
The cybersecurity journalist investigating this breach found his own driver’s license being used as a free sample to advertise it. That’s not a metaphor. Brian Krebs discovered the database because someone tipped him off that his ID was the bait criminals were using to attract buyers. It’s a detail that captures exactly how brazen this kind of operation has become.
According to Engadget, more than 153 million scans of US and Canadian driver’s licenses recently went on sale on the dark web through a service called Nexus. The documents didn’t stop at driver’s licenses either. Medical cards, employment records, and residence cards were all part of the package. Krebs verified the authenticity of the data by interacting directly with the criminals, who sent him a scan of his own license. Other victims confirmed the same. And among those victims, apparently, is Secretary of Defense Pete Hegseth, whose license scan was also shown to Krebs. That detail alone raises questions that go well beyond ordinary identity theft.
The FBI has opened an investigation, with the New Orleans field office taking the lead. Krebs has pointed to IDScan, a Louisiana-based ID verification company, as the likely source of the breach. The connection isn’t subtle. Many confirmed victims share one thing in common: they rented a car from Hertz, which uses IDScan to verify customer identities at the counter.
IDScan’s client list is worth paying attention to. It includes Target, FedEx, Motorola, and Jack Henry. Target contacted Engadget to say it was not involved in the breach because it doesn’t transmit guest data to IDScan. But the broader point stands. Every time you hand your ID to a business and they scan it into a third-party verification system, you’re trusting that vendor’s security practices. You have no visibility into those practices. You don’t get to opt out.
This is the part the ID verification industry doesn’t like to talk about. These companies sit on enormous, centralized collections of government-issued identity documents. They are exactly the kind of target that attracts serious criminal operations. And when they fail, the damage is measured in hundreds of millions of people’s most sensitive personal data.
Nexus has since shut down, and the login page now says the platform is unavailable. So the documents aren’t actively for sale at this moment. But they exist. They’re out there. A similar breach hit Discord users after its third-party verification provider was compromised, exposing more than 70,000 government IDs. That incident barely registered as a major story. This one is nearly 2,200 times larger. The scale should be shocking. The pattern, sadly, is not.