A massive database containing 153 million US and Canadian driver’s licenses recently appeared for sale on a Russian cybercrime forum. This breach, which circulated on the forum known as Exploit, included a staggering range of identity documents. Beyond the millions of driver’s licenses, the cache reportedly held 10 million ID cards, 1.9 million travel documents, and hundreds of thousands of medical and access cards, according to cybersecurity journalist Brian Krebs. The breach came to light after Krebs discovered the service, dubbed Nexus, while monitoring the forum. To prove the legitimacy of the data, the hackers posted Krebs’ own driver’s license as a free sample. The situation grew even more serious when he discovered that the database contained the personal information of U.S. Secretary of Defense Pete Hegseth. Krebs confirmed the data was real after verifying details for friends and family members who consented to the search. The common thread among the victims was their use of specific businesses, including Hertz and a marijuana dispensary called Planet13. Security and privacy researcher Zach Edwards confirmed his own information was in the leak, noting that he had provided his ID at Planet13. The scale of this exposure is daunting because of the level of detail included in the files By comparing the timestamps on the leaked document scans with the times victims visited these businesses, it became clear where the data originated. It turns out that neither Hertz nor Planet13 handles this verification internally. Both companies rely on an outside provider for identity authentication, a company identified as idscan.net. The FBI is reportedly investigating the leak of more than 153 million US and Canadian driving licencesAccording to KrebsOnSecurity, the records are being sold on the dark web and include photos, addresses and other personal information pic.twitter.com/nyt13c50rb— Dexerto (@Dexerto) September 2, 2026 Many of the leaked licenses feature photographic, UV, and IR scans. This level of detail makes it significantly easier for criminals to commit identity theft, as these documents are frequently accepted to open bank accounts or establish new lines of credit. The potential for harm extends to highly vulnerable populations, including people in witness protection programs or those escaping domestic violence. Jillian Kossman, a marketing and operations leader at idscan.net, addressed the situation after being contacted by Krebs. “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” she said. The FBI is also involved, with the New Orleans field office opening an official investigation into the breach. This isn’t the first time a third-party service provider has caused such a headache. A similar incident previously impacted the communication app Discord, exposing 70,000 government IDs. These recurring failures have privacy experts, including the EFF, calling for caution. There is growing concern regarding the push for mandatory online age verification laws. Critics argue that these requirements increase the amount of sensitive data being stored by third parties, creating more targets for hackers and further compromising personal privacy. While the Nexus service is no longer available as of the time of writing, the damage is done for millions of people.