"A license contains the owner's date of birth, address, physical descriptors, and a government-issued ID number. This is enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable,” said Seemant Sehgal, founder and CEO of BreachLock.
The Nexus service on the Exploit forum and the claimed haul
Investigative reporting published by Brian Krebs says a service called "Nexus" offered access to digital scans of identity documents to users of the Exploit Russian cybercrime forum. Operators of Nexus reportedly claimed the trove contained more than 153 million driver’s licenses — mainly for American and Canadian drivers — alongside ID cards, travel documents, medical cards and other records. They also reportedly said the data came from an active breach at "a major identity verification company."
How Brian Krebs traced activity to IDScan.net
Krebs published the initial reporting and, according to his account, tracked activity from his own and other identified victims' movements to make a link between the Nexus data and IDScan.net, a New Orleans-based identity verification provider. The Nexus service went dark shortly after Krebs published his post, and the firm named in the reporting said it is investigating the matter.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildFBI involvement and IDScan.net's response
The FBI is reportedly investigating a potentially large breach of identity data that may have swept up details for as many as 170 million North Americans. IDScan.net — the New Orleans-based identity verification provider Krebs linked to the Nexus data — said it is currently investigating the matter, according to the reporting. The nexus of claims, tracking and an active federal probe leaves key operational questions pending with law enforcement and the company’s internal review.
Expert warnings from Seemant Sehgal and Denis Calderone
Two security experts quoted in the reporting described both the lasting harms of this type of exposure and the systemic gaps it reveals. Sehgal emphasized the permanence of the risk: the fields on a driver's license — date of birth, address, physical descriptors and a government-issued ID number — cannot be changed in the way a password or a payment card number can, and they are often treated as reliable for identity checks.
Denis Calderone, CTO at Suzu Labs, urged businesses that contract with identity verification vendors to scrutinize retention practices and contractual data-minimization obligations. Calderone noted there is currently no infrastructure analogous to a credit freeze that allows someone to flag a compromised driver's license number. He added that organizations collecting and centralizing government-issued identity documents should apply at least the same security posture as they would to payment card data, if not a higher standard.
What this means for identity verification vendors, financial institutions, and consumers
- Identity verification vendors: will likely face questions about how long scans are retained, what contractual limits exist on storage and reuse, and whether customers can audit handling of scanned government-issued documents.
- Financial institutions and government agencies that rely on scanned ID documents: may need to reassess which checks they treat as reliable, since Sehgal highlighted how the data contained in a license can be sufficient to pass many current verification processes.
- Consumers whose information may be in the dataset: confront a long-term exposure because key identity fields cannot be changed; Calderone pointed to the absence of a practical mechanism to "freeze" or otherwise flag a compromised driver's license number.
The public facts in this report leave open several concrete avenues for follow-up: the FBI's eventual findings, IDScan.net's internal investigation results, and whether the Nexus claims about the scope and source of the data can be independently verified. Until those pieces are resolved, the episode underscores two simple but consequential points drawn from the experts quoted here — that scanned government IDs are both high-value and long-lived, and that current processes and contractual practices may not adequately protect or limit their exposure.
Original reporting: https://www.infosecurity-magazine.com/news/fbi-probes-breach-153-million/




