Caesars Denies Exposure as FBI Probes Theft of 153 Million Driver’s License Scans

Key Points

  • Caesars Entertainment and Circa Casino were pulled into news coverage of the FBI’s probe of a dark web marketplace advertising 153 million U.S. and Canadian driver’s license scans for sale this week
  • Both Las Vegas casino operators were identified as clients of the identity verification service IDScan.net, which was identified by researchers as the likely source of the leak
  • Caesars stated it has not been an IDScan client since February 2025 and did not authorize the company to retain any scans

The largest known leak of North American driver’s license scans has thrust Caesars Entertainment and Circa Casino into the spotlight. Both Las Vegas casino operators appeared on the known client roster of identity verification provider IDScan.net — Caesars on IDScan’s public client/trust page, Circa via a case study on IDScan customers that use the company’s VeriScan to scan IDs at its 21-and-over entrances.

Caesars Entertainment
Caesars Entertainment, owner of Caesars Palace, said the largest breach of North American driver’s license scans “should have no impact” on its customers. (Image: Caesars Entertainment)

This week, the FBI opened an investigation into a massive dark‑web marketplace selling more than 153 million U.S. and Canadian driver’s license scans that researchers say were likely stolen from IDScan, which has not named any company as a source of the stolen files and has not confirmed a breach of its systems as of Thursday morning (Sept. 3).

Caesars quickly pushed back. In a statement, the company said it has not been an IDScan client and has not used the company’s VeriScan system since February 2025, well over a year before the breach surfaced.

“As we had no active VeriScan accounts at the time of the incident and did not authorize IDScan.net to retain data from our accounts, the company has informed us that the incident should have no impact on Caesars Entertainment,” the company wrote.

Circa has not responded to requests from Casino.org for comment. If they do, we will update this story with their response.

Nexus Point

The records surfaced after a service calling itself Nexus was advertised on the Russian-language cybercrime forum Exploit on Monday (Aug. 31). Nexus claimed searchable access to identity documents for more than 170 million people, including more than 153 million driver’s licenses, more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards.

The operators said the data came from an “active intrusion” at a major identity verification provider. Security journalist Brian Krebs traced the likely source to New Orleans-based IDScan.net after matching timestamps and scan types to businesses that use the company’s systems.

IDScan has said it is investigating. In a customer notice reported after Krebs’s story, the company said it had received information suggesting that certain information may have been exposed, that IDScan.net may be implicated, and that it was working to determine whether unauthorized access occurred.

Krebs confirmed the data’s authenticity after finding his own Virginia driver’s license among the records. Timestamps matched the moments he and his mother handed their licenses to a Hertz counter. (Hertz is among the brands IDScan lists as using its verification services.)

Within hours of Krebs’ report, the Nexus site vanished from the dark web, its login page replaced by a message saying the service was no longer available.

Other people found matching records. Security researcher Zach Edwards said the timestamp on his license lined up with a visit to Planet 13’s Las Vegas dispensary. In 2022, IDScan announced an exclusive identity-verification agreement with Planet 13.

The stolen set also included records for high-ranking U.S. officials, including Defense Secretary Pete Hegseth and an FBI assistant director. Nexus’s advertised inventory included hundreds of thousands of Common Access Cards used for Department of Defense and other secure-facility access.

The FBI’s New Orleans field office opened an investigation on Tuesday (Sept. 1).

Unique ID-Theft Danger

What makes this alleged breach uniquely insidious is the type of data stolen. IDScan’s authentication process can capture six images per document: front and back under visible light, infrared, and ultraviolet. These multispectrum scans are the same authentication layers banks and government agencies use to verify that a document is genuine.  

Leaked files reviewed by researchers included infrared and ultraviolet scans, not only ordinary photos.

Possessing all six images gives criminals the full “spectral fingerprint” of a real license — a template capable of defeating the very systems designed to detect fakes.

In addition, replacing one’s driver’s license won’t eliminate the danger of ID theft because a new license number doesn’t erase the old one from every bank, government agency, rental counter, or verification system that stored it, and it doesn’t invalidate the visible light, infrared, and ultraviolet images that were taken.

Corey Levitan joined Casino.org in 2022 after a long career covering Las Vegas. He currently covers entertainment, dining and gaming news in Las Vegas.

Corey spent six years covering the Vegas Strip for the Las Vegas Review-Journal, where he also wrote the most popular humor column in the city’s history. (For “Fear and Loafing,” he tried out 176 Vegas jobs, including poker player, blackjack dealer and Follie Bergere dancer.)

Corey has won more than 100 local, state and national awards for his journalism, which has also appeared in Rolling Stone, New York Magazine and the New York Post.

Corey is a New York native whose hobbies include playing guitar, trying to be a better husband, and arguing with strangers on Facebook.

Contact Corey at corey@casino.org.

Comments icon

Conversation (0)

+ Add a comment

Be the first to comment on this article.

Write a comment

Your email address will not be published.