In one of the most severe supply-chain data breaches in history, a cybercrime entity operating under the moniker Nexus launched a dark web marketplace selling high-resolution digital scans of identity documents belonging to more than 170 million individuals across North America. Among the stolen assets are over 153 million state and provincial driver’s licenses, millions of government identification cards, international travel documents, and specialized state-issued credentials, including medical marijuana dispensary cards.
An investigation into the breach reveals that the stolen data originates from idscan.net, a Louisiana-based identity verification vendor whose hardware and software systems process more than 21 million ID verifications monthly for enterprise clients worldwide. The breach, which hackers claim involved continuous data exfiltration for over a year, exposed sensitive physical scans—including infrared and ultraviolet security images—of everyday citizens as well as high-ranking federal figures, including U.S. Defense Secretary Pete Hegseth and an Assistant Director of the Federal Bureau of Investigation (FBI).
Following the public exposure of the repository, the New Orleans Field Office of the FBI opened a formal investigation alongside the agency’s Cyber Division. Shortly after law enforcement involvement and media inquiry, the Nexus service abruptly went offline, replacing its catalog with a brief message indicating it was no longer operational. Nevertheless, the compromise of multi-spectral identity records presents unprecedented long-term identity theft, physical security, and national security risks.
Detailed Chronology of Discovery and Investigation
[Late August 2025] ----> [Aug 31: Exploit Post] ----> [Early Sept: Trace to IDScan] ----> [FBI Call & Takedown] ----> [Sept 8: Formal Disclosure]
Nexus exfiltrates Nexus advertises 170M+ Scans matched to Hertz, FBI opens inquiry; Nexus IDScan.net issues public breach
data silently for records on dark web; free Planet13, and multi-spectral dark web market goes notice offering credit
over 12 months. sample triggers inquiry. IR/UV hardware signatures. offline. monitoring.
The Initial Dark Web Listing
On Monday, August 31, a newly registered user on the prominent Russian-language cybercrime forum Exploit posted an advertisement launching Nexus, a specialized identity theft marketplace. The proprietor claimed to host a vast catalog of identity scans covering more than 170 million residents across the United States and Canada.
To demonstrate authenticity, the seller posted a free sample in the opening thread containing six distinct image files belonging to cybersecurity investigative journalist Brian Krebs. The files included front and back color photographs, infrared (IR) scans, and ultraviolet (UV) validation images of his Virginia driver’s license. Crucially, each file contained embedded filenames with GMT timestamps pointing to a precise date in June 2025.
Tracing the Physical Footprint
To pinpoint the breach’s origin, security researchers cross-referenced the timestamps on their own compromised records with real-world activity logs:
Travel and Car Rentals: Krebs verified that the timestamp on his leaked Virginia license coincided exactly with a domestic flight trip where he rented a car from Hertz. Crucially, he had used a U.S. passport at the Transportation Security Administration (TSA) airport security checkpoint because he lacked a Real ID at the time, leaving the Hertz rental counter as the sole location where his physical driver’s license was handled and scanned.
Concurrent Family Records: Scans of Krebs’ mother were located within the Nexus database bearing timestamps identical to his down to the second—matching the moment both presented their driver’s licenses to the same Hertz counter representative.
Third-Party Research Validation:Larry Baldwin, principal intelligence researcher at cybersecurity firm Cybera, identified his own front-and-back license scans on Nexus, matching the precise time he picked up a Hertz rental vehicle during a personal vacation.
Commercial Dispensary Activity: Security researcher Zach Edwards (founder of DecryptAds) found his driver’s license listing in Nexus tagged with a timestamp from a mid-August trip to Las Vegas for the DEFCON security conference. Edwards confirmed he had scanned his license at Planet13, a massive multi-state cannabis dispensary.
Uncovering the Vendor: IDScan.net
The common denominator across these disparate physical interactions was identity verification technology powered by idscan.net.
In 2022, Planet13 announced an exclusive national identity verification partnership with idscan.net to handle age and identity checks across its locations. Furthermore, idscan.net publicly lists major corporate enterprises—including Hertz, Target, FedEx, Motorola Solutions, and financial service providers like Jack Henry—as deployments for its ID scanning hardware and software suite.
The inclusion of specialized infrared (IR) and ultraviolet (UV) file types within the leaked Nexus database provided conclusive technical proof. Standard mobile apps or basic optical character recognition (OCR) scanners capture only visible light; idscan.net’s high-end physical verification terminals specifically capture IR and UV spectrums to detect physical counterfeit modifications.
+-----------------------------------------------------------------------------------+
| Physical Access Point (Hertz, Dispensary, etc.) |
+-----------------------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------------------+
| IDScan.net Terminal (Visible Light + Infrared + Ultraviolet) |
+-----------------------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------------------+
| Exfiltration Channel (Unnoticed Backdoor Active for >12 Months) |
+-----------------------------------------------------------------------------------+
|
v
+-----------------------------------------------------------------------------------+
| Nexus Cybercrime Repository (153M+ Driver Licenses Exposed) |
+-----------------------------------------------------------------------------------+
Federal Law Enforcement Intervention
During the investigation, researchers discovered that the Nexus database contained sensitive government identities, including the driver’s license of U.S. Defense Secretary Pete Hegseth and a senior Assistant Director of the FBI.
Upon learning that executive federal officials and law enforcement leadership were actively listed for purchase, senior leaders from the FBI’s Cyber Division convened a conference call with security analysts. During the briefing, federal authorities confirmed that the FBI New Orleans Field Office had launched a formal criminal inquiry into idscan.net and the Nexus infrastructure.
Shortly after the FBI’s involvement became known and initial news reports circulated, the Nexus dark web portal vanished. The login screen was wiped and replaced with a single line of text: "This service is no longer available."
Supporting Context, Data Metrics, and Technical Analysis
Database Volume and Breakdown
The size of the Nexus repository makes it one of the largest specialized identity theft caches ever offered publicly on dark web forums. Rather than consisting of simple text databases containing stolen names and Social Security numbers, Nexus offered high-resolution, multi-spectral raw image files.
Document Category
Total Records Claimed
Key Geographical Highlights
Driver’s Licenses
153,000,000+
Bulk U.S. distribution; 1.1M+ Canadian records (473,673 in Ontario alone).
State/Provincial IDs
10,000,000+
Non-driver state identification cards across multiple jurisdictions.
Travel & International IDs
3,000,000+
Passports, international ID cards, and cross-border travel credentials.
Medical & Dispensary Cards
579,000+
State-issued medical cards and registered marijuana dispensary credentials.
An automated search query executed on the Nexus portal showed approximately 11.5 million pages of results, displaying 15 entries per page, confirming the seller’s claim of holding over 170 million records.
Nexus Database Composition (Total: ~170 Million Records)
[===================================================] Driver's Licenses (153M+) - 88.2%
[===] State Identification Cards (10M+) - 5.8%
[=] Travel & International Documents (3M+) - 1.7%
[-] Medical & Dispensary Cards (579k+) - 0.3%
Continuous Exfiltration Rate
The threat actors behind Nexus revealed that they maintained persistent access to idscan.net’s data pipelines for more than a year. This claim was supported by real-time tracking of the portal’s total inventory:
Over a single 24-hour observation window, the total driver’s license count displayed on Nexus grew by nearly 400,000 records.
Freshly scanned identity documents were captured, processed, and added to the dark web repository in near real-time, indicating an active, unpatched breach at the infrastructure level.
The Anatomy of a Scanned Record
For each identity entry, Nexus provided potential buyers with up to six distinct image files, including:
Front Image (Visible Light): High-definition color scan showing face photo, legal name, date of birth, address, and license numbers.
Back Image (Visible Light): High-definition scan showing PDF417 barcodes, magnetic stripes, and state restrictions.
Infrared Front Scan (IR): Used by identity verification systems to confirm embedded anti-counterfeiting ink patterns invisible to the naked eye.
Infrared Back Scan (IR): Validates structural back-side security features under infrared light.
Ultraviolet Front Scan (UV): Captures state-specific fluorescent watermarks visible only under UV wavelength radiation.
Ultraviolet Back Scan (UV): Confirms secondary background safety threads and reactive seals.
Initially, idscan.net refrained from offering specific technical detail regarding the vector of exfiltration. Jillian Kossman, a marketing and operations executive at the company, stated in an early correspondence:
"At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation."
Following internal investigations and pressure from law enforcement, idscan.net published an official security advisory on September 8:
"IDscan.net has determined that an unauthorized third party may have accessed and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers. IDscan.net is directly notifying affected individuals and providing complimentary credit protection services."
Corporate Client Pushback: Caesars Entertainment
While idscan.net highlighted major enterprise clients on its marketing materials, at least one major corporation contested its association with the breached vendor. A spokesperson for Caesars Entertainment issued a statement clarifying their relationship:
"Caesars Entertainment has not been a client of IDScan.net and has not used its VeriScan platform since February 2025. Caesars had no active VeriScan accounts at the time of this incident, did not authorize IDScan.net to retain data from historical accounts, and has been assured by IDScan.net that this breach has no impact on Caesars operations."
Other enterprise clients listed on idscan.net’s trust platform—including Hertz, Target, FedEx, Motorola Solutions, and Jack Henry—did not immediately comment on whether their historical customer verification databases had been fully purged or compromised.
Future Outlook, Systemic Privacy Risks, and Regulatory Fallout
1. Structural Failure of Multi-Spectral Identity Verification
Historically, financial institutions, age-restricted businesses, and identity platforms viewed physical driver’s license scans—especially those containing infrared and ultraviolet signatures—as a gold standard for remote verification. Fraudsters previously struggled to manufacture fake IDs that matched IR and UV properties.
With 153 million legitimate multi-spectral records now exposed, bad actors can bypass automated fraud verification tools. Criminals can pair stolen high-resolution IR/UV scans with advanced 3D printing and laser-engraving technologies to manufacture physical counterfeit licenses that pass automated multi-spectral verification terminals at banks, car rental desks, and border crossings.
The idscan.net breach underscores growing risks associated with statutory age-verification laws. Across numerous U.S. states and international jurisdictions, new legislation requires digital platforms, commercial venues, and online services to verify user ages by collecting government-issued IDs.
Privacy researcher Zach Edwards noted that these requirements concentrate massive amounts of sensitive data into third-party vendors that lack enterprise-grade security oversight:
"This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for driver’s licenses under the guise of protecting kids. These mandates force sensitive personal data into the hands of third-party vendors without sufficient security oversight to keep citizens safe."
3. Severe Physical and National Security Threats
The breach extends beyond identity theft and financial fraud into physical safety and national security risks:
Exposing Protected Identities: Cybera researcher Larry Baldwin pointed out that raw facial photographs paired with real-world names expose individuals who rely on anonymity for personal safety. This includes victims of domestic violence fleeing abusers and individuals placed within the Federal Witness Protection Program (WITSEC). Modern facial recognition engines can index the millions of clean headshots in the Nexus leak, rendering traditional identity protection measures obsolete.
National Security Exposure: The presence of driver’s licenses belonging to defense officials, federal law enforcement agents, military personnel holding Common Access Cards (CAC), and commercial drivers (CDL) provides foreign intelligence assets with actionable data for targeted spear-phishing, blackmail, and physical surveillance.
Policy and Regulatory Trajectory
In the wake of the Nexus breach, state regulators and federal agencies are expected to re-evaluate identity data retention policies. Key legislative and industry adjustments under consideration include:
Mandatory Zero-Data Retention: Prohibiting third-party verification vendors from storing raw IR, UV, or visual image files once an identity check is completed.
Standardized Vendor Audits: Requiring identity verification providers processing over one million monthly transactions to undergo third-party cybersecurity audits.
Hardware-Level Encryption: Implementing end-to-end hardware encryption on physical ID scanners to prevent local caching and continuous cloud exfiltration.
As identity verification systems become increasingly integrated into daily life, the Nexus market leak serves as a stark reminder that centralized stores of sensitive identity credentials remain primary targets for global cybercrime syndicates.