The FBI is investigating a dark-web service that claimed to have access to 153 million driver’s license records covering individuals in the United States and Canada. The database, known as the Nexus collection, reportedly included records marked “CDL” or “ECDL,” raising concerns that stolen commercial driving credentials could make driver verification more difficult across the supply chain.
“The FBI can confirm that it is looking into the incident,” FBI New Orleans told FreightWaves. The agency declined to provide additional details, citing the ongoing investigation.
Authorities have not identified a transportation company or commercial driver as being affected. There is also no evidence at this stage linking the records to cargo theft.
KrebsOnSecurity first reported the apparent connection to Louisiana-based identity provider IDScan.net. The company has not confirmed that its systems were accessed without authorization. Reuters was likewise unable to independently determine where the collection originated. Federal investigators have released no additional information about the source of the data.
IDScan.net markets CDL authentication services to transportation companies. Its logistics materials feature FedEx and Tractor Supply Co., although they do not explain whether those companies currently use the platform. An IDScan case study also describes an unnamed Northeast produce distributor using the company’s VeriScan identity-verification platform at a warehouse.
The company specifically targets distribution centers, ports, freight brokers, third-party logistics providers and motor carriers.
FreightWaves previously examined IDScan’s warnings surrounding fake CDLs and fictitious pickups. Chief Operating Officer Jillian Kossman said criminals have used fraudulent credentials to impersonate legitimate drivers, noting that many counterfeit licenses can appear authentic during a visual inspection.
That earlier discussion highlighted the role identity-verification systems can play in protecting freight pickups.
Nexus claimed ongoing access to identity records
Nexus emerged on August 31 through an advertisement posted on the Russian cybercrime forum Exploit. The operator claimed to be offering more than 160 million North American driver’s license and identification-card records.
The advertisement also claimed access to another 10 million documents, including travel credentials, residency cards and medical files. According to the seller, roughly 500,000 new records were being added every day.
The threat actor further claimed persistent access to a major identity-verification company and its customers. The advertisement alleged that the operation had been collecting material continuously for more than a year.
Those statements remain allegations made by the seller and have not been confirmed by investigators. IDScan.net has not identified a compromised customer or confirmed that its platform was breached.
Zach Edwards, a staff threat researcher at Infoblox, examined Nexus before the service disappeared. Among the records he found was his own driver’s license from a recent cybersecurity conference trip to Las Vegas.
Other records displayed submission dates spanning multiple days, suggesting that at least some of the material had been obtained relatively recently.
Brian Krebs separately monitored the number of licenses displayed by the service and observed the reported count rise by nearly 400,000 in a single day. While searching unrelated names, he also encountered records carrying CDL and ECDL labels.
“There were quite a few in results when searching for random things,” Krebs told FreightWaves.
The files he examined did not appear visually different from other license records.
Some states use ECDL to designate an enhanced commercial driver’s license. However, no one has confirmed what the CDL or ECDL designations specifically represented within the Nexus database.
Krebs found no scans directly associated with freight facilities or commercial pickup activity. The database also did not contain warehouse names, shipment histories or transaction information.
Nexus went offline shortly after Krebs published his findings. Its login page subsequently displayed a message stating that the service was no longer available.
There is no public evidence showing that law enforcement was responsible for taking the service offline. Investigators have not confirmed whether copies of the database remain available elsewhere.
Authentic IDs could undermine freight pickup controls
The potential availability of commercial driver’s licenses raises a particular concern for freight companies, because criminals involved in cargo hijacking already devote considerable effort to appearing legitimate.
“The fact that this threat actor has potentially acquired commercial drivers licenses raises the stakes for freight companies,” Edwards wrote.
Authentic identity documents could make impersonation attempts more difficult to detect. However, investigators have not connected any Nexus record to a cargo-theft operation or other freight crime.
Many of the files reportedly contained photographs showing both sides of the identification card. Some records also included barcode information, ultraviolet images and infrared captures.
Such complete records could potentially allow criminals to reproduce convincing documents using legitimate personal information. Edwards warned that simply presenting a genuine-looking digital or printed credential may not be enough to establish the identity of the person attempting to collect freight.
“Stolen documents can absolutely defeat KYC systems,” Edwards wrote.
His recommendation is straightforward: companies should verify that the individual physically presenting the credential matches the identity associated with the shipment. Freight facilities may also consider requiring physical credentials as part of their release procedures.
Merul Dhiman, who develops identity-verification technology for FreightCheck, which serves transportation companies, pointed to an additional vulnerability for freight operations.
“A CDL is an authorization token, not just an ID,” Dhiman wrote.
A legitimate credential can successfully pass document validation without proving that the individual holding it is actually authorized to collect a particular shipment.
“The system confirmed the document,” Dhiman wrote. “It never confirmed who was holding it.”
Dhiman recommended connecting the live individual at the pickup location with the approved identity before the load is released. This creates a direct link between the person, the credential and the assigned shipment.
IDScan.net’s public relations firm acknowledged FreightWaves’ inquiry and forwarded questions to company representatives. No substantive response had been received before publication.
Reuters also said it could not independently establish the reported source of the records. The FBI investigation remains ongoing.
Several major questions therefore remain unanswered. Investigators have not verified the totals advertised by Nexus, identified a compromised system or determined how many commercial licenses were contained in the collection.
Authorities have also not reported evidence of freight fraud resulting from the alleged exposure.
Why It Matters
For many freight operations, a valid CDL functions as both an identity document and evidence that a driver is authorized to perform a pickup. If criminals obtain genuine license records, a successful document scan could potentially help an impostor pass an initial verification step and gain access to valuable cargo.
The case highlights the limits of relying exclusively on document authenticity when releasing freight.
CFCO
In my opinion, CFCO training reinforces the importance of human-level verification before freight leaves a facility. An authentic CDL can establish that the document is legitimate, but it does not by itself establish that the person standing at the dock is the authorized driver.
Freight teams therefore need to connect the individual physically present at pickup with the approved carrier, the verified identity and the assigned shipment before releasing the load.














