A scan of Defense Secretary Pete Hegseth's driver's license was offered for $100 on a dark-web identity marketplace that claimed access to more than 153 million North American license records, according to cybersecurity journalist Brian Krebs, prompting an FBI inquiry into a suspected breach involving identity-verification provider IDScan.net.
The marketplace, known as Nexus, offered digital copies of U.S. and Canadian driver's licenses containing far more than basic identification information, Krebs reported on KrebsOnSecurity. Records allegedly included images of the front and back of licenses as well as infrared and ultraviolet scans used in some identity-verification systems.
One of the records available for purchase belonged to Hegseth and carried a $100 price tag, according to Krebs. The cybersecurity journalist said his own Virginia driver's license appeared as a free sample advertising the service on a Russian cybercrime forum.
The presence of a cabinet official's identification illustrates the potential national-security dimension of a breach that otherwise appears to have swept up large numbers of ordinary consumers. The supplied report doesn't indicate that Hegseth himself was specifically targeted or that his identity was successfully used for fraud.
Nexus claimed its database contained more than 153 million driver's licenses, along with 10 million identification cards, three million international travel or identification documents and 579,000 medical cards.
Krebs reported finding indications that the marketplace's enormous inventory claims could be credible. A search without identifying criteria produced roughly 11.5 million pages of results, with approximately 15 records displayed on each page.
The database also appeared to be expanding rapidly. The number of driver's-license records reportedly increased by nearly 400,000 over a 24-hour period, while the Nexus operators claimed they had been extracting new information for more than a year.
The marketplace was subsequently reported to have gone offline, displaying a message saying it was no longer available. Its disappearance doesn't establish what happened to copies of the data that may already have been downloaded or sold.
Evidence examined by Krebs pointed toward IDScan.net, a Louisiana-based company whose technology allows businesses to scan and authenticate identification documents both online and at physical locations.
Krebs reported that timestamps associated with some license images corresponded with dates on which victims had used services requiring identification, including car rentals and other businesses conducting identity checks. Those correlations contributed to suspicions that the records originated from systems associated with IDScan.net.
IDScan.net says its VeriScan platform provides services including identity-fraud prevention, age verification, visitor management and access management. According to the company's public materials, its technology verifies millions of IDs and identities each month and is used by thousands of businesses.
The company's website and trust materials have identified major brands including Hertz, FedEx and Target. IDScan.net also markets its products to cannabis dispensaries and other businesses required to verify customers' ages.
The presence of companies in IDScan.net's marketing materials doesn't by itself establish that customer information collected by those businesses was exposed. The supplied report also doesn't establish precisely how Nexus obtained the documents or independently confirm that all of the marketplace's claimed 153 million license records were authentic.
IDScan.net hasn't publicly confirmed the reported scale or details of a breach. Krebs said the company was investigating but hadn't provided substantive answers to his detailed questions.
Cybernews separately cited a message from IDScan.net saying the company was working to validate information surrounding a possible security incident and determine whether unauthorized access had occurred.
The FBI's New Orleans field office has opened an official inquiry into the apparent incident involving IDScan.net, according to Krebs. The supplied report doesn't provide details about the scope of the federal investigation or whether investigators have identified who operated Nexus.
Driver's-license scans can be particularly valuable to criminals because a single record can contain a person's full name, home address, date of birth, photograph, signature and license number. High-resolution front-and-back scans can provide substantially more material for identity fraud than credentials such as an exposed email address or password alone.
Infrared and ultraviolet images could create additional risks because such scans are used by identity-verification technologies to examine security features embedded in identification documents. Access to multiple versions of authentic IDs could potentially aid attempts to defeat fraud controls or impersonate victims during identity checks.
The reported victims range from a senior U.S. government official to people who may simply have presented identification while renting a vehicle, entering an age-restricted business or completing another routine transaction. Whether Nexus actually possessed all of the records it advertised remains under investigation, leaving the FBI and IDScan.net to determine how much information was exposed and how it reached a marketplace built to sell identities.