Skip to content

This article features deals sourced directly by Gizmodo and produced independently of the editorial team. We may earn a commission when you buy through links on the site.

Deals

153 Million Americans Are About to Find Out Their Driver’s License Is on the Dark Web

A dark web platform called Nexus surfaced on September 1, offering searchable access to more than 153 million scanned US and Canadian driver's licenses, and the FBI opened an investigation the same day.
By

Reading time 6 minutes

What makes this incident different from every other data leak sitting in your inbox is the type of data involved. Passwords can be reset. Credit card numbers can be reissued. A driver’s license photo, complete with your name, date of birth, home address, and license number, cannot be changed. Once it’s on a criminal marketplace, it stays useful to fraudsters for the rest of your life. And there are, according to the criminals behind the service, 152,999,999 other people in exactly the same position as you.

How a Dark Web Service Ended Up With 153 Million Driver’s Licenses

The story was broken by investigative journalist Brian Krebs on the KrebsOnSecurity blog. A source alerted Krebs on August 31 to a new listing on the Russian cybercrime forum Exploit, in which a user claimed to be selling searchable access to identity documents belonging to more than 170 million people across North America. The service, called Nexus, allowed buyers to look up individual records by name and other identifiers. Krebs was tipped off when the vendor used Krebs’s own Virginia driver’s license as a free preview.

Krebs traced the source of the data to IDScan.net, a New Orleans-based identity verification company. IDScan processes more than 21 million verifications per month at over 20,000 locations globally, and its client list spans car rentals, hotels, retailers, financial services firms, and marijuana dispensaries. When contacted, the company acknowledged an internal investigation and did not confirm or deny a breach. On the same day, after Krebs shared his findings with law enforcement, the FBI’s New Orleans field office opened an official inquiry. Nexus went dark shortly after the story published, though the underlying data is almost certainly still circulating on other criminal marketplaces.

Why You Cannot Reset a Driver’s License Like a Password

The average consumer has been through enough breach notifications by now to have developed a routine: change the password, freeze the credit, roll on with life. That routine doesn’t work here. A password is a piece of arbitrary text you chose and can replace in thirty seconds. A driver’s license is a government-issued document that ties your face, address, date of birth, and unique identifier together in a single artifact. You cannot change any of those fields on demand. When the license expires, you’ll get a new number in some states, but your face, your name, and your history stay exactly the same.

That permanence is what makes the Nexus listing genuinely dangerous. Every person in the dataset now carries a lifelong exposure. Identity verification systems used by banks, government agencies, cell carriers, and hundreds of consumer platforms still treat a driver’s license photo as a reliable trust signal. If your license photo is now sitting in a searchable criminal database, it can be fed into every one of those verification flows, potentially for decades. The security researcher Seemant Sehgal, CEO of BreachLock, put it plainly in his comments to Infosecurity Magazine: none of the fields on your license can be changed, so every person in this dataset will carry the exposure with them for life.

The Six Files Behind Every Leaked License

The Nexus dataset was reportedly not just basic photos. Each license entry included six separate image files: standard front and back scans, plus infrared and ultraviolet versions of the same document. Those infrared and UV images matter because they reveal the security features that governments embed in modern licenses precisely to prove authenticity, which means the leaked records are close to what a fraudster would need to build convincing fake IDs or to defeat scanners that check for hologram and watermark authenticity.

Beyond driver’s licenses, the platform reportedly held over 10 million ID cards, 3 million travel documents and international IDs, and roughly 579,000 medical cards, including marijuana dispensary cards. Some records were flagged with the notation “CAC,” which if confirmed would refer to Common Access Cards, the government-issued credentials that unlock federal buildings and secure facilities. According to Krebs, the licenses of at least one senior US government official appeared in the database. The seller of Nexus claimed on the Exploit forum that they had been exfiltrating fresh data from the source for more than a year before offering the searchable service publicly.

What to Do Before the Data Starts Circulating

The hard truth is that there’s no perfect fix for a leaked identity document. But the practical steps you can take substantially reduce the day-to-day risk of that leak turning into actual fraud. Start with a credit freeze at all three US bureaus (Equifax, Experian, and TransUnion), because a freeze actually prevents new accounts from being opened in your name, unlike credit monitoring which only tells you after the fact. If you’ve ever handed a scanned ID to a car rental, hotel chain, retailer, or dispensary that used IDScan.net, treat your name and address as burned for phishing purposes: expect targeted “identity theft protection signup” and “verify your record” emails within the coming weeks.

Beyond that, ongoing surveillance of criminal marketplaces is genuinely useful here, and that’s where NordVPN‘s Dark Web Monitor becomes practically relevant. The feature, included in the Advanced and Ultra plans, continuously scans dumped databases and cybercrime forums for your personal information, then alerts you the moment your email address, identifiers, or credentials appear in a new listing. For a breach like this one, where the underlying data will likely surface on other marketplaces after Nexus itself was shut down, that continuous scanning matters more than a one-time credit report check.

Monitor your identity with NordVPN

Where NordVPN Fits, and What It Cannot Fix

Let’s be direct about the limits. NordVPN could not have prevented IDScan.net from being breached. Your license was in that vendor’s cloud infrastructure long before you had any control over it, and no network-layer tool would have changed that outcome. What NordVPN does, and what makes it worth considering in the aftermath of this specific type of leak, is reduce the ongoing damage. The Dark Web Monitor covers the surveillance side, and the Threat Protection Pro feature covers the follow-up phishing wave.

Threat Protection Pro blocks known phishing domains, malicious redirectors, and scam sites at the network level, which is directly relevant because the criminal buyers of Nexus data will use it to run targeted phishing campaigns. Fake “IDScan.net verification” emails, fake “FBI investigation update” notifications, and fake “identity theft protection signup” pages are all near-certain to appear over the coming weeks. NordVPN’s tracker and phishing filter catches a meaningful share of these before they load in your browser, which is a genuinely useful layer on top of your inbox’s own filtering. Combined with the audited no-logs policy that NordVPN’s core VPN service operates under, it’s one of the reasons the provider consistently ranks near the top of most best VPN comparisons focused on privacy-first architecture rather than just speed benchmarks.

Get NordVPN with Threat Protection

NordVPN Basic at $3.49 per Month

NordVPN’s Basic plan is currently available at $3.49/month, which works out to $94.23 billed once for 27 months of service (24 + 3 free). That’s a 69% discount off the standard rate. Annual renewal continues at $139.08/year, cancelable from the account dashboard at any time.

The Basic plan covers the core VPN across up to 10 devices with applications for Windows, macOS, Linux, iOS, Android, browser extensions, and router installation for whole-household coverage. The two features most directly relevant to the fallout from a breach like this one, Dark Web Monitor and Threat Protection Pro, sit in the Advanced and Ultra tiers rather than in Basic. If ongoing identity surveillance is the main reason you’re signing up after reading this article, the higher tiers are the ones that actually deliver on the promise.

Get NordVPN Basic at $3.49/month

30-Day Money-Back Guarantee

NordVPN backs every plan with a 30-day money-back guarantee. If the service doesn’t fit the way you use your devices, you can request a full refund within the first month. Refunds are processed through 24/7 chat support, and funds typically return within 5 to 10 business days depending on the payment method used.

That gives you a full month to install the apps across your setup, test the speeds on your home connection, run the phishing filter and dark web monitor against the wave of scam messages that will follow the IDScan story, and see whether the service holds up before the refund window closes. A note on the subscription: the $3.49/month rate applies to the first 27 months. Auto-renewal kicks in at the standard annual rate after that. If you’d rather cancel or renegotiate before renewal, set a reminder in your calendar 7 to 10 days before the renewal date.

Start a 30-day risk-free trial

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.