A newly launched identity theft service claims to be selling more than 153 million driver’s license scans belonging primarily to people in the United States and Canada, with evidence pointing toward a possible breach involving identity verification provider IDScan.net.
The collection allegedly includes more than 153 million driver’s licenses, 10 million other identification cards, more than 3 million travel documents or international IDs, and at least 579,000 medical cards.
The FBI’s New Orleans field office has opened an investigation into an apparent breach involving IDScan.net, according to reporting by KrebsOnSecurity. IDScan.net said it was investigating but had not publicly confirmed unauthorized access or the scope of any potential compromise at time of publication.
Identity scans appear linked to IDScan.net customers
The dark web service, operating under the Nexus name, appeared online at the end of August and claimed access to identity documents covering more than 170 million people across North America.
KrebsOnSecurity investigated the dataset by examining records belonging to multiple people and comparing timestamps attached to their ID scans with real-world activity.
Several individuals reportedly found that timestamps associated with their driver’s license images corresponded with occasions when they had provided their IDs during car rentals, travel, hotel visits or age-verification checks.
In multiple cases, those circumstances overlapped with organizations or industries using IDScan.net technology.
IDScan.net provides identity verification, document authentication, age verification and ID scanning services. Its website says the platform is used across automotive, hospitality, retail, finance, gaming, logistics and other industries and lists major companies among organizations using its technology.
Records reportedly include high-resolution ID scans
The alleged dataset is significantly more sensitive than a conventional breach containing names, emails and passwords.
Some records reportedly contain front-and-back images of driver’s licenses along with infrared and ultraviolet scans used to authenticate physical identity documents. Associated records may also include timestamps and other information generated during verification.
That combination could give criminals material useful for identity theft, account recovery fraud, social engineering and attempts to defeat identity verification systems that rely on images of government-issued documents.
Unlike passwords, much of the information printed on a driver’s license cannot simply be changed after a breach. Names, dates of birth, photographs, addresses and license details may remain valuable to attackers for years.
153 million figure appears plausible but remains unconfirmed
The operator claims to possess more than 153 million driver’s license records, but neither IDScan.net nor law enforcement has publicly verified that number.
KrebsOnSecurity reported that a blank search of the service returned approximately 11.5 million pages with roughly 15 records per page, suggesting that the claimed scale may be plausible.
Approximately 1.1 million results reportedly involved Canadian driver’s licenses, with the majority of the collection appearing to involve people in the United States.
The number of driver’s license records visible through the service also reportedly increased by nearly 400,000 within approximately 24 hours.
The operators claimed they had been continuously collecting new data for more than a year, raising the possibility that any underlying compromise may have been active for an extended period. That claim has not been independently verified.
Car rentals and dispensaries among possible collection points
KrebsOnSecurity’s investigation found several cases where timestamps associated with driver’s license images lined up with car rentals.
Other records appeared connected to identity checks performed at marijuana dispensaries and other businesses where customers are routinely asked to present government-issued identification.
IDScan.net says its systems perform more than 21 million identity verifications each month across more than 20,000 locations worldwide.
The company offers systems capable of scanning the front and back of identification documents and performing infrared and ultraviolet analysis, capabilities consistent with some of the images reportedly found in the alleged stolen dataset.
Those similarities provide evidence pointing toward IDScan.net infrastructure, but they do not establish how the data was obtained or whether every record originated from the company’s systems.
FBI opens investigation as IDScan.net examines incident
KrebsOnSecurity reported that the FBI’s New Orleans field office opened an official investigation on Sept. 1 into an apparent breach involving IDScan.net.
IDScan.net told Krebs that it was investigating the matter but had not reached conclusions about the source or scope of the alleged exposure.
The company had not issued a detailed public incident statement confirming a breach at time of publication.
Shortly after the initial report was published, the Nexus service reportedly became unavailable and displayed a message stating that the service was no longer operating.

Its disappearance does not eliminate the risk posed by the records. If the dataset was copied or sold before the service went offline, the identity documents could continue circulating privately or reappear elsewhere.
Long-term identity theft risk
The potential exposure is particularly serious because government-issued identification is routinely used as a trust anchor for opening financial accounts, recovering accounts, passing Know Your Customer checks and proving identity.
High-quality front-and-back scans combined with security-feature imagery could make fraudulent identity submissions more convincing, particularly against services that rely heavily on document uploads.
The incident also highlights the concentration risk created by identity verification providers. A single vendor may process identification documents collected by thousands of businesses across unrelated industries, creating a centralized repository of highly durable personal information.
Until IDScan.net completes its investigation, the source, full scale and duration of the apparent compromise remain unconfirmed.










