CasinoAdvisor

FBI Investigates 153 Million Leaked Driver License Scans; Las Vegas Casinos Named

Advisor AI
Written by
Last updated 9 hours ago | Fact checked |
Enforcement · 2 min read
FBI Investigates 153 Million Leaked Driver License Scans; Las Vegas Casinos Named
Photo: Casino.org

Based on reporting by Casino.org →

A breach of unprecedented scale has thrust major Las Vegas casino operators into a federal investigation after researchers traced 153 million stolen U.S. and Canadian driver license scans to identity verification service IDScan.net. The stolen data surfaced this week on a dark-web marketplace called Nexus, which advertised searchable access to identity documents for over 170 million people, including driver licenses, identification cards, travel documents, and medical records.

Security journalist Brian Krebs authenticated the breach by locating his own Virginia driver's license in the leaked dataset, with timestamps matching the exact moment he presented it at a Hertz rental counter. Hertz is among the brands IDScan lists as clients. Other researchers independently confirmed the breach's authenticity, including one who found his records from a Planet 13 Las Vegas dispensary visit, matching a 2022 IDScan partnership announcement.

Caesars Entertainment and Circa Casino appeared on IDScan's public client roster, drawing immediate scrutiny from federal authorities and the media. Caesars responded swiftly with a statement asserting that it has not been an IDScan client since February 2025 and did not authorize the company to retain any scans from its accounts. The company characterized the breach as having "no impact" on its customers given the timing. Circa Casino has not yet responded to inquiries about its relationship with IDScan or potential exposure.

The FBI's New Orleans field office opened its investigation on September 1, with IDScan confirming it is investigating potential unauthorized access to its systems. The company issued a customer notice stating it received information suggesting certain data may have been exposed and that it was working to determine the scope of any breach.

What distinguishes this breach as particularly dangerous is the technical sophistication of the stolen data. IDScan's authentication process captures six distinct images per document: front and back under visible light, infrared, and ultraviolet wavelengths. These multispectrum scans replicate the authentication layers used by banks and government agencies to verify document authenticity. Leaked files reviewed by researchers included both infrared and ultraviolet scans, providing criminals with the complete "spectral fingerprint" of legitimate licenses - a template potentially capable of defeating fraud-detection systems designed to identify counterfeits.

The breach also included records of high-ranking U.S. officials, including Defense Secretary Pete Hegseth and an FBI assistant director, underscoring the severity of the exposure. Nexus advertised hundreds of thousands of Common Access Cards used for Department of Defense and secure-facility access.

Meaningfully, obtaining a replacement driver's license offers limited protection, as old license numbers remain in legacy systems at banks, government agencies, and verification platforms. The visible light, infrared, and ultraviolet images cannot be invalidated simply by issuing new documentation. This structural weakness in identity verification infrastructure leaves affected individuals vulnerable to sophisticated identity theft long after document replacement.

The investigation represents one of the most significant identity-verification breaches in North American history and raises questions about data retention practices across the identity verification industry. For casino operators who rely on ID verification systems to comply with age-verification and anti-money laundering requirements, the incident underscores operational and regulatory risks associated with third-party service provider security.

Related stories