Caesars Denies Exposure as FBI Probes Theft of 153 Million Driver’s License Scans

Caesars Denies Exposure as FBI Probes Theft of 153 Million Driver’s License Scans

The largest known leak of North American driver’s license scans has put Caesars Entertainment and Circa Casino in the spotlight. Both Las Vegas casino operators appeared on the client list of identity verification provider IDScan.net — Caesars on IDScan’s public client page, and Circa in a case study showcasing how the company uses IDScan’s VeriScan system to check IDs at its 21-and-over entrances. Caesars Entertainment, which owns Caesars Palace, stated that the massive breach “should have no impact” on its customers.

FBI Investigation Underway

This week, the FBI opened an investigation into a dark-web marketplace that is selling more than 153 million U.S. and Canadian driver’s license scans. Researchers believe the data was likely stolen from IDScan.net, though the company has not named any source for the stolen files and, as of Thursday morning (Sept. 3), has not confirmed a breach of its systems. Caesars quickly pushed back against any suggestion of involvement.

In a statement, Caesars clarified that it has not been an IDScan client and has not used the company’s VeriScan system since February 2025 — more than a year before the breach surfaced. “As we had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from our accounts, the company has informed us that the incident should have no impact on Caesars Entertainment,” the statement read.

Circa has not responded to requests for comment from Casino.org. If they do, this story will be updated with their response.

The Nexus Leak

How the Data Surface

The records surfaced after a service calling itself Nexus was advertised on the Russian-language cybercrime forum Exploit on Monday (Aug. 31). Nexus claimed to offer searchable access to identity documents for more than 170 million people, including:

The operators stated that the data came from an “active intrusion” at a major identity verification provider. Security journalist Brian Krebs traced the likely source to New Orleans-based IDScan.net after matching timestamps and scan types to businesses that use the company’s systems.

IDScan’s Response and Data Verification

IDScan said it is investigating the claims. In a customer notice reported after Krebs’ story, the company acknowledged receiving information suggesting that certain data may have been exposed, and that IDScan.net may be implicated. It stated it was working to determine whether unauthorized access occurred.

Krebs confirmed the data’s authenticity after finding his own Virginia driver’s license among the records. Timestamps matched the moments he and his mother handed over their licenses at a Hertz counter — Hertz is among the brands IDScan lists as using its verification services.

Within hours of Krebs’ report, the Nexus site vanished from the dark web, its login page replaced by a message saying the service was no longer available.

Other individuals also found matching records. Security researcher Zach Edwards said the timestamp on his license matched a visit to Planet 13’s Las Vegas dispensary. In 2022, IDScan announced an exclusive identity-verification agreement with Planet 13. The stolen set also included records for high-ranking U.S. officials, including Defense Secretary Pete Hegseth and an FBI assistant director. Nexus’s advertised inventory included hundreds of thousands of Common Access Cards used for Department of Defense and other secure-facility access.

The FBI’s New Orleans field office opened an investigation on Tuesday (Sept. 1).

Unique ID-Theft Dangers

Why This Breach Is Particularly Dangerous

What makes this alleged breach uniquely insidious is the type of data stolen. IDScan’s authentication process can capture six images per document: front and back under visible light, infrared, and ultraviolet. These multispectrum scans are the same authentication layers that banks and government agencies use to verify that a document is genuine.

Leaked files reviewed by researchers included infrared and ultraviolet scans, not just ordinary photos. Possessing all six images gives criminals the full “spectral fingerprint” of a real license — a template capable of defeating the very systems designed to detect fakes.

Limited Protection After a Breach

Additionally, replacing one’s driver’s license won’t eliminate the danger of identity theft. A new license number doesn’t erase the old one from every bank, government agency, rental counter, or verification system that stored it. It also doesn’t invalidate the visible light, infrared, and ultraviolet images that were captured.

This means that even if a victim gets a new license, criminals can still use the old spectral scans to create convincing forgeries, bypassing security checks that rely on these detailed images.