Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
FBI Investigates Dark Web Sale of 153 Million Stolen Driver's Licenses, Including Defense Secretary Hegseth's

Since Krebs's September 1 report, the FBI has opened a formal inquiry and the leak site has vanished
Since independent cybersecurity journalist Brian Krebs published his findings on Monday, September 1, the FBI's New Orleans field office has opened a formal investigation, and the dark web marketplace at the center of it has disappeared entirely.
The site, called Nexus, advertised itself on the Russian cybercrime forum Exploit as holding identity documents belonging to more than 170 million people in North America, according to Krebs. That included a claimed 153 million driver's licenses, more than 10 million identification cards, over 3 million travel documents or international IDs, and roughly 579,000 medical cards, per Krebs on Security.
Krebs said he only noticed the listing because the seller offered his own Virginia driver's license as a free sample. He then checked roughly a dozen friends and relatives against the database. Nine of them turned up, and each record's timestamp lined up with a real trip or transaction those people had actually made, Krebs reported.
The Hertz and Planet 13 connection
Krebs traced a pattern. He and his mother had rented a car from Hertz, and their license scans showed up in Nexus with timestamps seconds apart. Security researcher Zach Edwards, whose license also appeared in the database, said the timestamp on his record matched a trip to Las Vegas where he had his ID scanned at the marijuana dispensary Planet 13.
Both Hertz and Planet 13 are customers of IDScan.net, a New Orleans-based identity verification company that says it performs more than 21 million verifications a month across 20,000-plus locations, including more than 1,900 marijuana dispensaries, according to Krebs's reporting. Planet 13 had publicly announced its verification partnership with IDScan.net back in 2022.
A spokesperson for IDScan.net, Jillian Kossman, told Krebs the company was investigating but declined to share further details, saying his updates had been "welcome, and helpful to our team's investigation." Neither IDScan.net nor the FBI has publicly confirmed that IDScan.net was the actual source of the leak.
Names in the database
The FBI confirmed to multiple outlets, including TIME and Reuters, that it is looking into the incident but would not comment further "due to the ongoing nature of the investigation." Fox News national security correspondent Jennifer Griffin reported on the investigation's national security implications on Special Report, airing September 4.
Among the records Krebs found was the driver's license of Defense Secretary Pete Hegseth, along with what the Epoch Times described as the license information of an FBI assistant director. Krebs and other outlets reported additional unnamed high-ranking government officials also had records in the database.
Zach Edwards, a threat researcher, told KIRO 7 that "there's never been a breach of driver's licenses at this scale," adding that the exposure of high-profile officials' documents "created legitimate national security risks." James E. Lee, president of the Identity Theft Resource Center, which has tracked breaches since 2005, told TIME the leak could rank among the most extensive single exposures of driver's license data ever recorded.
The bigger question: why so much ID data exists to steal in the first place
A fair concern raised in TIME's coverage is that the breach exposes a broader problem. Businesses and government-adjacent services increasingly require customers to hand over scanned copies of government IDs for age or identity verification, and that data often sits in third-party databases indefinitely. Critics of mandatory ID-scanning requirements, whether for dispensaries, alcohol sales, or age-restricted online content, argue that every scan creates a fresh honeypot for hackers, and that consumers rarely know where their data ends up once it leaves the counter.
That concern is legitimate. IDScan.net's client list alone reportedly spans retail, transportation, and cannabis businesses, meaning a single company's server could be the point of failure for identity documents scanned at thousands of unrelated locations nationwide. Nexus itself claimed it had been "continuously exfiltrating new data for over a year into our private database," a claim neither Krebs nor the FBI has independently verified but one that, if true, means the exposure was silent for months before anyone noticed.
The Nexus site displayed the message "This service is no longer available" shortly after Krebs's report went public, according to Krebs on Security and KIRO 7. But Krebs told TIME that going dark doesn't mean the data is gone. "This data set will continue to have massive value to the cybercriminal community for many years, and we are likely to see this service or one very similar appear again on the darknet," he said.
No charges have been filed and no suspects have been named. IDScan.net has not confirmed or denied being the breach's source, and the FBI has given no timeline for its investigation. The Federal Trade Commission is advising anyone who suspects their license was exposed to freeze or monitor their credit, contact their local DMV, and report suspected fraud directly to the FTC.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.