153 Million License Scans Went Up for Sale. Then Vanished.
Krebs on Security found a dark-web service selling scans of more than 153 million North American driver's licenses. The FBI opened an inquiry. The likely.

TL;DR
- —You do not "create an account" at a rental counter.
- —You hand over a license because the clerk needs to see it.
- —The sales thread on the Russian forum Exploit used Krebs's own Virginia license as a free sample.
You do not "create an account" at a rental counter. You hand over a license because the clerk needs to see it. A scanner beeps. You get keys. The scan is the product. On 1 September 2026, Brian Krebs reported that a new identity-theft service named Nexus was selling digital scans of more than 153 million driver's licenses from the United States and Canada, plus identification cards, travel documents, and medical cards. The sales thread on the Russian forum Exploit used Krebs's own Virginia license as a free sample. The FBI's New Orleans field office opened an inquiry. The New York Times reported on 4 September that the bureau is investigating the theft and sale of the scans. Shortly after Krebs published, Nexus went offline. What Nexus claimed Krebs reported these inventory claims from the service: More than 153 million US and Canadian driver's licenses
More than 10 million identification cards
More than 3 million travel documents and/or international IDs
At least 579,000 medical cards A blank search, Krebs wrote, returned about 11.5 million pages at roughly 15 results per page. A Canada-only search returned about 1.1 million licenses, with Ontario the largest concentration. Those numbers are Nexus's marketing plus Krebs's paging math. They are not a company disclosure. They are still much larger than a typical consumer breach sample, and Krebs authenticated records by matching licenses belonging to himself, relatives, and other people who could say when and where they had handed over the card. TechCrunch reported that samples included a license photo associated with US Defense Secretary Pete Hegseth. The Department of Defense told TechCrunch it was aware of the reports. Nexus also claimed it had persistent access to a major identity-verification company and that hundreds of thousands of documents were being added daily. If that claim is true, this is not a one-time export. It is a live tap. The likely pipe: ID scanning as a service Krebs, working with researcher Zach Edwards, identified IDScan.net, a Louisiana identity-verification company, as the likely source. Several people whose licenses appeared in Nexus had recently shown ID at Hertz or at a cannabis dispensary that IDScan lists as a client. Timestamps on some images lined up with those handovers. IDScan told Krebs it was investigating. As of the TechSpot and Galaxy Research follow-ups in early September, the company had not issued a detailed public statement confirming a breach. That is the whole genre of "identity verification": a retailer never wanted to keep your license image, so it outsourced the keeping. The vendor then has a dataset no customer can audit, delete, or even see. Why a license scan is worse than a leaked password A password can be rotated. A license scan is a government-issued face, number, address, and date of birth in one image. Infrared or UV captures, if present, make counterfeits easier. Combined with a rental or dispensary timestamp, the scan also says where you were. This is the KYC inversion. Age checks, car rentals, and "we need to see ID" rules create a centralized photocopy of the population because every desk is a collection point and one vendor stores the copies. If you rented a car, entered a dispensary, or otherwise let a clerk scan your license through a third-party device in the last couple of years, assume the image may be in circulation. That is not the same as proof that IDScan was breached. It is the only honest personal response while the company investigates. What to do Treat unexpected "your ID was flagged" messages as phishing. Real notices will not ask you to re-upload a license to a random portal.
Freeze credit if you are in the US or Canada and you regularly scan ID at retail. The breach check will not show a license image; it may still show related email dumps.
Use the delete-yourself guide for broker copies of your address and date of birth. Brokers will not have the scan; they will have the fields that make the scan useful.
If you run a shop that scans IDs: ask the vendor, in writing, whether images are stored, for how long, where, and whether they were in this incident. "We use a scanner" is not a data-processing agreement. The honest limit IDScan has not published a victim count. Nexus is gone. The FBI has not named a defendant. Anyone selling "we confirmed 153,347,439 records" as a company figure is laundering a marketplace claim. The confirmed facts are smaller and worse: license images of real people, including a journalist's, were for sale, and the collection point looks like ordinary ID checks. The photocopy was the product. The clerk was the upload button.