Crime & Scandals
Caesars Denies Data Exposure Following FBI Probe into 153 Million Stolen ID Scans
Posted on: September 3, 2026, 12:57h.
Last updated on: September 7, 2026, 08:44h.
The largest known leak of North American driver’s license scans has thrust Caesars Entertainment and Circa Casino into the spotlight.
Both Las Vegas gaming operators appeared on the client roster of identity-verification vendor IDScan.net—Caesars on the company’s public client-trust page, and Circa through a published case study detailing its use of IDScan’s VeriScan software at 21-and-over entrances.

This week, the FBI opened an investigation into a massive dark-web marketplace selling more than 153 million U.S. and Canadian driver’s license scans. Researchers traced the leaked images to identity-verification firm IDScan.net, though the company has not confirmed a breach or publicly named any affected clients.
Caesars quickly pushed back. In a statement, the company said it has not been an IDScan client and has not used the company’s VeriScan system since February 2025, well over a year before the breach surfaced.
“As we had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from our accounts, the company has informed us that the incident should have no impact on Caesars Entertainment,” the company wrote.
Circa has not responded to requests from Casino.org for comment. If they do, we will update this story with their response.
Nexus Point
The records surfaced after a service calling itself Nexus was advertised on the Russian-language cybercrime forum Exploit on Monday (Aug. 31).
Nexus claimed searchable access to identity documents for more than 170 million people, including more than 153 million driver’s licenses, more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards.
The operators said the data came from an “active intrusion” at a major identity verification provider. Security journalist Brian Krebs traced the likely source to New Orleans-based IDScan.net after matching timestamps and scan types to businesses that use the company’s systems.
IDScan has said it is investigating. In a customer notice reported after Krebs’s story, the company said it had received information suggesting that certain information may have been exposed, that IDScan.net may be implicated, and that it was working to determine whether unauthorized access occurred.
Krebs confirmed the data’s authenticity after finding his own Virginia driver’s license among the records. Timestamps matched the moments he and his mother handed their licenses to a Hertz counter. (Hertz is among the brands IDScan lists as using its verification services.)
Within hours of Krebs’ report, the Nexus site vanished from the dark web, its login page replaced by a message saying the service was no longer available.
Other people found matching records. Security researcher Zach Edwards said the timestamp on his license lined up with a visit to Planet 13’s Las Vegas dispensary. In 2022, IDScan announced an exclusive identity-verification agreement with Planet 13.
The stolen set also included records for high-ranking U.S. officials, including Defense Secretary Pete Hegseth and an FBI assistant director. Nexus’s advertised inventory included hundreds of thousands of Common Access Cards used for Department of Defense and other secure-facility access.
The FBI’s New Orleans field office opened an investigation on Tuesday (Sept. 1).
Unique ID-Theft Danger
What makes this alleged breach uniquely insidious is the type of data stolen. IDScan’s authentication process can capture six images per document: front and back under visible light, infrared, and ultraviolet.
These multispectrum scans are the same authentication layers banks and government agencies use to verify that a document is genuine.
Leaked files reviewed by researchers included infrared and ultraviolet scans, not only ordinary photos.
Possessing all six images gives criminals the full “spectral fingerprint” of a real license — a template capable of defeating the very systems designed to detect fakes.
Replacing a driver’s license won’t eliminate the risk of identity theft. A new license number doesn’t erase the old data from existing bank, government, or rental databases—nor does it invalidate the stolen visible-light, infrared, and ultraviolet scan images.
The incident serves as a stark reminder that while centralized ID verification streamlines operations, it also creates high-value targets for cybercriminals.
Conversation (1 comment)