“The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards,” wrote independent journalist Brian Krebs after finding a listing on a Russian cybercrime forum.
Nexus listing and the scope of the exposure
Krebs reported that a service on a Russian cybercrime forum — referred to in the listing as Nexus — returned roughly 11.5 million pages of results when searched with no parameters, at roughly 15 results per page. The listing included documents from both Canada and the United States, with approximately 1.1 million Canadian driver’s licenses identified and the single largest Canadian concentration from Ontario (473,673 records). The listing’s claimed totals and the search results suggest the offering contains more than 153 million driver’s licenses overall, plus the additional identification cards, travel documents and medical cards Krebs described.
The FBI has launched an official probe
The report says the FBI has opened an official investigation into the source of the scans. The published listing and the scale of the material prompted immediate attention from law enforcement while security leaders and vendors weighed in on likely causes and consequences.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildIDScan documentation, data retention defaults, and concentration risk
Industry commentary in the report raised two connected problems: concentration of identity data among a small number of providers, and retention settings that preserve full image scans. Donald McFarlane pointed to IDScan’s documentation, saying the product defaults to “Collect all” and that some customers have no option to delete collected records; he described a Basic plan that “appears to require collecting everything and provides no option to delete it.” Denis Calderone warned that many large customers outsource identity checks to the same vendors — naming Hertz, Target, Caesars, FedEx and “over a thousand marijuana dispensaries” — increasing the impact of a single breach. Calderone added that the records reportedly include front, back, infrared, and ultraviolet scans, and that the database “grew by 400,000” while data “appears to be a live pipeline” that may have been exfiltrating for more than a year.
Security leaders’ technical and operational concerns
Several security executives framed the incident as a systemic failure of verification practices, retention policy and privileged access controls. Seemant Sehgal noted that a driver’s license contains immutable attributes — date of birth, address, physical descriptors and a government-issued ID number — and observed that “none of those fields can be changed,” meaning exposure is effectively lifelong. Kevin Surace argued the pattern looks like persistent authorized access — “If an attacker gets in as an employee, administrator, contractor or service account, database encryption does not save you because the system treats them as authorized.” He recommended fingerprint-based biometric assured identity on dedicated hardware and urged rethinking how much identity data organizations retain.
Eli Ben nun warned of timing risks as organizations enter the September hiring surge and the holiday season, saying “the more authentic information attackers have, the harder it is to distinguish a legitimate request from a bad actor.” John Strand urged stronger protections and accountability for large data aggregators, suggesting some collections of personal data should receive protections similar to those for protected health information.
What this means for technologists, procurement leaders, and consumers
- For technologists and security teams: look for evidence of long-term exfiltration and persistent access, validate retention and deletion controls, and reassess privileged access for service and admin accounts — concerns raised directly by Kevin Surace and Denis Calderone.
- For procurement and enterprise leaders: demand contractual data-minimization obligations, audit rights and short retention windows; Donald McFarlane warned executives who “choose to hoard data they do not need should expect to answer for the consequences.”
- For consumers and the public: recognize that compromised driver’s-license images and scans are difficult to remediate — Denis Calderone noted that replacing a compromised license involves DMV processes and paperwork and that “You can’t get a new face.”
The Nexus listing, the FBI probe, and the security leaders’ responses converge on a narrow set of decisions: whether vendors and their customers will limit what they collect and retain; whether enterprises will insist on audit and deletion rights; and whether regulators will treat large identity repositories with stronger, HIPAA-like controls as John Strand suggested. One clear, policy-facing question the record leaves is who will be held accountable for business choices that created such a large, centralized target — and whether those choices will change before the next breach.




