Million Stolen Driver's Licence Scans

A security journalist discovered his own driving licence for sale online within hours of handing it to a car-hire clerk, exposing an alleged breach of over 153 million ID scans.

A dark web marketplace calling itself Nexus is advertising more than 153 million high-resolution scans of driver’s licences from the United States and Canada, according to investigations published by KrebsOnSecurity and Ars Technica. The suspected source is IDScan.net, a Louisiana-based identity verification company that processes document scans on behalf of car-hire firms, hotels, and retailers. The FBI has opened an investigation.

The story broke in a deeply personal way. Dan Goodin, senior security editor at Ars Technica, found a scan of his own driver’s licence listed for sale on Nexus within hours of handing the document to a member of staff at a car-hire desk. His experience became the thread that unravelled a far larger alleged breach.

How Nexus Works

Nexus appeared in late August 2026 on a Russian-language cybercrime forum. Unlike the more familiar stolen-password or card-number markets, this service offered something different: searchable, forensic-quality scans of government-issued identity documents. A user could reportedly enter a name, locate a matching record, and purchase front-and-back images of that person’s licence. In some cases, the scans also included infrared and ultraviolet captures — the kind of detail that makes forgery or impersonation considerably easier.

Brian Krebs, the independent cybersecurity journalist behind KrebsOnSecurity, traced the likely origin of the documents to IDScan.net. That company provides document scanning and verification services to businesses across the car-hire, hospitality, retail, and age-restricted sales sectors. Hertz is among the firms reported to have used IDScan.net’s systems. Krebs’ investigation found that Nexus claimed a total inventory of roughly 170 million identity-related documents, including over 10 million ID cards, more than 3 million travel documents or international IDs, and at least 579,000 medical cards.

The scale points to a centralised breach rather than scattered theft from individual businesses.

Journalists Verified the Scans Themselves

Several security journalists and researchers didn’t just take Nexus’s word for it. Krebs, his mother, an FBI assistant director, and multiple researchers all confirmed that Nexus could produce real, accurate scans of their documents on request. Goodin’s account at Ars Technica was especially striking: the timeline between handing over his licence at the car-hire desk and finding it listed online was measured in hours, not days. That detail has led critics to suggest the data exfiltration from IDScan.net may have been ongoing, possibly in near real-time.

Krebs himself described the service as unlike anything he had previously encountered in this space, given the specificity and quality of the documents on offer.

IDScan.net Under Scrutiny

IDScan.net has not publicly confirmed a breach, but the company is now facing scrutiny over its data-retention practices and security controls. As of early September 2026, several class-action lawsuits have been filed in the United States against the firm, alleging negligence in protecting the driver’s licence data that later appeared on Nexus. The suits are at an early stage, and no court has yet made findings against the company.

Cybersecurity experts and privacy advocates have been direct in their criticism. The core argument is that centralised storage of high-resolution identity document scans by third-party verification vendors creates exactly the kind of single point of failure that criminals will target. Retaining a scan of someone’s driving licence long after the original transaction has served its purpose, critics argue, offers little benefit to the customer and considerable risk.

Some commentators have called for stricter regulation of identity verification services — including hard limits on how long document scans can be kept and clearer disclosure to consumers about where and how their IDs are processed after they hand them over.

The FBI Is Investigating

The FBI has confirmed it is investigating both the Nexus marketplace and the suspected upstream breach at IDScan.net. Investigators are expected to examine whether the company complied with relevant data-protection and security obligations. No charges have been filed and no arrests announced as of the time of writing.

For their part, the documents advertised on Nexus are described as primarily from the United States and Canada. No official UK body has confirmed that British driving licences are included in the dataset, and any such claim remains unverified.

What This Means for Kent Residents

Kent residents who have visited the United States or Canada and handed their driving licence or passport to a car-hire firm, hotel, or retailer using IDScan.net’s systems may be indirectly affected — though whether any UK-issued documents appear in the Nexus dataset has not been confirmed by the Information Commissioner’s Office or any other official UK authority. Anyone concerned should monitor their bank and credit-card statements closely, consider setting up credit-reference agency alerts, and report any suspected misuse of personal data to Kent Police or Action Fraud. Kent County Council’s trading standards service can also offer guidance on identity theft and fraud prevention.

Source: @arstechnica

⚡

Dark Web Service 'Nexus' Claims to Sell 153 Million Stolen Driver's Licence Scans Quiz

5 questions