Wed 09 Sep 2026 / 09:13 ET
Kernel
Security 3 min read

FBI investigates Nexus listings of 153 million driver’s license scans

The FBI is examining a dark-web service that advertised millions of ID scans, while the claimed breach source and record count remain unconfirmed.

Dana Voss

By Dana Voss / Security Correspondent

FBI investigates Nexus listings of 153 million driver’s license scans
img: Krebs on Security

The FBI is looking into Nexus, a dark-web service that advertised scans of more than 153 million U.S. and Canadian driver’s licenses, according to reporting cited by KIRO 7. For people searching fbi nexus drivers licenses, the important distinction is not subtle: the service and the federal inquiry were reported, but the claimed scale, the authenticity of every record, and the alleged breach source have not been independently confirmed.

Nexus was advertised by a new user on Exploit, a Russian cybercrime forum, after a tipster alerted KrebsOnSecurity on Aug. 31. The service offered searchable identity-document records for people in North America. Its operators claimed their inventory included more than 153 million driver’s licenses, more than 10 million other identification cards, more than 3 million travel or international-ID documents, and at least 579,000 medical cards.

Those are criminal-operator claims, not an audited tally. KrebsOnSecurity reported that a blank search in Nexus returned roughly 11.5 million pages, with about 15 results shown on each page. That works out to about 172.5 million result slots, but it cannot establish how many people or distinct documents were in the collection, whether entries were duplicates, or whether the listed document categories were accurate.

What is the FBI investigating in the Nexus driver’s license case?

According to KIRO 7’s report, which cited Reuters, the FBI said it was “looking into the incident” and declined further comment because the matter was ongoing. KrebsOnSecurity reported that the FBI’s New Orleans field office had opened an inquiry into the source of the images.

The available reporting does not establish who obtained the records or how. Nexus operators claimed they had been extracting data for more than a year from an active breach at a large identity-verification company. Later reporting identified Louisiana-based IDScan.net as a suspected source, but RH-ISAC said the company had not confirmed unauthorized access or the scope of any incident.

Why ID-scanning systems are under scrutiny

KrebsOnSecurity found that the service’s records could include multiple scans of an ID’s front and back, including visible-light, infrared and ultraviolet images, with timestamps attached to files. The reported driver’s-license total rose by nearly 400,000 over a 24-hour period, an observation consistent with continued uploads but not proof that a live breach was supplying them.

The reporting also found a pattern worth investigating, not a finished attribution. Nine people who consented to searches for their licenses told KrebsOnSecurity they had traveled or rented a vehicle around the timestamps associated with their scans. The reporter’s own scan and his mother’s were timestamped seconds apart after they handed their licenses to a Hertz representative together. That correlation points toward an ID-scanning workflow, but it does not prove which company, system, or party exposed the files.

Nexus reportedly went offline shortly after the first reporting, displaying a message that the service was no longer available, according to RH-ISAC and KIRO 7. Taking down a storefront does not answer the questions the investigation now has to answer: whether the underlying data was copied, where it came from, and how broadly it may circulate.

What can people do if a license may be exposed?

KIRO 7 cited Federal Trade Commission guidance advising people affected by a data breach to check, freeze or monitor their credit. People concerned specifically about a driver’s license can contact their state DMV, and should report related fraud or scams to the FTC.

This story draws on original reporting from Krebs on Security.

More Security/

view all ↗