Generated by Codex with GPT 5.6 Sol XHigh

Techmeme surfaced KrebsOnSecurity’s September 1 investigation, “FBI Probes Service Selling 153M+ Drivers Licenses.” Its importance is not just the extraordinary headline number. The reporting reconstructs how identity scans collected during ordinary transactions may have flowed into a searchable criminal marketplace, turning a system designed to establish trust into infrastructure for impersonation.

The marketplace, called Nexus, appeared on the Russian-language cybercrime forum Exploit on August 31. Its operator claimed to offer more than 153 million US and Canadian driver’s-license records, alongside over 10 million other identity cards, more than three million travel or international identity documents, and at least 579,000 medical cards. A blank search returned about 11.5 million result pages with roughly 15 entries each, and the displayed license count grew by nearly 400,000 in one day. Those observations make the claimed scale plausible, but they do not establish that every listing is unique or authentic.

Following timestamps back to the scanner

The investigation began with unusually direct evidence: the seller used author Brian Krebs’s own Virginia driver’s license as a free sample. His Nexus record contained three pairs of front-and-back images—a normal scan plus infrared and ultraviolet versions—with timestamps matching a June 2025 trip. The additional light-spectrum images suggested that the files came from specialized verification equipment rather than a phone camera or a conventional document leak.

Krebs then asked more than a dozen friends and relatives for permission to search Nexus. Nine had records, and all nine associated the image timestamps with travel. Several matched car rentals. Krebs and his mother found scans timestamped seconds apart, corresponding to the moment they handed their licenses to the same Hertz representative. Another researcher, Zach Edwards, matched his record to a Las Vegas trip on which a Planet 13 dispensary had scanned his ID.

Those separate trails converged on IDScan.net, a Louisiana identity-verification provider. IDScan had announced an exclusive national verification agreement with Planet 13, listed Hertz and other large companies as customers, documented infrared and ultraviolet scanning, and said it processed more than 21 million verifications each month at over 20,000 locations. During Krebs’s reporting, IDScan said it was investigating but did not confirm a breach or answer detailed questions. The FBI’s New Orleans field office separately told Krebs it had opened an inquiry into an apparent breach involving the company.

This is strong attribution by correlation, not a completed forensic finding. The matching timestamps, customer relationships, scan formats, and vendor capabilities all point in the same direction. But the article does not establish which IDScan system was accessed, whether a customer or integration was the initial entry point, how many records are genuine, or whether the advertised collection contains repeated scans of the same people. The marketplace operator’s claim of continuous exfiltration for more than a year also remains a claim, although the rapidly rising record count is consistent with ongoing access.

Verification data becomes an impersonation kit

Identity checks are often presented as a short-lived exchange: a person proves who they are, the business approves the transaction, and the check is over. Nexus exposes the danger when the underlying evidence persists. A high-resolution front-and-back license scan can contain an address, date of birth, signature, portrait, document number, barcode, and machine-verifiable security details. Unlike a password, most of those attributes cannot be meaningfully rotated after a breach.

That makes the collection useful far beyond conventional identity theft. The same documents used to satisfy onboarding, age-check, rental, financial, or account-recovery procedures can be replayed against other organizations. Records attributed to government access cards, medical cards, dispensaries, and travel-related transactions also show how a single verification provider can aggregate people who never knowingly chose that provider or understood where their scans would be processed.

The concentration creates asymmetric risk. A business gains a quick verification decision, while the vendor accumulates a durable dataset whose compromise can affect people across unrelated services. Customers may remember showing an ID to a rental desk or venue, but they are unlikely to know the scanner’s operator, retention period, downstream processors, or breach-notification path. That opacity makes exposure difficult even to discover, much less remediate.

Nexus disappeared shortly after the story was published, replacing its login page with a shutdown message. That limits immediate access through one storefront, but it does not show that the source intrusion ended or that copies of the data were recovered. The engineering lesson is therefore broader than this marketplace: verification systems should minimize raw-image retention, isolate customer data, monitor bulk access, and preserve enough provenance to notify affected people. Collecting identity evidence may reduce fraud at the front door, but retaining it at massive scale can create a more valuable target behind the door.