Skip to content

Security1 publisher3 min readPublished

Nexus sold access to 153 million genuine US and Canadian driver's licences

Krebs On Security watched the database grow by nearly 400,000 records in one day, matching Nexus's own claim of more than a year of continuous exfiltration from an identity verification company.

The Watch · Security desk

What happened

  • Krebs On Security revealed a newly launched dark web service called Nexus selling access to identity documents, among them 153 million driver's licences belonging to US and Canadian citizens.
  • In a cybercrime forum post, Nexus said it had access to a major identity verification company and had spent more than a year continuously exfiltrating fresh data into a private database.
  • Krebs found licences belonging to Secretary of War Pete Hegseth, an assistant director at the FBI and other senior US government officials sitting in the same collection.
  • Circumstantial evidence led Krebs to identity verification service IDScan, which has since confirmed it is investigating a data breach while the FBI looks into the incident.
  • Nexus vanished from the dark web soon after the story published, without its operators claiming to have deleted the database they had built.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Companies that outsourced identity proofing now carry an exposure that sits outside their own systems: the vendor's retained copy of the documents, not the customer's database, is what reached the market.
  • capability A licence number works as a join key, so a buyer can attach a name, address and photo to health, travel and credit records already taken in earlier campaigns.
  • constraint There is no remediation step here comparable to a password reset, and a site going dark does not shrink a dataset its operators still hold.
  • contradiction IDScan confirms a breach investigation, but the tie between IDScan and the Nexus dataset rests on circumstantial evidence, so nobody can yet tell which businesses' customers are in the file.

The growth rate carries the story. Krebs On Security saw the database add nearly 400,000 licences in a single day [3]. Divide 153 million by 400,000 and you get about 383 days [18]. Nexus told a cybercrime forum it had been exfiltrating continuously for more than a year [2]. The observed daily rate and the claimed duration reproduce the observed total, which points at a feed that stayed open rather than one theft resold later. A single day of counting is a single day of counting, but it is the kind of number a live pipeline produces and a static dump does not.

What the corpus defeats is narrower than the totals suggest. IDScan's own site describes the service as confirming that an ID is authentic and presented by its legitimate owner, and detecting fraudulent documents [7]. Krebs verified that the licences in the Nexus database were real, including his own and those of nine friends and family members [4]. Genuine licence records supply the document half of that check to whoever buys them. Whether the selfie and liveness half also leaked is not in the record [19]. Document proofing gets cheaper to fool here; calling it finished outright would need evidence nobody has published.

The intelligence case rests on linkage. Tom Uren's argument is that licence numbers are keys in other databases, and that records get far more valuable when they resolve to a named person with a home address and a photo [11]. The precedent is the mid-2010s Chinese collection run across Anthem, Equifax, Marriott, United Airlines and the Office of Personnel Management [12], which the US intelligence community is certain was used to counter American intelligence efforts against China [13]. The method is public as well: Bellingcat used a hacked database in 2022 to identify a deep cover GRU officer trying to infiltrate a NATO command post in Naples [14], and its 2018 reporting named the suspects in the Novichok attack on Sergei Skripal [15]. By 2020 it said it had acquired dozens of leaked databases to cross-reference new material against [16]. Nothing in the material shows this dataset reaching a foreign service. The argument is about a documented collection pattern, not a confirmed acquisition.

The takedown changes little. Nexus disappeared from the dark web shortly after publication, and the operators never claimed to have deleted anything [9]. Uren puts the US portion at roughly 63 percent of the country's total licences [10] and notes that identity verification companies get breached frequently [17]. The FBI is looking into this one, and IDScan has confirmed it is investigating a data breach [8]. For the businesses that bought document checks as a service, the live question is retention: which vendor holds copies of scanned identity documents, and for how long after the check returns a pass.

What to watch

  • Whether IDScan's investigation confirms it as the source of the Nexus dataset, and what notification volumes follow by state.
  • Whether Nexus reappears under a new name, or the 153 million records surface as a bulk resale or free dump.
  • Whether the FBI inquiry produces charges or a named actor behind the year-long exfiltration.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories