The FBI is investigating a newly launched identity-theft service called Nexus that claims to sell digital scans of more than 153 million driver’s licenses from people in the United States and Canada, according to Brian Krebs at KrebsOnSecurity. Krebs reports that the service appeared this week on the dark web and was promoted by a new user on Exploit, a Russian cybercrime forum. The listing reportedly advertised access to identity documents for more than 170 million people in North America. The source who alerted Krebs did so, Krebs writes, because the seller used Krebs’s own Virginia driver’s license as a free sample in the initial sales thread. The headline number is not the only category Nexus is claiming. According to KrebsOnSecurity, the service says it has more than 153 million driver’s licenses, more than 10 million identification cards, more than 3 million travel documents and/or international IDs, and at least 579,000 medical cards. Krebs reports that the total for driver’s-license records rose by nearly 400,000 over a 24-hour period. Krebs says his checks inside Nexus suggest the 153 million figure may not be implausible, though the cluster does not independently verify the database size. He reports that a blank search returned about 11.5 million pages of results with roughly 15 results per page. A search limited to Canadian driver’s licenses reportedly returned about 1.1 million results, with Ontario accounting for 473,673 records. The alleged provenance of the data remains the critical unresolved question. Krebs reports that the operators of Nexus claim the license images are coming from an active breach at a “major identity verification company” with multiple Fortune 500 customers. Separately, Krebs says interviews with people whose licenses appeared for sale suggest the images may be siphoned from a widely used identity-verification company based in Louisiana. KrebsOnSecurity also reports that the FBI’s New Orleans field office has opened an official inquiry into the source of the images. The item does not name the suspected company, and the provided materials do not include an FBI statement or confirmation from any identity-verification vendor. The records described by Krebs are not limited to ordinary consumer identity documents. He reports that the service includes a record for U.S. Defense Secretary Pete Hegseth and other high-ranking U.S. government officials. The database also reportedly includes marijuana dispensary cards, records marked “CDL,” and records marked “CAC,” which Krebs notes may refer to Common Access Cards used for government physical access. For now, the story should be treated as a serious but still developing cybercrime report. The FBI inquiry, the record counts, and the Louisiana-company lead all come through KrebsOnSecurity; Nexus’s own claims are claims by alleged criminals, not established facts. What is clear from the reporting is that a marketplace is advertising a large trove of identity-document images, and federal investigators are looking into where those images came from. Who benefits: Fraud crews would benefit most if Nexus’s advertised inventory is real, because document scans can support account takeover, synthetic identity, and verification bypass attempts. Investigators may also gain leads if the marketplace’s records reveal a common source. Who's exposed: People whose licenses or other identity documents appear in the database are directly exposed. Companies using the implicated identity-verification pipeline could face customer-support, compliance, and incident-response pressure if the source is confirmed.