Why the Nexus driver’s-license trove may be more consequential than an ordinary megabreach—and why replacing every American ID would not solve it

By Jonathan Brown | September 4, 2026


The most important fact about the extraordinary driver’s-license story published this week by Brian Krebs is not the number 153 million. That number remains a claim made by criminals, and it may count documents or scanning events rather than 153 million unique people. The important fact is the type of material that Krebs found.

This was apparently not another spreadsheet of names, dates of birth, addresses and identification numbers. The new dark-web service called Nexus displayed searchable images of real identity documents: fronts, backs, portraits, barcodes and, in at least some records, infrared and ultraviolet captures made by specialized document-authentication hardware. Krebs found six image files attached to his own license—three front-and-back pairs comprising ordinary, infrared and ultraviolet views. The timestamps matched the day in June 2025 when he and his mother handed their licenses to a Hertz rental-car representative. Her images were timestamped seconds away from his.

That distinction is enormous. A conventional personal-data breach gives an attacker facts about a person. A high-resolution document breach can give the attacker the artifact that businesses have increasingly been trained to accept as proof of those facts.

It is too early to declare that 153 million Americans have lost their usable identities, that every leaked image can defeat a modern verification service, or that IDScan.net has been conclusively established as the breached party. It is not too early to say that the evidence described by Krebs is unusually strong, that the FBI has publicly confirmed it is investigating the report, and that the incident exposes a structural defect in North America’s identity system. We have spent years responding to mass theft of static personal information by demanding photographs of static identity documents. Now a service built to authenticate those documents appears to have become a central reservoir from which the documents themselves could be stolen.

What is actually known

Nexus was advertised on August 31 by a new account on the Russian-language cybercrime forum Exploit. Its operator claimed access to identity records concerning more than 170 million people in North America, including more than 153 million driver’s licenses, more than 10 million other identification cards, more than three million travel or international identity documents, and at least 579,000 medical cards. Krebs was alerted because the seller used his Virginia driver’s license as a free sample.

Krebs did more than repeat the advertisement. A blank Nexus search returned roughly 11.5 million pages with about 15 entries per page, broadly consistent with the advertised license count. A search limited to Canadian licenses produced about 1.1 million results. During one 24-hour period, the displayed driver’s-license total increased by nearly 400,000. Nexus claimed it had been continuously exfiltrating new material for more than a year.

The decisive work was correlation. With permission, Krebs searched for documents belonging to more than a dozen relatives, friends and researchers. Nine people whose licenses appeared in Nexus connected the image timestamps to travel or commercial transactions on or near those dates. Krebs and his mother both presented licenses at Hertz. Cybersecurity researcher Larry Baldwin found an image timestamp matching a recent Hertz rental. Privacy researcher Zach Edwards found his license associated with his August trip to Las Vegas; he had not rented a car but had scanned his ID at Planet 13, a cannabis dispensary that had publicly announced an identity-verification relationship with IDScan.net.

IDScan.net, a New Orleans company, supplies scanning and identity-authentication systems across hospitality, rental, cannabis, retail, finance and other industries. Its own materials say it performs more than 21 million verifications each month at more than 20,000 locations. Its product pages describe devices that perform front-and-back comparison, ultraviolet and infrared image analysis, watermark and hologram checks—the same unusual classes of images seen in the Nexus records.

That is a compelling chain of circumstantial and technical evidence: known users of the same provider, matching transaction times, an image format matching the provider’s advertised hardware, enormous volume consistent with a centralized verification network, and apparent near-real-time acquisition. IDScan.net told Krebs it was investigating. A purported early notice sent to some customers said the company had initiated incident response, was securing potentially affected systems, preserving logs, coordinating with law enforcement and engaging outside counsel and forensic specialists. The company had not, as of September 4, publicly confirmed unauthorized access, the source of the Nexus corpus, the number of affected people, the relevant customers, the retention period or the attack path.

Reuters independently obtained a brief FBI statement on September 2. The bureau said it was “looking into the incident” but would not comment further because the investigation was ongoing. Reuters could not independently establish the source of the data and reported that IDScan.net did not answer its repeated inquiries. That leaves the correct attribution formula as apparently or likely sourced from systems in IDScan.net’s ecosystem—not a forensically confirmed IDScan.net breach.

The same restraint applies to the scale. Nexus’s number originated with Nexus. Pagination and spot checks make it difficult to dismiss, but “153 million driver’s licenses” may mean records, images, documents or scan events. Krebs’s own entry contained three pairs of images. Repeat rentals, repeated age checks, license renewals and multiple records for the same holder could substantially reduce the count of unique victims. Conversely, Nexus advertised other document classes not included in that headline figure. Until investigators deduplicate the corpus and identify what was actually reached, comparisons by victim count remain provisional.

Even with those caveats, this may be the largest known criminally searchable collection of government-issued identity-document images in North America. The United States had about 240 million licensed drivers in 2024, according to the Federal Highway Administration. If anything close to 153 million unique, current licenses were involved, the population exposure would be staggering. We simply do not yet know that denominator.

Yes, Nexus went dark. No, the danger did not.

The reported shutdown is real but easy to misunderstand. Krebs updated his article at 8:56 p.m. Eastern on September 1 to say that, shortly after publication, the Nexus login page disappeared and was replaced by the message, “This service is no longer available.” Reuters and other outlets subsequently reported the disappearance. On September 3, Krebs said in a comment that the site remained offline as far as he knew and that nobody he knew possessed a complete copy of the database.

That is good news in the narrowest sense. The most visible retail interface stopped serving searches, at least at its known address. It may mean the operator panicked, the host or administrator intervened, law enforcement applied pressure, the seller chose to relocate, or the entire launch was abandoned after attracting a level of attention no competent criminal wants. There is no public evidence yet establishing which explanation is correct.

It would be a serious mistake to interpret a dead storefront as deletion of the underlying material. Nexus claimed to have maintained its own private database for more than a year. If true, the operators could reopen under another name, sell the corpus privately, divide it among partners, use it themselves, or retain it as leverage in an extortion negotiation. Buyers may already have obtained individual files or batches. And even if Nexus was the only criminal copy—which cannot be assumed—the apparent access path must be contained before newly scanned documents are safe.

The storefront going dark therefore changes availability, not exposure. It may reduce impulsive, retail-level abuse today. It does not establish that the collection has been recovered, destroyed or rendered unusable.

Is this as big as Equifax?

In verified scope, not yet. In potential consequence, very possibly—and in one respect it represents the failure of the defense adopted after Equifax.

The 2017 Equifax breach exposed personal information belonging to 147 million people. The Federal Trade Commission later specified at least 147 million names and dates of birth, 145.5 million Social Security numbers, and 209,000 payment-card numbers and expiration dates. Equifax was foundational because it destroyed the premise that a person’s biographical history could function as a secret. Names, birth dates, former addresses, loan amounts and Social Security numbers could no longer reliably distinguish the legitimate person from a criminal holding a stolen dossier. The breach accelerated the decline of knowledge-based authentication—the familiar questions about previous streets, lenders and monthly payments.

Identity systems responded by moving toward documentary and biometric proofing. Upload the driver’s license. Photograph its reverse. Extract and validate the barcode. Take a selfie. Compare the living face with the portrait. Look for signs that the card template and security features are genuine. The 2025 edition of the National Institute of Standards and Technology’s digital-identity guidance treats a physical driver’s license or state ID as “strong” evidence when its physical security features are inspected and the portrait is compared with the applicant or an issuing source.

Nexus appears to attack the raw material of that replacement process. A criminal no longer has only the victim’s correct answers. The criminal may have a professionally captured image of the evidence used to vouch for those answers.

That does not make the two incidents identical. Equifax included Social Security numbers on an almost population-wide scale, and those numbers drive credit, taxation, employment and benefits fraud. The Nexus material described publicly does not necessarily include Social Security numbers. Equifax’s affected-person count and breach source were confirmed; Nexus’s are not. A license image also is not automatically sufficient to open a bank account, enter a federal building or pass a well-designed remote proofing flow.

But the document corpus has qualities that a credit-bureau database did not. It contains a trusted portrait, signature, physical description, license number, issue and expiration dates, machine-readable data, current or historical address, and visual evidence of a genuine card. It may disclose the exact image that a verification provider will use in a face comparison. It can be paired with Social Security numbers, telephone numbers, credit histories and leaked credentials already circulating from other breaches. Criminal data is cumulative. The license does not have to contain every necessary element if it supplies the missing high-confidence element in an assembled identity package.

This is why “Equifax, but with pictures” is funny and inadequate. The radical feature is not merely greater detail. It is the collapse of separation between identity evidence and identity data.

What criminals can—and cannot—do with the scans

The immediate risk is not that every buyer can print a perfect REAL ID at home. Modern licenses contain tactile, optical and manufacturing features that an image file does not reproduce: substrate characteristics, laser engraving, variable imagery, microprinting, windows, raised elements and effects that change with angle or illumination. Infrared and ultraviolet captures are observations of a real card under different light, not the machinery, materials or secret production files required to duplicate it. They are not equivalent to cryptographic private keys.

Ars Technica suggested that the extra images could help counterfeiters make cloned cards capable of passing hologram tests. That is plausible as a concern, but it has not been demonstrated for this corpus. Infrared and ultraviolet references could teach a sophisticated forger how a specific authentic document behaves under a scanner and allow testing against the same class of controls. Yet a flat captured response may not recreate dynamic holographic or material effects, and some security patterns are already known to professional counterfeiters. We should not promote possibility into a proven universal bypass.

The lower-friction attacks are more immediate. Many remote workflows never handle the physical card. They accept an uploaded front image and reverse image, then parse the barcode, compare fields, consult databases, and sometimes request a selfie or short video. A genuine high-resolution scan can defeat the crudest “is this a plausible license image?” gate. It supplies perfectly consistent front-and-back biographical data. It can make a fraudulent application look less anomalous to a human reviewer. It can be edited into a synthetic document or placed on a screen for injection into a poorly protected capture process.

A selfie requirement raises the bar but does not end the attack. If the criminal resembles the victim, recruits a look-alike or uses the victim’s portrait to construct a presentation or injection attack, the legitimate document image becomes an important component. NIST’s current guidance explicitly addresses forged evidence, stolen evidence, biometric presentation attacks and the injection of falsified identity images or morphed media. Secure systems must determine not simply whether an image depicts a real card, but whether a live applicant controls authentic evidence and is the person to whom an authoritative issuing source assigned it.

The scans can also improve social engineering. A caller who knows the full license number, issue date, expiration date, address and physical descriptors—and can email or upload a convincing copy—may be better positioned to persuade a bank, carrier, payroll desk, cryptocurrency exchange, insurer or government help desk to reset an account. The exact result depends on each organization’s recovery process. A license is rarely the sole credential in a well-run system, but account recovery remains an uneven human process where documentary confidence can override other warnings.

New-account fraud is an obvious concern. Financial institutions’ customer-identification procedures often accept government-issued photo identification as documentary evidence, while stronger programs add database checks, device intelligence, fraud analytics and biometric or live interaction. A credit freeze can make it harder to open accounts that depend on a credit report, but it does not block every deposit account, prepaid product, cryptocurrency account, payment service, telecom account, rental, insurance claim or government interaction.

The corpus could support account takeover and SIM-swap attempts, freight and vehicle-rental fraud, unemployment or benefits fraud, fraudulent employment, money-mule recruitment and laundering accounts. These are risk paths, not confirmed consequences of Nexus. As of September 4, there is no verified public accounting tying a wave of completed fraud to this particular dataset.

Some effects are not financial. A license image can connect a face to a legal name, home address, birth date, height and signature. That is dangerous for domestic-violence survivors, stalking targets, undercover personnel, witnesses and public officials. Images attributed to senior government personnel reportedly appeared in Nexus, including Defense Secretary Pete Hegseth and an FBI assistant director. A Common Access Card image is not the same thing as a usable Common Access Card: actual federal logical access relies on certificates, possession, a PIN and revocation checking. But a detailed image may support impersonation, targeting, phishing or physical pretexting. The national-security concern is the combined targeting package, not a magical photograph that unlocks every secured door.

The medical and cannabis-related cards introduce a different injury: disclosure of sensitive associations. A record can reveal not merely identity but where and why a person was verified. Timestamp and customer context can place a person at a rental counter, dispensary, hotel, casino, health-related business or secured facility. The scanning network may therefore have produced a shadow travel and activity log even when location tracking was not the advertised purpose.

Must the government reissue everyone’s ID?

Almost certainly not everyone’s, and not immediately. More important, mass reissuance by itself would be an extraordinarily expensive partial remedy.

Driver’s licenses are issued by states and territories, not from one federal credential database. Before any rational reissuance decision, investigators would need to determine which documents were present, deduplicate them, identify issuing jurisdictions, distinguish current from expired cards, learn whether full license numbers and barcodes were exposed, and securely notify affected people and state agencies. A blanket recall based on Nexus’s advertised number would replace untold licenses that may never have been present while potentially missing holders of other compromised documents.

Suppose states did reissue every affected card. What changes? Potentially the card number, issue date, expiration date, barcode data and physical design. Those changes matter only when a relying party checks whether the presented credential is current and valid. If an online service merely inspects the stolen image and never queries an issuing authority, it may continue accepting an invalidated card. The victim’s name, birth date, face, signature and often address do not become secret again. And if states issue a duplicate with the same identifier—as replacement policies vary by jurisdiction—the security gain may be smaller still.

Reissuance is most useful when paired with revocation and real-time validation. A bank or identity provider should be able to learn that document number X was superseded and reject it. Physical cards were not designed as globally queryable, revocable digital authenticators, however, and the United States does not operate a universal consumer-facing validation service for every commercial verifier. The driver’s license is simultaneously permission to drive, a state record, an age credential and America’s de facto internal identity card, but its verification infrastructure remains fragmented.

The scale illustrates the practical problem. The United States has approximately 240 million licensed drivers. Even the seller’s unverified 153 million figure would represent records equal to nearly two-thirds of that population if every record were unique and American—which they are not. Producing cards, verifying applicants, mailing credentials, handling people without stable addresses, staffing motor-vehicle offices, resolving fraud disputes and updating thousands of dependent systems would be a national undertaking. California’s current driver’s-license fee is $45; that is not a national production-cost estimate, but it shows how quickly retail-scale replacement runs into billions of dollars before administrative costs and lost time.

So the user’s sardonic forecast is probably right: there is no visible political or administrative path to “reissue everybody.” But the deeper reason is not only that government will refuse to pay. It is that printing the same identity facts onto fresh plastic does not repair an identity architecture that accepts pictures of plastic as decisive evidence.

Targeted replacement could still become necessary for confirmed victims, especially where a state changes the license number and supports status validation. Government and regulated institutions may place risk flags on exposed document numbers. High-risk public officials, protected witnesses and victims facing active impersonation may require individualized remediation. Affected Common Access Cards or other cryptographic credentials can be revoked and reissued more meaningfully because their certificates support machine-verifiable status. Passports have separate reporting and invalidation procedures. The response should follow the credential and threat model, not one universal command to visit the DMV.

What would actually fix the problem

The first obligation is forensic containment and disclosure. The suspected provider and its customers need to establish the initial-access vector, whether access persists, which systems and tenants were reached, what was downloaded, how long the attacker remained, and whether client credentials or API keys were compromised. They should preserve evidence while terminating unauthorized sessions, rotating reachable secrets and validating that scanners are no longer feeding a hostile repository. Customers need enough information to identify their own affected transactions and notify people without forcing victims to guess where an invisible subcontractor processed their card.

The second obligation is data minimization. A business checking whether a customer is 21 ordinarily needs a yes-or-no age assertion, not a durable warehouse containing the person’s address, portrait, signature and multispectral card images. A rental firm may need to establish that a person is licensed and eligible to drive, but that does not automatically justify indefinite retention of every raw authentication image by a central vendor. IDScan.net’s March 2026 privacy policy says client data may include government-issued ID data, biometrics and precise location. It says processing and retention are governed by contracts with business clients and that information is retained as reasonably necessary for collection purposes, legal duties, dispute resolution, fraud prevention and contract enforcement. That language does not reveal a uniform deletion deadline for raw scans.

There are examples of a better rule. Federal Trade Commission guidance under the Children’s Online Privacy Protection Act permits parental verification using government ID only if the identification is promptly deleted after verification. The principle should not be confined to children’s services: collect the minimum claim, retain the minimum evidence, and impose a short, explicit deletion schedule unless a documented legal need requires otherwise. Fraud-model development does not justify keeping an indefinitely reusable identity artifact merely because storage is cheap.

The third obligation is to stop treating a document image as an authenticator. Identity proofing establishes who someone is; authentication establishes that the same person is returning. After enrollment, organizations should rely on phishing-resistant authenticators, device-bound credentials or carefully protected recovery methods—not repeated uploads of the same license. For new proofing, systems should validate document status with authoritative sources, detect media injection, require liveness or attended review where risk warrants it, rate-limit automated attempts, and correlate device and behavioral risk without turning surveillance into the default.

Cryptographically verifiable mobile driver’s licenses offer a more promising model when implemented correctly. Unlike a screenshot of plastic, a mobile credential can present signed data from the issuer, disclose only the attributes needed for a transaction, and support status checking. NIST classifies a properly implemented mobile driver’s license as superior evidence because its mobile security object can be validated and revocation checked when available. The caveats are substantial: wallets and issuer systems become high-value targets, privacy depends on unlinkability and selective disclosure, phones can be coerced or compromised, and no one should be forced into a centralized tracking system. But the security direction is correct: verify an issuer’s signed assertion rather than accumulate photocopies.

Finally, responsibility has to follow the data chain. The person at a rental counter often has no idea that a third-party platform receives the scan, what modes the hardware captures, whether the rental company or vendor retains it, which subcontractors can access it, or how deletion works. “Ask before allowing a scan” is sensible but inadequate when refusal means no car, no hotel, no job onboarding or no access to a legally age-restricted service. Procurement contracts should require tenant isolation, least-privilege access, immutable audit logs, bulk-export detection, strict retention, independent testing, rapid incident notice and a usable way to delete or revoke records. Regulators should demand that the collecting business remain accountable for its processor rather than sending victims through a maze of vendors.

What an individual can do now

There is no verified public Nexus lookup service. Anyone claiming to check the corpus should be treated skeptically, especially if the site asks for a license image, Social Security number, payment or account credentials. Krebs said the marketplace was offline and that no one known to him had the full database. A new “breach checker” could easily be a second collection trap.

People who had an ID scanned at a rental counter, dispensary, hotel, retail location or other IDScan.net-associated environment should preserve receipts and dates but should not assume exposure is confirmed. Watch for notices from the merchant, issuing state and verification provider. Ask the merchant in writing which identity processor handled the transaction, what was retained, and whether the transaction falls within the investigated period. Residents of states with applicable privacy laws may have access, correction or deletion rights, although exceptions, processor relationships and an active forensic hold may complicate requests.

A credit freeze at Equifax, Experian and TransUnion is the most valuable broad consumer step against new credit opened in one’s name; it is free and remains until lifted. A fraud alert can add verification friction. Review credit reports, bank and card activity, new-account mail, carrier notices and government correspondence. Secure email and mobile accounts with unique passwords and phishing-resistant multifactor authentication where available, because control of email or telephone recovery channels can turn a document dossier into an account takeover. Add a carrier account PIN or port lock if offered. Consider an Internal Revenue Service Identity Protection PIN for tax-return fraud.

Do not file false theft reports or reflexively replace a license solely because the seller advertised a huge number. If the issuing agency or a credible breach notice confirms that a license was exposed, contact the state motor-vehicle agency and ask specifically whether replacement changes the credential number and whether the old number will be flagged. If actual misuse appears, use IdentityTheft.gov to create a recovery plan, preserve evidence, dispute fraudulent accounts and make the appropriate police or agency reports.

None of these steps can retract a face, address or signature. They reduce the number of systems in which stolen evidence can be converted into money or control. The burden is unfairly transferred to potential victims precisely because the institutional response is incomplete.

The real emergency is the trust model

The final assessment, as of September 4, must remain conditional. Nexus advertised a historic corpus. Krebs convincingly authenticated a sample and developed strong evidence pointing toward a widely deployed identity-scanning ecosystem. The FBI confirmed an investigation. The marketplace disappeared after disclosure. IDScan.net has acknowledged investigating possible exposure but has not publicly confirmed the breach or scope. No authoritative deduplicated victim count, attack vector, affected-client list or downstream fraud total has been released.

Yet waiting for the final number should not delay the architectural conclusion. An identity-verification company is not merely another vendor holding customer information. It is a concentration point for the documents society uses to decide who may open an account, enter a building, rent a vehicle, obtain regulated goods, recover credentials and exercise legal privileges. Centralizing raw identity evidence creates a target more reusable than most password databases and potentially more operationally useful than another trove of static biographical data.

The United States will probably not reissue every driver’s license. It will offer monitoring, targeted replacements, investigations, lawsuits and perhaps years of notifications. Those measures may help individual victims, but they cannot restore secrecy to photographed evidence. The only durable response is to stop designing systems that require identity documents to remain secret after they have been shown.

The license in your wallet was built to be presented. Any security system that collapses when an accurate picture of it escapes has confused identification with authentication. Nexus did not create that error. It may simply have exposed it on a scale large enough that government and industry can no longer pretend not to see it.

Principal sources


Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.

Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.