Illustrative image generated with AI
Nexus: 153 Million Driver’s Licenses on the Dark Web, Raising Suspicions of a Near–Real-Time Scanning Pipeline
Nexus sells 153M driver's licenses with IR/UV scans appearing hours after scanning, suggesting a live theft pipeline. FBI investigates IDScan.net link.
Text generated by artificial intelligence, published without human review. AI transparency
A driver’s license reportedly obtained by an employee of a car rental company appeared on the dark web just hours after it was scanned. The document was being sold on Nexus, a new underground service advertising more than 153 million driver’s licenses, often accompanied by high-resolution images and scans captured in the infrared and ultraviolet spectrums.
An investigation by KrebsOnSecurity, published Tuesday and reported on September 2, 2026, describes a rapidly expanding archive. In just 24 hours, the number of available licenses reportedly increased by nearly 400,000.
The timing has raised concerns about an ongoing data theft from a platform used to verify documents at car rental companies, dispensaries, and other businesses. The FBI is investigating, while IDScan.net, a company publicly linked to the data pipeline, has launched an internal review.
An Archive Built for Counterfeiting, Not Just Identity Theft
Nexus did not offer simple lists containing names, addresses, and driver’s license numbers. Each document appeared to include multiple files, including high-resolution images of both the front and back.
The observed material also included scans captured in the infrared and ultraviolet bands. This significantly increases the severity of the exposure: these scans can reveal security features that are not visible in an ordinary photograph, including elements used to verify holograms and the authenticity of the document substrate.
A criminal could therefore combine identifying information with complete images and data obtained in previous breaches. Current and former addresses, Social Security numbers, and demographic profiles could make fraudulent applications, account openings, or impersonation attempts more convincing.
The risk is not limited to online fraud. The availability of multispectral scans could facilitate the production of counterfeit documents designed to pass visual or automated checks.
Identities found in the archive included those of journalist Brian Krebs, his mother, an FBI deputy director, and several security researchers. It is not known how many distinct individuals were represented by the 153 million records, because a single document could be represented by multiple files.
New Scans Appeared on Nexus Within Hours
The most concerning aspect was the speed at which documents were published. In several cases, documents became available within a day of being presented to a business; in some instances, only a few hours passed.
This pattern is difficult to reconcile with the mere circulation of an old stolen archive that was later resold. Instead, it suggests ongoing—or at least very recent—access to data collected by a centralized scanning service.
The car rental company involved in the primary case has not been identified. It is therefore impossible to determine which location scanned the license, what local system was in use, or whether the document passed through infrastructure shared with other companies.
The method of compromise is also unknown. It could involve an account, an application interface, a cloud repository, an internal system, or an integration with a third party. At present, however, there is not enough technical evidence to attribute the leak to any specific component.
There are also no publicly available indicators of compromise, such as IP addresses, domains, hashes, or account names to search for in corporate logs. No vulnerable software versions have been disclosed, and no CVE identifier has been associated with the incident.
The Connection to IDScan.net and Its Relationships with Hertz and Planet13
Available information has linked the possible scanning pipeline to IDScan.net, a New Orleans-based company specializing in document capture and verification. The company says its technology can produce images in the infrared and ultraviolet spectrums—the same types observed on Nexus.
IDScan.net has also announced an exclusive agreement with Planet13, a dispensary chain operating in multiple states, and has identified Hertz and 11 other companies among its customers or users.
One of the cases examined involved a person who had visited a Planet13 location in Las Vegas. The interval between presentation of the document and its availability on Nexus was considered consistent with a connection between the scanning system and the underground marketplace.
These are clues, however, not a conclusive technical reconstruction. IDScan.net has not disclosed whether it confirmed unauthorized access to its systems, nor which infrastructure may have stored or transferred the images.
A company spokesperson said that an internal review is underway. Representatives of the car rental company involved had not provided an immediate response.
Not Just Driver’s Licenses: CACs and Residence Permits Also Listed
Nexus advertised a broader catalog of personal documents. In addition to U.S. and international driver’s licenses, the listings included identity cards, travel cards, health insurance cards, residence permits, and work authorizations.
The service also claimed to possess scans of cards issued by marijuana dispensaries. The data included labels such as “CDL,” probably referring to commercial driver’s licenses, and “CAC,” presumably referring to Common Access Cards.
CACs are government credentials that are also used to authorize physical access to public buildings and protected environments. Their possible presence in the archive therefore expands the potential impact beyond financial fraud to include security procedures and access-control systems.
It is not known whether the CAC images were accompanied by enough information for operational use, or whether any impersonation attempts have been recorded. Nevertheless, the exposure alone warrants review by the organizations responsible for issuing and managing the cards.
Nexus Is Offline, but What Happened to the Data Remains Unclear
Nexus became unreachable within hours of the investigation’s publication. It has not been clarified whether the service was seized, voluntarily shut down by its administrators, relocated, or made unavailable for another reason.
The disappearance of the portal does not mean that the archive was deleted. The operators may have retained copies, distributed the files to other criminals, or prepared to relaunch under a different name.
The service’s disappearance also creates a problem for victims: there is currently no public procedure for checking whether a specific license was included. No broad notifications, revocation measures, or coordinated program to replace exposed documents have been announced.
The FBI is conducting an investigation. The confirmed number of victims, the geographic scope of the collection, and when the theft began are all unknown.
What Affected Customers and Companies Can Do
Anyone who presented a driver’s license to a car rental company, dispensary, or another business equipped with a scanner cannot automatically conclude that they were affected. At the same time, the speed observed in these cases justifies taking certain precautions.
Potentially affected individuals can:
- retain receipts and communications that can help establish where and when the document was scanned;
- monitor credit reports, newly opened accounts, loan applications, and unusual changes to personal information;
- consider placing a security freeze on their credit file or using fraud-prevention tools available in their jurisdiction;
- contact the authority that issued the license to learn what procedures apply in the event of suspected exposure;
- promptly report any impersonation attempts or unauthorized use;
- notify the relevant security office if the document involved is a CAC or another government credential.
For companies, the priority is to review logs for integrations with scanning services, administrative access, bulk exports, and anomalous API calls. Organizations should also verify which images are retained, for how long, and under what permissions.
Replacing a driver’s license may reduce some risks, but it does not eliminate copies that have already been stolen or the associated personal data. Until the origin, duration, and scope of the access are clarified, the Nexus case should be treated as a potentially ongoing compromise—not simply a closed criminal archive.
Sources
This article is an original reworking based on the sources below.
