TL;DR: A dark web service called Nexus advertised searchable access to more than 153 million driver's license scans from the US and Canada, plus state IDs, travel documents, and medical cards. The inventory was first flagged by independent journalist Brian Krebs, whose own Virginia driver's license appeared as a free sample. The FBI confirmed to TIME that it is looking into the incident. Krebs traced the trove to IDScan.net, a New Orleans identity verification vendor that scans IDs at Hertz, Target, FedEx, marijuana dispensaries, and casinos, among others. Four proposed class actions have been filed in Louisiana federal court. IDScan has not publicly confirmed a breach [1][2].

What the Dark Web Listing Showed

A new user appeared on the Russian-language cybercrime forum Exploit on August 31, 2026, advertising a service called Nexus, Safestate reported. The seller claimed searchable access to identity records for more than 170 million people across North America, with more than 153 million of those entries described as driver's licenses. The advertised inventory also included more than 10 million state identification cards, more than 3 million travel documents, and 579,000 medical cards [2].

The operators claimed the records came from a live intrusion at a major identity verification company and said new data had been added for more than a year [1]. Independent journalist Brian Krebs was alerted to the site, and his own Virginia driver's license was offered as a free sample. He went on to confirm nine of the leaked documents [1].

Nexus went offline several days after Krebs's reporting. No independent party has confirmed the operators' numbers, and the 153 million figure came from the sellers themselves. Anyone who purchased or copied the database may still possess it [2].

Why Krebs Pointed to IDScan

Krebs reportedly searched for people who had consented to identity checks and received matching documents. A blank search returned approximately 11.5 million pages of results, and that body of evidence pointed to IDScan.net as the likely source [2]. IDScan is a New Orleans identity verification company whose systems are used at car rental counters, casinos, gun shops, and cannabis dispensaries across the United States. The company performs more than 21 million verifications per month across more than 20,000 locations, according to Safestate [2].

Affected document images reportedly came from ID scans performed at businesses including Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and Jack Henry. Consumers affected may not have had a direct relationship with IDScan at all. They were scanned when they handed over an ID at a counter [2].

IDScan's spokesperson told Krebs the company was investigating. TIME reached out to IDScan for comment and reported no response at publication [1]. As of the September 7 Safestate report, IDScan had not publicly confirmed a data breach, named the systems involved, or set up a public notification portal [2].

What the Records Contain

Each license entry reportedly contained six image files: a standard front scan, a standard back scan, an infrared image, and an ultraviolet image. Infrared and ultraviolet captures are used to verify security patterns on licenses, and the report warns that stolen IR and UV reference material could help counterfeiters defeat the same checks [2]. The records also include names, addresses, license numbers, and dates of birth [2].

License images do not expire when a breach ends. A driver's license stays valid until its printed expiration date, so a license scanned today can be weaponized for years [2]. Krebs told TIME: "This data set will continue to have massive value to the cybercriminal community for many years, and we are likely to see this service or one very similar appear again on the darknet" [1].

The contrast with payment cards is structural. PCI DSS bars payment processors from storing raw card numbers after a transaction. There is no comparable federal retention standard for identity verification vendors, and the result is a handful of companies sitting on archives of government-issued identity documents [2].

The FBI, the Lawsuits, and the Defense Secretary

The FBI confirmed to TIME that the bureau is "looking into the incident" and declined further comment "due to the ongoing nature of the investigation" [1]. Safestate, citing court filings, reports the FBI's New Orleans field office opened an investigation on September 1, 2026 [2].

At least four proposed class actions have been filed in Louisiana federal court, and two law firms have opened public investigations seeking additional claimants. Possible multidistrict litigation has been raised [2]. Louisiana's notice periods for affected residents run 60 days from discovery and 10 days to the state attorney general after consumer notices [2].

TIME also reports that the data set includes the personal information of Defense Secretary Pete Hegseth [1]. The Security of a serving Cabinet secretary's identity documents in a private vendor's archive is its own story, and the FBI's interest in that single record is one reasonable explanation for why the bureau moved quickly.

What It Means for You

Most people whose licenses are in this set will never have heard of IDScan.net. They handed an ID to a clerk at a rental counter, a dispensary, or a casino, and a third-party vendor they never chose kept the scans. That is the model the article describes, and it is the same model the Flock federal data sharing class action has put under scrutiny on the ALPR side. A service that quietly gathers identifying documents from many unrelated businesses becomes a single target that, once breached, exposes every business's customers at once.

James E. Lee, president of the Identity Theft Resource Center, told TIME that there is no way to opt out short of refusing to be scanned at any business that uses the vendor. Krebs put it directly: "There is no way to 'protect' yourself from someone else using a digital scan of your license if the company collecting the scans is relieved of them by hackers, apart from choosing not to have your ID scanned by anything or anyone" [1].

Lee suggested making the data less useful after the fact. Monitor bank, credit, and online accounts, place fraud alerts, and consider a credit freeze at Equifax, Experian, and TransUnion [1]. Do not click links in unsolicited breach notifications. Treat any reference to the breach that arrives by email or phone as a potential phishing attempt, and verify status with the business where you handed over the ID, not with whoever claims to be notifying you [3]. And remember: a stolen dark web copy of a document cannot be recalled. Once a scan is out, the protective move is to make the rest of your identity harder to use, not to chase the image back.

What to Watch

IDScan's breach statement. As of the most recent reporting, the company had not confirmed the breach publicly. Whether it does, what systems it names, and whether it sets up a notification portal will determine how quickly affected people can verify status [2].

The class actions. Four Louisiana filings and the prospect of multidistrict consolidation are the early procedural milestones. A motion to dismiss is the likely next inflection point [2].

Retention standards for ID scans. The article's argument is structural: there is no federal retention rule for identity scans comparable to PCI DSS for payment cards. Watch for any congressional or state-level response that forces vendors to delete scans after verification, the same way credit card processors must [2].

Sources

  1. TIME, Miranda Jeyaretnam - FBI Probes Report of Breach Exposing 153 Million Driver's License Scans (September 3, 2026). https://time.com/article/2026/09/03/fbi-probes-reported-dark-web-drivers-license-breach/
  2. Safestate - IDScan Faces Lawsuits Over Alleged 153 Million ID Data Breach (September 7, 2026). https://www.safestate.com/post/idscan-faces-lawsuits-over-alleged-153-million-id-data-breach
  3. NCC Group - News reaction: Reports of 153 million driver's licence scans linked to IDScan.net (September 2026). https://www.nccgroup.com/newsroom/news-reaction-reports-of-153-million-drivers-licence-scans-linked-to-idscannet/