Dark Web Marketplace Nexus Exposes Over 153 Million Scanned IDs, Including High-Profile Targets
A recent investigation by KrebsOnSecurity has uncovered a dark web marketplace called Nexus, which is selling high-resolution scans of over 153 million driver’s licenses and other sensitive IDs including those of journalists, security researchers, and even an FBI assistant director. The breach appears to stem from car rental companies and other organizations that routinely scan customer IDs, with some records traced back to commercial driver’s licenses (CDLs) and Common Access Cards (CACs), used for secure government facility access.
The stolen IDs, available for purchase, include multiple image formats standard scans, infrared, and ultraviolet captures likely intended to bypass hologram-based fraud detection. Beyond driver’s licenses, Nexus also offers medical cards, employment authorizations, residence permits, and marijuana dispensary IDs, with one victim confirming their data was linked to a Las Vegas Planet13 dispensary visit.
The FBI is actively investigating the breach, which highlights the growing risk of third-party data exposure in industries handling sensitive identification documents. The incident underscores the vulnerabilities in ID verification processes, where scanned documents can be exfiltrated and monetized on underground markets.
Federal Bureau of Investigation (FBI) cybersecurity rating report: https://www.rankiteo.com/company/fbi
"id": "FBI1788603918",
"linkid": "fbi",
"type": "Breach",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '153 million+',
'industry': 'Automotive/Rental Services',
'name': 'Car rental companies',
'type': 'Organization'},
{'industry': 'Retail (Cannabis)',
'location': 'Las Vegas',
'name': 'Planet13 (Las Vegas dispensary)',
'type': 'Organization'},
{'industry': 'Government',
'name': 'Government agencies (CAC holders)',
'type': 'Organization'},
{'name': 'Journalists, security researchers, FBI '
'assistant director',
'type': 'Individuals'}],
'attack_vector': 'Third-party data exposure',
'data_breach': {'data_exfiltration': 'Yes',
'file_types_exposed': ['Standard scans',
'Infrared',
'Ultraviolet'],
'number_of_records_exposed': '153 million+',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (PII, government access '
'credentials)',
'type_of_data_compromised': ['Driver’s licenses',
'Medical cards',
'Employment authorizations',
'Residence permits',
'Marijuana dispensary IDs',
'Commercial driver’s licenses '
'(CDLs)',
'Common Access Cards (CACs)']},
'description': 'A recent investigation by KrebsOnSecurity has uncovered a '
'dark web marketplace called Nexus, which is selling '
'high-resolution scans of over 153 million driver’s licenses '
'and other sensitive IDs, including those of journalists, '
'security researchers, and even an FBI assistant director. The '
'breach appears to stem from car rental companies and other '
'organizations that routinely scan customer IDs, with some '
'records traced back to commercial driver’s licenses (CDLs) '
'and Common Access Cards (CACs). The stolen IDs, available for '
'purchase, include multiple image formats such as standard '
'scans, infrared, and ultraviolet captures likely intended to '
'bypass hologram-based fraud detection. Beyond driver’s '
'licenses, Nexus also offers medical cards, employment '
'authorizations, residence permits, and marijuana dispensary '
'IDs, with one victim confirming their data was linked to a '
'Las Vegas Planet13 dispensary visit.',
'impact': {'brand_reputation_impact': 'High',
'data_compromised': '153 million scanned IDs',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential'},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes',
'high_value_targets': 'Journalists, security '
'researchers, FBI assistant '
'director'},
'investigation_status': 'Active (FBI)',
'lessons_learned': 'The incident highlights vulnerabilities in third-party ID '
'verification processes and the risks of scanned document '
'exfiltration.',
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': 'Insecure third-party ID '
'verification processes and lack of '
'safeguards for scanned documents.'},
'recommendations': 'Organizations handling sensitive IDs should implement '
'stricter data protection measures, including encryption, '
'access controls, and monitoring for unauthorized '
'exfiltration.',
'references': [{'source': 'KrebsOnSecurity'}],
'response': {'law_enforcement_notified': 'FBI'},
'threat_actor': 'Dark web marketplace (Nexus)',
'title': 'Dark Web Marketplace Nexus Exposes Over 153 Million Scanned IDs, '
'Including High-Profile Targets',
'type': 'Data Breach',
'vulnerability_exploited': 'Insecure ID verification processes'}