SCCG · Regtech

FBI Opens Probe Into 153 Million Stolen Driver’s License Scans Tied to ID Verification Provider

growfreshnorth-america
FBI Opens Probe Into 153 Million Stolen Driver’s License Scans Tied to ID Verification Provider
AI-generated illustration.

TL;DR — The FBI is investigating the theft of over 153 million driver’s license scans likely taken from IDScan.net. Caesars Entertainment denied exposure after ending its VeriScan use in February 2025. The multispectrum scans create persistent identity theft risks that license replacement does not resolve.

SCCG Take — The incident highlights persistent gaps in vendor data retention practices. Regulators and operators should expect closer scrutiny of identity verification contracts going forward.

The FBI’s New Orleans field office opened an investigation on September 1 into a dark-web marketplace selling more than 153 million U.S. and Canadian driver’s license scans. The service known as Nexus advertised searchable access to identity documents for more than 170 million people. It disappeared from the Russian-language cybercrime forum Exploit within hours of initial reports.

Caesars Entertainment stated it has not been an IDScan.net client and has not used the company’s VeriScan system since February 2025. “As we had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from our accounts, the company has informed us that the incident should have no impact on Caesars Entertainment,” the operator said. Circa Casino has not responded to requests for comment. The details surfaced according to reporting by Casino.org News.

Scale of the Nexus Data Set

Nexus offered more than 153 million driver’s licenses, more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. Security journalist Brian Krebs linked the material to New Orleans-based IDScan.net after matching timestamps and scan types. IDScan.net said it is investigating whether unauthorized access occurred and that certain information may have been exposed.

The records included scans from visits to locations such as a Hertz counter and Planet 13’s Las Vegas dispensary. The set also contained records for high-ranking U.S. officials, including Defense Secretary Pete Hegseth, plus hundreds of thousands of Common Access Cards.

Unique ID-Theft Danger

IDScan’s process can capture six images per document: front and back under visible light, infrared, and ultraviolet. The leaked files reviewed by researchers included these multispectrum scans. This gives criminals the full spectral fingerprint of a genuine license, a template capable of defeating systems designed to detect fakes.

Replacing a driver’s license will not eliminate the danger. A new license number does not erase the old one from every bank, government agency, rental counter, or verification system that stored it. The infrared and ultraviolet images remain available to fraudsters.

Reporting: Casino.org News

Generated by SCCG’s automated editorial system from published source reporting. SCCG Management holds editorial responsibility.

Steve’s read · SCCG Intelligence

This breach exposes the hidden liability in third-party identity verification: data you never see creates risk you own.

We've connected hundreds of operators with compliance and tech vendors over three decades. This breach proves that due diligence cannot stop at contract signature — data retention, deletion protocols, and downstream liability must be negotiated hard and audited constantly, or you inherit risk you cannot see or control.

SCCG angle: SCCG helps operators audit vendor data practices before contracts are signed and negotiate enforceable retention, deletion, and liability terms. We connect clients to vetted identity-verification providers and cybersecurity specialists who understand gaming's regulatory exposure, and we broker the introductions that let you compare stacks and move fast when a vendor relationship needs to change.

SCCG Media · Daily briefing

Gaming, betting and prediction markets — the desk’s read, every weekday.

Subscribe →

Related

SponsoredBumble Mobile — SCCG partnerGaming Sector Update: Prediction Market Appeal, Lottomatica-CIRSA Merger, and Fresh Compliance RulesFinanstilsynet Orders Inpay A/S to Stop New Gambling Client Relationships After AML Breaches
Curated by SCCG · Powered by SCCG Technology