
A massive trove of more than 170 million Americans’ and Canadians’ sensitive identity documents has surfaced for sale on the dark web, sounding the alarm over the growing push for centralized digital ID and online identity-verification systems.
The staggering database includes scans of more than 153 million driver’s licenses.
It also contains 10 million ID cards, more than three million travel documents, and over half a million medical cards.
Even President Donald Trump’s Defense Secretary Pete Hegseth was exposed.
An assistant director of the FBI was also reportedly among the victims.
The enormous collection of personal identification documents was being sold through a dark web service called “Nexus.”
Cybersecurity journalist Brian Krebs uncovered the operation after the stolen records appeared on a Russian cybercrime forum.
The breach represents a chilling demonstration of the danger created when millions of citizens are required to hand over their most sensitive identity documents to centralized verification services.
And the threat is becoming increasingly urgent as politicians push to expand digital identification and age-verification requirements across the Internet.
153 Million Driver’s Licenses Exposed
The scale of the exposed database is extraordinary.
Nexus contained more than 153 million driver’s license scans from the United States and Canada.
Combined with the other compromised documents, the database contained records covering more than 170 million people.
Before disappearing from the dark web, Nexus allowed customers to search through the enormous collection of identity documents.
The people behind the operation openly boasted that they had been siphoning off information for more than a year.
“We have been continuously exfiltrating new data for over a year into our private database,” Nexus stated on the Russian forum.
“Records are available to preview before purchase with pertinent information redacted.
“Customer photos are displayed if available.”
The criminals claimed their source was a “major identity verification company” that works with several Fortune 500 corporations.
Krebs was given compelling evidence that the database was genuine.
The person controlling the files produced a scan of Krebs’ own Virginia driver’s license.
Krebs then discovered his mother’s license in the system.
The timestamps on the two documents were separated by only seconds.
ID Scans Traced to Verification Network
That timing provided an important clue.
Krebs and his mother had handed their driver’s licenses to a Hertz representative at the same time.
“I was able to find my mother’s driver’s license in this service as well, and the timestamps for her images are just a few seconds apart from mine,” Krebs wrote.
“That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.”
Privacy researcher Zach Edwards also found his license inside Nexus.
Its timestamp corresponded with a trip to Las Vegas during which he presented his ID to the TSA, the Aria hotel, and marijuana dispensary Planet13.
Edwards said Planet13 was the only one of those locations where he knew his license had been scanned.
Planet13 signed an exclusive identity-verification agreement with Louisiana-based IDScan.net in 2022.
IDScan.net also provides verification technology used by Hertz.
The company says its technology operates at more than 20,000 locations and processes more than 21 million identity verifications every month.
It also provides verification services for more than 1,000 marijuana dispensaries across 19 states.
Major companies named on its website include Hertz, FedEx, Caesars Entertainment, Target, Motorola Solutions, and Jack Henry.
Centralized ID Systems Create Massive Targets
The apparent breach exposes the fundamental danger of building enormous systems designed to collect and process citizens’ identity documents.
The more governments and corporations demand that people scan driver’s licenses and other official documents to prove who they are, the more valuable those centralized repositories become to criminals.
A database containing millions of government-issued identity documents is an extraordinary target.
And when those systems are compromised, the information cannot simply be reset like a password.
A victim can change a compromised password within minutes.
They cannot replace their face, date of birth, identity history, or other permanent personal information every time another database is breached.
The Nexus exposure shows what is at stake when identification systems operate on an enormous scale.
More than 170 million highly sensitive identity documents were apparently made available through a criminal marketplace.
The people behind Nexus even claimed they had been continuously stealing new information for over a year.
Governments Push for Even More Online ID Checks
The bombshell comes at a particularly alarming moment.
Governments are increasingly pushing online age-verification requirements that can force citizens to prove their age or identity before accessing lawful content.
Many of the proposals are promoted as measures to protect children.
But requiring millions more people to submit identity documents inevitably creates vast new streams of highly sensitive personal data that must be processed somewhere.
Every additional ID check creates another opportunity for that information to be collected, retained, mishandled, breached, or stolen.
Louisiana has been among the states pushing digital identification and online age-verification measures.
IDScan.net itself is based in Louisiana.
The company says global brands use its technology across tens of thousands of locations.
IDScan.net told Krebs that it is investigating the apparent breach.
“At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” IDScan.net’s Jillian Kossman told Krebs.
The FBI’s New Orleans field office also opened an investigation on September 1.
However, determining exactly who stole the records could now be more difficult.
Nexus mysteriously vanished from the dark web on the same day Krebs exposed the operation.
Digital ID Push Comes with Enormous Risk
The disappearance of Nexus does nothing to undo the damage if millions of identification documents have already fallen into criminal hands.
Nor does it eliminate the broader threat exposed by the scandal.
Americans are increasingly being asked to surrender identification to private systems as a condition for accessing products, services, and online content.
The justification may be security, fraud prevention, or “child safety.”
But concentrating identity information on such an enormous scale creates a prize for hackers that becomes more valuable with every person added to the system.
The exposure of more than 170 million identity documents is a warning of what can happen when that infrastructure is compromised.
Centralized digital ID systems are sold to the public as a way to make the Internet and everyday life safer.
But when those systems fail, the consequences can be catastrophic.
And unlike a stolen password, once a person’s most fundamental identity data escapes into the hands of criminals, there may be no way to take it back.
In Case You Missed It:
HisStory Ep. 10 – King Nimrod’s Tower of Babel to Make Atlantis Great Again
Conservative Inc influencers after the group chat sends out the new talking points
For breaking news from one of the most over the target and censored names in the world join our 100% Free newsletter at Newsletter, The best way to get the information you want.
Also follow us at Gab
Follow us on Gab.com , Like, comment, and subscribe.
Telegram, Join our Telegram chat
Shop Patriot and Detox the Deep State by shopping with our sponsors.
RedPillLiving.com, Home of Sleepy Joe – the world’s most powerful all natural sleep formula.
The Serapeum.com, The Hidden History of Man & The Mystery Babylon Religion of The Deep State.








