Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
153 Million Driver's Licenses Leaked on Dark Web After Suspected Breach at ID Verification Firm IDScan.net

A dark web marketplace called Nexus surfaced this week selling digital scans of more than 153 million driver's licenses from people in the United States and Canada, according to cybersecurity journalist Brian Krebs of KrebsOnSecurity.
The listings also included more than 10 million identification cards, roughly 3 million travel documents, and about 579,000 medical cards, some tied to marijuana dispensaries. Tom's Hardware, citing the same Nexus listing at a later snapshot, broke the numbers down further: 1.9 million travel documents, 1.3 million international driver's licenses, 429,000 Common Access Cards, 91,000 residence cards, 77,000 employment authorization records, and 5 million other documents. The slightly different totals across outlets aren't a contradiction. The seller told buyers the database was growing by nearly 400,000 records every 24 hours, so any two snapshots taken hours apart will show different numbers.
Krebs learned about the leak because someone tipped him off that his own Virginia driver's license was being used as a free sample to advertise Nexus on a Russian cybercrime forum called Exploit. He confirmed the data was real by contacting other people whose records showed up in the database, including friends and family who gave consent to search for their names.
Among the records Krebs found: a scan of Defense Secretary Pete Hegseth's driver's license. Protect.computer additionally reported that Nexus claimed to hold a record for an assistant director of the FBI, though that specific claim has not been independently corroborated elsewhere.
The Trail Leads to Louisiana
Krebs and other researchers traced the likely source to IDScan.net, a Louisiana-based identity verification company. According to protect.computer, IDScan.net's technology is installed at more than 20,000 locations worldwide and processes over 21 million verifications a month for clients including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment, plus more than 1,000 marijuana dispensaries across 19 states.
The connection wasn't a guess. Security researcher Zach Edwards told Krebs his own information appeared in Nexus, and the timestamp on his leaked ID matched the exact time he used it at a Planet13 marijuana dispensary, not at an airport. Other victims' timestamps lined up with Hertz rental counter visits. Both Planet13 and Hertz outsource ID authentication to IDScan.net, which is what pointed researchers to the company rather than to the retailers themselves.
IDScan.net has not issued a public statement confirming a breach. Jillian Kossman, a marketing and operations leader at the company, told Krebs: "At this point I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation."
The FBI's New Orleans field office opened a formal investigation into the matter on September 1, 2026, according to protect.computer and Krebs. No charges have been filed and no suspect has been named. The Nexus login page has since gone dark, with the site announcing the platform is no longer available, according to Engadget, though the stolen data itself hasn't vanished just because the storefront closed.
Privacy and ID-Based Age Verification
The leak lands in the middle of an ongoing policy argument over ID-based age verification. A growing number of states require users to upload a government ID or submit to face scans before accessing certain websites, dispensaries, or age-restricted purchases, a requirement many parents and lawmakers support as a straightforward way to keep minors away from pornography, tobacco, and other age-gated products.
Malwarebytes argues that argument runs into a hard problem: every company that collects a scanned ID becomes a new target. "Once someone uploads an ID, the service or its vendor can potentially link the visit to their identity," the outlet wrote, noting that a breached ID, unlike a password, can't simply be reset. The Nexus dump, with front-and-back scans plus infrared and ultraviolet images meant for anti-counterfeiting checks, shows what's actually at stake when that trust fails: a license number, date of birth, and home address can't be changed the way a compromised login can.
That tension isn't unique to IDScan.net. Discord disclosed a breach through a third-party vendor last year that exposed more than 70,000 government IDs, according to Engadget. The IDScan.net case is bigger by orders of magnitude, and the record count was still climbing when Krebs last checked, meaning whoever had access to the source system may not have lost it yet. Anyone who has rented from Hertz, shopped at a dispensary using ID verification, or done business with an IDScan.net client in the past year has reason to check their credit reports for new accounts opened in their name.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.