A dark web identity theft service called Nexus has allegedly exposed more than 153 million American and Canadian drivers' licenses, prompting a federal investigation into what cybersecurity experts describe as one of the largest breaches of government-issued identification documents ever reported.
The FBI confirmed Wednesday that it is investigating the incident. "The FBI is aware of this report and is looking into the incident," the bureau said in a statement, declining to provide additional details because of the ongoing nature of the investigation.
Independent cybersecurity journalist Brian Krebs discovered the trove after Nexus was advertised on a Russian cybercrime forum. The service claimed to possess more than 170 million identity documents, including 153 million drivers' licenses, 10 million identification cards, more than three million travel documents, and hundreds of thousands of medical cards.
Among those whose records appeared in the database was Secretary of War Pete Hegseth, according to Krebs's investigation. The database reportedly contained detailed images of identification documents rather than merely names or license numbers, including photographs, addresses, dates of birth, document numbers, and other identifying information.
Krebs said he was initially alerted when Nexus offered his own Virginia driver's license as a free sample. He subsequently located the licenses of numerous other individuals and verified that several records corresponded to real-world instances in which those people had presented their identification.
What the Left Is Saying
Democratic lawmakers have called for greater oversight of identity verification companies and stronger data protection standards following the breach announcement.
Senator Dick Durbin of Illinois, chair of the Senate Judiciary Committee, said the scale of the alleged breach demands immediate Congressional attention. "If confirmed, this would represent an unprecedented exposure of Americans' personal identification data," Durbin said in a statement. "We need to understand how these companies are collecting and storing such sensitive information and what safeguards exist."
Consumer advocacy groups aligned with progressive causes have long warned about the risks of commercial identity verification systems. The Electronic Frontier Foundation, which has criticized the expansion of facial recognition and ID scanning technology, said the incident illustrates the dangers of allowing private companies to amass vast databases of identification documents.
"This breach shows why we need federal data minimization laws," said Adam Schwartz, senior attorney at EFF. "Companies should not be permitted to retain copies of everyone's driver's license indefinitely."
What the Right Is Saying
Conservative Republicans have emphasized the importance of cybersecurity infrastructure and private-sector cooperation with law enforcement in responding to such breaches.
Senator Josh Hawley of Missouri, who has championed data security legislation, said the breach highlights the need for mandatory reporting requirements. "Companies sitting on massive databases of personal information must face real consequences for failing to protect that data," Hawley said. "This is exactly why I've pushed for stronger breach notification laws."
Industry groups have cautioned against premature conclusions about the source of the breach before the FBI investigation concludes.
The Identity Verification Industry Association, a trade group representing companies like IDScan.net, issued a statement saying it takes security concerns seriously while emphasizing that identity verification services play a critical role in preventing fraud. The group noted that its members process millions of legitimate verifications daily to prevent underage access to regulated products and combat identity theft.
What the Numbers Show
The scope of the alleged breach is substantial by any measure, according to available data.
The Nexus service claimed to possess more than 153 million drivers' licenses from American and Canadian residents. For context, there are approximately 240 million licensed drivers in the United States alone, meaning the database could contain records for a majority of American drivers if accurate.
IDScan.net, which has been identified as a possible source of the compromised data, says its technology processes more than 21 million identity verifications each month at over 20,000 locations. The company's listed customers and partners have included major corporations such as Hertz, Target, and FedEx, according to information on its website.
When Krebs first examined Nexus, the service claimed approximately 153 million drivers' licenses. Within roughly 24 hours, that number grew by nearly 400,000 records, suggesting new stolen data was being added continuously rather than being a static historical dump.
The 153 million figure represents claims made by Nexus operators and has not been independently verified by the FBI or any other government agency.
The Bottom Line
The FBI investigation is ongoing, and several key questions remain unanswered. It has not yet been confirmed how many individuals were actually affected, whether all records originated from a single source, or what specific security failures allowed the alleged breach to occur.
IDScan.net told Krebs it was investigating but has not provided public explanation of whether its systems were compromised or how many people may have been affected. The database disappeared from the dark web shortly after Krebs published his investigation, replaced with a message stating the service was no longer available.
The incident is likely to intensify debate over federal data protection standards for identity verification companies. Currently, data breach notification requirements and security standards vary by state, and there is no comprehensive federal law specifically regulating how these companies must handle identification documents they collect in the course of business.
What to watch: Congressional hearings on the breach, potential legislative proposals for federal data minimization standards, and any announcements from IDScan.net regarding the scope of compromise to its systems.