If you ever needed more proof that governments pressuring companies to collect ID data from customers or users is a bad idea, you only have to look at what happened this week. A dark-web service advertised on August 31 has been offering over 153 million scans of driver’s licenses, more than 10 million other identity cards, over 3 million travel documents and/or international IDs, and at least 579,000 medical cards.
The data apparently stems from a company hired to verify people’s identities. The service, called Nexus, was advertised on the Russian-language cybercrime forum Exploit.
Security researcher Brian Krebs found that a blank search on Nexus returned about 11.5 million result pages with roughly 15 results per page. This would support the claim that there were over 153 million license scans in the database, and the number increased by nearly 400,000 in 24 hours.
Nexus itself claimed to have “continuously exfiltrated new data for over a year into our private database” – but this is not verified and could be an advertising claim.
What Krebs was able to verify is that his own Virginia license was among those available on the site. He searched with permission for the licenses of more than a dozen friends and relatives; nine people whose records appeared said that the attached timestamps matched or closely tracked their travels.
In the case of Krebs and his mother, the timestamps corresponded to a June 2025 car rental from Hertz. Their records were created seconds apart, matching their account that they handed both licenses to the rental representative at the same time.
Krebs’s record contained three pairs of images showing the front and back of the license in visible light, infrared, and ultraviolet.
Privacy researcher Zach Edwards also found his license on Nexus. Its timestamp matched a trip to Las Vegas, where he had presented the document to TSA, the Aria hotel and the Planet13 dispensary. Edwards said the dispensary was the only one of the three places where he knew the license had been scanned.