FBI Investigates Dark-Web Service Claiming 153 Million Driver's License Records, Raising CDL Security Concerns
Key Takeaways
- •The FBI is investigating the dark-web service Nexus, which claimed access to 153 million U.S. and Canadian driver's license records, including some labeled CDL or ECDL.
- •KrebsOnSecurity reported a possible connection to Louisiana identity provider IDScan.net, but the company has not confirmed any unauthorized access to its systems.
- •Nexus was advertised on the Russian cybercrime forum Exploit on August 31 and claimed roughly 500,000 fresh records were added daily, though these claims remain unverified.
- •The service went offline shortly after Brian Krebs published his findings, and no evidence indicates law enforcement caused its disappearance.
- •Researchers warn that stolen commercial licenses could defeat KYC systems and enable cargo theft, urging freight facilities to verify the person presenting a credential matches the approved identity before releasing shipments.

The FBI is investigating a dark-web service that claimed access to 153 million driver's license records. The collection, offered under the name Nexus, covered individuals across the United States and Canada, and some entries carried labels reading "CDL" or "ECDL." Researchers warn that stolen credentials of this kind could complicate driver verification throughout the supply chain, an area where warehouses and distribution centers already battle fictitious pickups and identity fraud.
"The FBI can confirm that it is looking into the incident," FBI New Orleans told FreightWaves. "Due to the ongoing nature of the investigation, we decline to comment further." Authorities have not identified an affected transportation business or commercial driver, and no evidence currently links these records to cargo theft.
KrebsOnSecurity first reported the apparent connection involving Louisiana identity provider IDScan.net. The company has not confirmed any unauthorized access involving its systems. Reuters also could not independently establish where the collection originated, and federal investigators have released no further details.
IDScan.net markets CDL authentication to transportation businesses. Its logistics page displays FedEx and Tractor Supply Co. without explaining their current use of the platform. A company case study describes an unnamed Northeast produce distributor using IDScan's VeriScan identity-verification platform at a warehouse. The company's target customers include distribution centers, ports, freight brokers, 3PLs and motor carriers.
FreightWaves has previously examined IDScan's warnings about fake CDLs and fictitious pickups. Chief Operating Officer Jillian Kossman described criminals using false credentials to impersonate legitimate drivers, noting that many fraudulent licenses appear convincing under visual inspection.
Nexus claimed continuous access
Nexus appeared on August 31 through an advertisement on the Russian cybercrime forum Exploit. The operator promoted more than 160 million North American license and identification-card records, along with another 10 million documents that included travel credentials, residency cards and medical files. The advertisement claimed roughly 500,000 fresh additions arrived daily.
The threat actor also claimed persistent access to a major identity-verification company and its customers, and said the operation had continuously collected material for more than a year. These statements remain seller claims rather than confirmed investigative findings, and IDScan.net has not identified any compromised customer or platform.
Zach Edwards, staff threat researcher at Infoblox, examined Nexus before the service disappeared. He found his own license — obtained during a recent cybersecurity conference trip to Las Vegas — within the collection. Other entries carried submission dates spread across multiple days, indicating that recently obtained documents were part of the trove.
Brian Krebs separately watched the displayed license count increase by nearly 400,000 in a single day. While searching unrelated names, he found CDL and ECDL labels. "There were quite a few in results when searching for random things," Krebs told FreightWaves. Those files showed no differences from other license entries.
Some states use ECDL to denote an enhanced commercial driver's license, but no one has confirmed what either designation meant inside Nexus. Krebs found no scans tied directly to freight facilities or commercial pickups; the database contained no warehouse names, shipment histories or transaction details.
Nexus went offline shortly after Krebs published his findings, its login page displaying a message that the service was no longer available. No public evidence indicates law enforcement caused the disappearance, and investigators have not confirmed whether copies of the data remain elsewhere.
Stolen IDs could weaken pickup checks
"The fact that this threat actor has potentially acquired commercial drivers licenses raises the stakes for freight companies," Edwards wrote. Criminal groups already invest significant effort into appearing legitimate during cargo hijacking schemes, and authentic identity documents could make impersonation attempts harder to detect. Investigators have not connected any Nexus record to such activity.
The concern is amplified by how freight operations commonly work: a valid CDL often serves as both identification and authorization to release valuable cargo, so a single successful scan of a genuine-looking credential could hand a shipment to an impostor unless someone separately verifies the person presenting it.
Many of the available files reportedly included photographs of both sides of each card, and some entries contained barcode data, ultraviolet images and infrared captures. Criminals could use complete documents to impersonate victims during identity checks, and Edwards warned that someone could print fraudulent licenses using genuine information.
"Stolen documents can absolutely defeat KYC systems," Edwards wrote. Digital scans alone may no longer provide enough certainty during hiring or pickup verification. He recommended confirming that each person matches the presented identity, and freight facilities may also require physical credentials before releasing cargo.
Merul Dhiman, who develops identity-verification technology for FreightCheck, which serves transportation companies, identified a broader concern for freight operations. "A CDL is an authorization token, not just an ID," Dhiman wrote. A genuine credential can pass validation without confirming that the person presenting it belongs with the shipment.
"The system confirmed the document," Dhiman wrote. "It never confirmed who was holding it." He recommended matching a live person with the approved identity at pickup — a step that connects the credential, driver and assigned load before release.
IDScan.net's public relations firm acknowledged the FreightWaves inquiry and forwarded questions to company representatives, but no substantive response arrived before publication. Reuters also could not independently establish the reported source.
The FBI investigation remains ongoing, and significant questions still surround the incident. Investigators have not verified the advertised totals or identified a compromised system. Nobody has confirmed how many commercial licenses appeared within Nexus, and authorities have not found any resulting freight fraud. What to watch next is whether investigators confirm the data's origin, whether copies of the collection resurface, and whether carriers and warehouses adjust pickup verification practices in response. CFCO training emphasizes that human-level verification should occur before freight leaves the dock: an authentic CDL validates the document, not the person holding it, and teams must connect that individual with the approved carrier and assigned shipment before release.