Pete Hegseth’s driver’s license turns up on the dark web

A digital scan of Defense Secretary Pete Hegseth‘s driver’s license surfaced on a dark web identity-theft marketplace called Nexus, according to cybersecurity journalist Brian Krebs of KrebsOnSecurity. Krebs reported that the record was listed for sale for $100. The listing was part of a far larger trove, with more than 170 million identity documents available for purchase through the service when Krebs examined it.
Hegseth’s inclusion in the database is notable given his role overseeing national defense. The Trump administration has also begun referring to the Pentagon as the Department of War, although Hegseth continues to be identified as Defense Secretary in most official and legal contexts.
How Krebs discovered the scheme
Krebs first learned of the operation after finding that his own Virginia driver’s license was being used as a free sample to advertise the service on a Russian-language cybercrime forum. The advertisement claimed the operators were adding roughly half a million new documents every day, sourced from what they described as a “major identity verification company,” suggesting near real-time access to that company’s systems.
According to Krebs, his own record in the database contained six separate image files, consisting of three sets of front-and-back photographs: a standard scan plus infrared and ultraviolet versions. The level of detail led Krebs and outside researchers to conclude that the images were consistent with scans produced by professional identity-verification hardware rather than simple photographs uploaded to a database.
The scale of the Nexus database
Nexus claimed to possess 153 million driver’s licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579,000 medical cards, 429,000 Common Access Cards, 91,000 residence cards, 77,000 employment authorization records and roughly 5 million other documents.
The United States has approximately 240 million licensed drivers, meaning the claimed 153 million driver’s licenses would represent roughly two-thirds of the country’s driving population if the figure is accurate.
The records reportedly went beyond driver’s licenses. Some documents in the database were labeled “CAC,” an abbreviation that may refer to Common Access Cards used to enter government buildings and secure federal facilities, although it remains unclear whether any active federal access credentials were compromised.
FBI opens an investigation
The FBI’s New Orleans field office opened a formal inquiry into the apparent breach. An FBI spokesperson confirmed that the bureau is “looking into the incident” but declined to comment further.
Krebs also reported finding the driver’s license of an FBI assistant director in the database, although he did not name the official. He noted that word of his inquiry appeared to reach the bureau quickly after he shared the finding with a trusted source. Krebs added that he did not find a license belonging to FBI Director Kash Patel in the Nexus database.
Tracing the source to IDScan.net
Working with security researcher Zach Edwards, whose own ID card was also found in the database, Krebs identified Louisiana-based identity-verification company IDScan.net as the likely source of the leaked scans. The company is used by major consumer brands to verify millions of people’s identification documents each month.
IDScan.net does not sell directly to consumers. Instead, it licenses software to businesses that need to check whether a driver’s license, passport or other government ID is authentic. A customer may hand over a card at a rental counter, dispensary or hotel desk or submit it through an online verification screen, with the vendor operating in the background.
IDScan.net reportedly processes more than 21 million identity verifications a month at more than 20,000 locations for clients that include Hertz, Target, FedEx and Caesars Entertainment. The company’s “trust” page also lists Motorola Solutions and financial services firm Jack Henry among its clients. Its documentation states that its technology scans IDs using infrared and ultraviolet light, matching the imaging signature investigators found in the leaked Nexus files.
Not every company named on that client list has been confirmed to have had its own customer data exposed. Caesars Entertainment told Krebs it had not been an IDScan.net client and had not used the company’s VeriScan product since February 2025, despite appearing on IDScan’s public materials.
Timestamps that matched real visits
Investigators built their case in part by matching timestamps on leaked license scans with real-world occasions when people had handed over their IDs.
Krebs found that the timestamp on his own leaked scan corresponded to a flight he took to the Midwest in June 2025. With permission, he searched the Nexus database on behalf of friends and family members and found nine license records whose timestamps matched their travel dates. Several individuals connected the records to Hertz car rentals.
Edwards found his own license in the database with a timestamp matching a trip to the DEFCON security conference in Las Vegas. He said the one venue he was certain had scanned his ID during that trip was the Planet13 marijuana dispensary.
IDScan.net announced an exclusive nationwide identity-verification agreement with Planet13’s dispensaries in 2022 and the company has said it handles identity verification for more than 1,000 marijuana dispensaries across 19 states.