A potentially large driver’s-license and identity-card breach is under investigation after a hacker site reportedly claimed access to more than 153 million digital scans from the United States and Canada, according to Tom's Guide, citing reporting by security journalist Brian Krebs. Tom's Guide reports that Krebs found a site called Nexus that appeared to be selling or exposing access to a database said to contain 153,347,439 identity-card scans. Krebs wrote that a blank search on Nexus returned about 11.5 million pages of results, with roughly 15 results shown per page, which he said suggested the headline number was not an obvious exaggeration. The records reportedly included driver's licenses. Tom's Guide says Krebs found his own license among the searchable entries and also found an entry for U.S. Defense Secretary Pete Hegseth; the Defense Department is reportedly aware and investigating. The possible vendor connection remains the central unresolved issue. Tom's Guide reports that Krebs worked with security researcher Zach Edwards, whose ID was also allegedly present, and that they identified Louisiana-based identity verification company IDScan as the potential source of the exposure. Edwards wrote on Bluesky that details in the report and the timing of his own license record pointed to what he described as an ongoing real-time breach at IDScan. IDScan has not publicly confirmed the breach in the material provided. Tom's Guide says Krebs reported that both the FBI and IDScan are investigating. Tom's Guide also says it contacted both organizations but did not receive a response before publication. According to Tom's Guide, an IDScan spokesperson told Krebs that the updates he provided were helpful to the company's investigation but that the company could not share additional information at that point. A note reportedly from the company said that on September 1 it received information suggesting certain data may have been exposed and that IDScan.net may be implicated; the company said it was working to validate the information, determine whether unauthorized access occurred, and assess the scope. The same reported note said IDScan had taken steps to secure its system, notified partner companies, retained legal counsel and begun a third-party forensic investigation. Tom's Guide also reports that Nexus went offline shortly after Krebs' report was published, though it said the site could reappear under another domain. For now, the facts support a serious developing incident rather than a fully confirmed breach narrative. The reported scale is unusually large, and the alleged data type—digital scans of government identity documents—is sensitive. But the exact source, duration, access method, affected partners and confirmed victim count remain open questions pending company, law-enforcement or forensic findings. Who benefits: Too early to tell. For now, the clearest beneficiaries would be investigators if the company or forensic review establishes what happened. Who's exposed: People whose licenses or identity cards were present in the alleged Nexus database may face exposure of sensitive identity-document images. Companies that rely on the implicated vendor could face operational, legal and customer-notification questions if the breach is confirmed.