The FBI confirmed to TIME it is 'looking into' a possible breach that may have exposed more than 153 million driver's license scans across the U.S. and Canada, first reported by independent journalist Brian Krebs.
A now-offline dark web service called 'Nexus' advertised digital scans of IDs belonging to more than 170 million people in North America, according to Krebs. The listing reportedly included more than 153 million driver's licenses, over 10 million identification cards, more than three million travel or international documents, and hundreds of thousands of medical cards. Defense Secretary Pete Hegseth's ID was reportedly among the sample data.
Krebs said he confirmed nine of the leaked documents; TIME has not independently verified the service's claims. Nexus claimed it obtained the records through a live breach at a 'major identity verification company' and had been 'exfiltrating new data for over a year.'
A spokesperson for IDScan.net, a New Orleans-based identity verification provider that works with marijuana dispensaries, retail, transportation, and finance businesses, told Krebs the company is investigating.
James E. Lee of the Identity Theft Resource Center said that if confirmed, this would be one of the largest single leaks of driver's license data on record — and that 'breaches of this size are now all too common.' Edgar Whitley, a Professor of Information Systems at LSE, told TIME a breach involving actual ID images carries 'significantly worse' risk than one involving names or ID numbers alone, since a high-quality scan makes it far easier for a criminal to impersonate the license holder or open new credit lines.
This isn't an isolated incident. Texas Parks and Wildlife disclosed in June that a third-party vendor breach may have exposed license, passport, and phone data for more than 3 million customers. Louisiana's Office of Motor Vehicles lost roughly 6 million records in a 2023 MOVEit breach claimed by the extortion group Clop. And National Public Data confirmed in 2024 that hackers accessed records including Social Security numbers for millions.
Here's the playbook for founders. If your product touches age verification, KYC, or onboarding compliance — retail, fintech, cannabis, travel, gig platforms — you are almost certainly leaning on a third-party ID scanner. That vendor's breach becomes your breach, in your customers' eyes and potentially in your legal exposure.
The math is simple: every ID scan or biometric file you retain past the moment you need it is a liability sitting on someone else's server, not an asset. Founders who get this right treat identity data like inventory with a shelf life — verify, then delete or tokenize, don't hoard. Before you renew your next verification contract, ask the vendor exactly how long they retain raw scans and where. If they can't answer clearly, that's your answer too.



