The FBI’s New Orleans field office has opened an inquiry into an apparent incident involving Louisiana identity-verification provider IDScan.net after a dark-web service called Nexus advertised searchable scans of more than 153 million U.S. and Canadian driver’s licenses. The advertised trove also included identification cards, travel documents and medical cards.
The development is serious precisely because the number is not yet a confirmed breach count. Nexus’s figures are claims made by an illicit service, not the result of a public forensic audit, and they do not establish how many unique people, current documents or valid records are involved. Still, the reporting that prompted the inquiry describes a collection with the sort of data that cannot be reset after an exposure: names, home addresses, birth dates, license numbers and photographs, including multiple image types used to inspect an ID.

What investigators and reporting have established
KrebsOnSecurity, which first detailed the Nexus offering, reported direct observations of the service and said the FBI’s New Orleans office had opened an official inquiry. Reuters-based follow-up reporting published by WSOC-TV separately reported that the FBI said it was looking into the incident.
Nexus advertised more than 153 million driver’s licenses, more than 10 million ID cards, more than 3 million travel or international-ID documents, and at least 579,000 medical cards. Those are separate marketplace categories. Adding them together may describe the service’s advertised inventory, but it would not demonstrate that more than 170 million individuals were affected. A person can appear in more than one category, records can be duplicated, and criminal-market listings can include stale or unusable material.
There is, however, one useful check on the scale of the listing that falls short of validating it. KrebsOnSecurity reported that a blank Nexus search produced roughly 11.5 million result pages, with about 15 results on each page. That observation made the advertised license total plausible as a count of listed results. It did not establish where the data came from, whether each result was distinct, or whether the documents were authentic.
The service reportedly became unavailable shortly after the report appeared, displaying a notice that it was no longer operating. Its disappearance removes a public window into the claims; it is not evidence that the material has been deleted, nor does it resolve how it was obtained.
The reported connection to IDScan.net
IDScan.net has not confirmed a breach. The company told KrebsOnSecurity it was investigating, without publicly confirming unauthorized access or describing the scope of any potential exposure. That limitation is important: an FBI inquiry and a vendor investigation are not findings that the company’s systems were compromised.
The reported link is based on several pieces of circumstantial technical and business evidence. KrebsOnSecurity found that timestamps associated with records matched transaction timing at businesses using IDScan.net, and that some listings carried front and back scans as well as infrared and ultraviolet images. The outlet also reported evidence connecting people whose documents appeared in Nexus to transactions at organizations tied to the provider. Those details point to IDScan.net as a likely source of the images, but do not prove the route by which data may have left a system.
That distinction leaves several possibilities open: a compromise at a provider, an issue in a connected customer environment, misuse of authorized access, or an incomplete understanding of the data’s provenance. Nexus operators claimed they had been collecting fresh data for more than a year from a major identity-verification company. That is an unverified assertion by the people marketing the service and should not be treated as an established timeline.
The case also illustrates why customer lists can mislead during incident reporting. KrebsOnSecurity reported that Caesars Entertainment appeared on an IDScan.net client list, but a Caesars spokesperson said the company had not been an IDScan.net client and had not used its VeriScan product since February 2025. A company’s inclusion on a present or former vendor list does not establish that its customers’ records are in a particular dataset.
Why document scans create a different exposure
A password leak is often disruptive but has a comparatively straightforward remedy: change the password, enable multifactor authentication and watch for account takeover. Government-ID scans are harder to retire. A replacement license may receive a new card number in some jurisdictions, but a person’s name, date of birth, address history and likeness remain useful ingredients for impersonation and social-engineering attempts.
The reported image formats add another concern. A basic photocopy exposes printed information. Front-and-back images can reveal barcode or machine-readable data and physical design details; infrared and ultraviolet captures may record features used by businesses to inspect whether an ID is genuine. The reporting does not establish that Nexus users could defeat any particular verification system, and it would be irresponsible to infer that from the images alone. But the material is more sensitive than a simple text list of license numbers because it can support more convincing identity claims.

Identity-verification vendors occupy an awkward but increasingly consequential position in the data economy. Bars, casinos, dispensaries, car-rental counters and other businesses may scan documents for age checks, fraud prevention or access control. The business receiving the card scan is visible to the consumer; the data-handling chain behind it often is not. A large incident involving that chain can expose information collected across many unrelated locations without showing that each location was separately breached.
Malwarebytes’ coverage and an Infosecurity Magazine report likewise describe the reported IDScan.net connection as under investigation, rather than confirmed. That is the appropriate state of the story: there is enough observed material to warrant law-enforcement and company scrutiny, but not enough public evidence to call 153 million people victims of a verified IDScan.net breach.
For consumers, the immediate practical fact is limited but consequential: an alleged marketplace inventory is not a notice that any individual document was exposed. The more durable issue for IDScan.net, its customers and regulators will be whether investigators can determine the collection’s origin, its age, its duplication rate and whether the advertised scan count corresponds to a real unauthorized disclosure.
