Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
▣ Breach NEXUS-ID-BREACH 2026-09-10

IDScan.net: Nexus Dark Web Identity Theft Service Sells 153M Driver's License Scans

"A dark web identity theft service called Nexus surfaced on the Russian cybercrime forum Exploit in late August 2026, advertising searchable access to digital scans of government-issued identity documents belonging to…"

A dark web identity theft service called Nexus surfaced on the Russian cybercrime forum Exploit in late August 2026, advertising searchable access to digital scans of government-issued identity documents belonging to roughly 170 million people across North America. KrebsOnSecurity, which broke the story on September 1, reported the service claimed more than 153 million U.S. and Canadian driver's licenses, over 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. The FBI's New Orleans field office opened a formal inquiry the same day, a fact Reuters confirmed independently on September 2 with the bureau stating it was investigating a report that "tens of millions" of licenses were being sold. Krebs and researcher Zach Edwards traced the likely source to IDScan.net, a Louisiana-based identity verification provider. One important caveat frames everything below: at the time of writing there is no PRIMARY-tier confirmation in the public record. No breach notification, regulator filing, or CERT advisory has been published. The attribution rests on journalistic reconstruction, and the company itself has only acknowledged that it is investigating.

What Happened

On Monday, August 31, a source alerted Brian Krebs to a new user on Exploit advertising an identity theft service offering digital scans of identity documents on more than 170 million people in North America. The tip came because the seller had posted Krebs' own Virginia driver's license as a free sample in the initial sales thread. The service, branded Nexus, offered previews before purchase with sensitive fields redacted, and the advertisement noted that "customer photos are displayed if available."

Krebs verified the data was authentic by locating his own license, then expanded the check to consenting friends and family. Per the ACS Information Age account, he traced multiple cases where victims had handed ID documents to third parties, including car rental firm Hertz and cannabis dispensary Planet13, around the time their records were captured. SecurityAffairs reports Krebs' own record carried a timestamp matching a June 2025 flight and car rental. That pattern of physical-world ID checks pointed at a shared upstream vendor rather than any single retailer.

Working with security researcher Zach Edwards, whose ID was also in the set, Krebs identified IDScan.net as the likely source. The New Orleans firm sells ID fraud prevention, access management, and age verification products, plus ID-activated door locks and mobile scanners. SecurityWeek reports the company performs over 21 million verifications per month at more than 20,000 locations across roughly a dozen industries. SecurityAffairs lists Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and Jack Henry among its named clients.

Nexus went offline shortly after Krebs published. SecurityWeek confirms the shutdown; ACS reports the login page was replaced with the message "this service is no longer available." IDScan CEO Jimmy Roussel did not respond to TechCrunch, but COO Jillian Kossman told Krebs the company was in the middle of an investigation, and ACS characterises the firm as having confirmed it was investigating a security incident days after the Exploit post appeared. The Department of Defense told TechCrunch it is "aware of these reports and is evaluating them," after Defense Secretary Pete Hegseth's driver's license was found among the listings.

What Was Taken

Record counts vary depending on which figure is being cited and how it was measured, and the difference matters.

The sensitivity is in the composition, not just the volume. SecurityAffairs reports each record contains six images of the license: front and back captured in visible, infrared, and ultraviolet light, plus a timestamp. Bitcoin.com quotes Dr. Marilyne Ordekian describing those IR and UV scans as "a security measure used to verify authenticity," used "to authenticate a physical document as genuine," and warning that criminals therefore hold "not just your ID, but also have the blueprint and the technical layer used to prove it is real."

Accounts also differ on the rate of growth. SecurityAffairs puts the increase at roughly 400,000 records per day at the time of publication; TechCrunch and Tech Weekly report the advertisement claimed about half a million new documents daily. Either figure implies the same conclusion the operators asserted directly: exfiltration was live and ongoing, sustained over more than a year, with something close to real-time access to the source systems.

Why It Matters

The reset problem is the whole story. Ordekian's framing to Bitcoin.com is the clearest articulation of it: "With breaches leaking passwords, one can reset their credentials and move on." A driver's license carries a photograph, home address, and date of birth, attributes that follow a person for years or permanently. There is no rotation procedure. Issuing a replacement license changes the document number but not the face, the birth date, or the address history already in criminal hands.

The infrared and ultraviolet layers escalate this from an identity theft dataset into a forgery reference library. Those channels exist precisely so a scanner or a trained human can distinguish a genuine document from a counterfeit. Publishing 153 million examples of what a genuine document looks like under IR and UV hands counterfeiters ground truth for every state and provincial template in the corpus, including the security features that document examiners rely on.

This also inverts the trust model of remote identity verification. Document-image-based KYC assumes that possessing a high-quality scan of an ID proves possession of the ID. A corpus of six-angle, multi-spectrum captures, many with matching customer selfies, undermines that assumption at population scale. Dmitry Popov of Sumsub, quoted by Bitcoin.com, argues that ID checks now require a second factor as a baseline rather than an enhancement.

Finally, the vendor concentration risk is stark. None of the 153 million people in this set chose to do business with IDScan.net. They handed a license to a bar, a dispensary, a rental counter, or a casino. The aggregation of ID captures into a small number of verification intermediaries created a single target whose compromise reaches further than any of its individual customers ever could. The presence of a sitting U.S. Defense Secretary's license, alongside the unconfirmed CAC records, demonstrates that this class of vendor holds national security exposure that its clients almost certainly never modelled.

The Attack Technique

The intrusion vector is not publicly known. No source in this set describes an initial access method, a malware family, a vulnerability, or a named threat actor. What can be stated from the reporting:

Treat any account of "how they got in" circulating elsewhere as speculation until IDScan.net, the FBI, or a regulator says otherwise.

What Organizations Should Do

  1. Inventory which identity verification vendors hold your customers' document images, and for how long. If you run age verification, rental checks, onboarding KYC, or physical access control, you likely have a downstream provider retaining ID scans on your behalf. Find the contract, find the retention clause, and find out whether IDScan.net or a reseller of it sits anywhere in that chain.
  2. Force retention and deletion terms into vendor agreements now. A verification event needs a result, not a permanent multi-spectrum archive of the document. Require deletion of raw captures after verification completes, demand evidence of enforcement, and treat indefinite image retention as a disqualifying finding in vendor review.
  3. Stop treating a document image as proof of identity. Add a second factor to any workflow where an uploaded or scanned ID is currently sufficient, aligning with the Sumsub position reported by Bitcoin.com. Liveness checks that can be defeated by a high-resolution photograph are not a second factor. Bind to something the attacker cannot copy from a stolen scan: a device, a cryptographic credential, an out-of-band confirmation, or a verified account history.
  4. Raise scrutiny on physical document acceptance, especially IR and UV validation. Scanner-based authenticity checks in this corpus should be considered degraded. Where physical ID drives high-value access, layer in checks that do not depend on the document's security features alone.
  5. Model the executive and privileged-user exposure explicitly. With a Defense Secretary's license confirmed in the set and government credential types reported by ACS, assume that senior staff, security-cleared personnel, and anyone with elevated access have had their ID imagery exposed. Pre-brief help desks and identity teams that voice or document-based verification of these individuals is now compromised, and escalate their account recovery paths to hardened, out-of-band procedures.
  6. Harden account recovery against knowledge-based and document-based attacks. Name, address, date of birth, and a matching license photograph are now available to purchase for a large share of the North American adult population. Any recovery flow that treats those as secrets is effectively open. Audit call center scripts and self-service recovery for this specific failure mode.
  7. Monitor for follow-on activity rather than waiting for notification. Because no breach notification has been issued and the record count remains disputed, individual notification may be slow or incomplete. Watch for synthetic identity applications, account takeover attempts citing verified ID, and new-account fraud patterns in your own environment, and track the FBI New Orleans inquiry and any subsequent IDScan.net statement for confirmed scope.

Sources: Nexus ID Breach Exposes a Blueprint for Fraud, Experts Warn | FBI Probes Service Selling 153M+ Drivers Licenses | 153 Million Driver License Images Offered on Dark Web | Dark Web Service Nexus Sells 153M+ Driver's Licenses | It sure looks like hackers breached a major ID card verification se... | FBI probes report of data breach exposing millions of drivers ... | 153 million driver licences exposed on dark web Information Age ACS | It Appears Hackers Have Compromised a Key ID Card Verification Serv...