A dark web identity theft service called Nexus surfaced in late August 2026 offering searchable access to digital scans of government-issued identity documents belonging to more than 153 million people in the United States and Canada, with the operators claiming roughly 170 million records overall. Brian Krebs broke the story on September 1 after finding his own Virginia driver's license posted as a free sample on the Russian cybercrime forum Exploit, and traced the likely source to Louisiana-based identity verification provider IDScan.net. The FBI's New Orleans field office opened a formal inquiry the same day, a step Reuters independently confirmed on September 2 and the New York Times also covered. One important clarification for readers: Nexus is the name of the criminal marketplace, not the breached company. The provider whose systems are believed to be the source is IDScan.net, which as of the latest reporting has issued no public statement.
What Happened
On Monday, August 31, a source alerted KrebsOnSecurity to a new vendor thread on Exploit advertising access to identity document scans covering more than 170 million people in North America. The seller claimed the material was being siphoned from an active, ongoing breach at a major identity verification company serving multiple Fortune 500 clients, and that the intrusion had been running for over a year. The Nexus site itself launched publicly the week of September 1.
Krebs verified authenticity by locating his own license, then those of other individuals who consented to be searched. Working with security researcher Zach Edwards, whose own ID was also in the set, he identified IDScan.net as the probable source. The company operates ID fraud prevention, age verification, access management, mobile scanners and an ID-activated door lock, and says it performs over 21 million verifications a month across more than 20,000 locations in roughly a dozen industries. SecurityAffairs lists Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment and Jack Henry among its customers; BleepingComputer notes deployments at car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries and hospitality venues.
Nexus was taken offline shortly after the Krebs article published, per SecurityWeek, but BleepingComputer notes the underlying database remains in criminal hands. Multiple lawsuits have since been filed in Louisiana, with law firms including Markovits, Stock & DeMarco and Hall Attorneys launching class action investigations. BleepingComputer states plainly that it is still unclear whether IDScan's systems were compromised or how many individuals are actually affected. Accounts on that point have not been reconciled by the company itself.
What Was Taken
Record counts vary by source and by what is being counted. The Exploit sales thread claimed roughly 170 million individuals' documents. Nexus itself advertised more than 153 million US and Canadian driver's licenses, more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards, per Krebs, with SecurityWeek rounding the medical card figure to roughly 580,000. Reuters described the exposure more conservatively as "tens of millions" of driver's licenses, and TechCrunch cited "more than 150 million" licenses and passports. Verification attempts also differ: Krebs reported that a blank search returned approximately 11.5 million pages at about 15 results per page, which implies a figure north of 170 million, while SecurityWeek characterised the same blank search as returning approximately 153 million results.
The geographic split skews heavily American. Canadian driver's licenses accounted for roughly 1.1 million records, with the largest concentration from Ontario at 473,673 records.
Growth rate estimates also differ. SecurityAffairs reports the total climbing by roughly 400,000 records per day at time of publication, while TechCrunch cites the Exploit advert claiming about half a million new documents added daily. Either figure implies near real time access to a live production system rather than a static historical dump.
The composition of each record is what elevates this above a conventional data breach. Per SecurityAffairs, each entry contains six images of the document: front and back captured in visible, infrared and ultraviolet light, plus a timestamp. Krebs matched his own record's timestamp to a June 2025 flight and car rental. The Nexus advert also stated that customer photos are displayed where available. Bitcoin.com News reports that Dr. Marilyne Ordekian characterised the infrared and ultraviolet captures as a security measure used to authenticate a physical document as genuine, meaning attackers hold not only the identity data but the technical layer used to prove a document is real. That expert framing comes from a single lower tier source and should be read as informed commentary rather than confirmed technical finding.
High profile individuals are in the set. Krebs reported that US Defense Secretary Pete Hegseth's driver's license was among the records offered for sale, alongside those of several other senior government officials. A Department of Defense spokesperson told TechCrunch it is "aware of these reports and is evaluating them."
Why It Matters
The core asymmetry is irreversibility. As Ordekian put it to Bitcoin.com News, a leaked password has an escape hatch because the credential can be reset. A driver's license photograph, home address and date of birth follow a person for years or permanently. There is no rotation procedure for a face.
Second, this is a concentration risk story. IDScan sits behind car rental counters, bank onboarding flows, dispensaries, gun shops and hotel check-in desks. A single provider aggregating 21 million verifications a month across 20,000 locations becomes a target of enormous value, and the downstream customers who fed it that data now carry the exposure without having been breached themselves. The Louisiana lawsuits allege exactly this, that IDScan failed to protect information belonging to clients such as Hertz.
Third, the presence of IR and UV captures raises the ceiling on what fraud is possible. Most identity verification stacks treat a document scan as proof of possession. If attackers hold the multispectral reference imagery for a genuine document, remote verification flows that rely on document imagery alone become substantially less trustworthy. Bitcoin.com News reports Sumsub's Popov arguing that ID checks now require a genuine second factor. That is a vendor voice with a commercial interest, but the underlying logic is sound and worth acting on regardless of who said it.
Fourth, the dwell time claim. If the operators are accurate that exfiltration ran for more than a year before detection, the failure was not perimeter security but the absence of egress monitoring on a high volume image store. Note this claim originates with the criminals and has not been independently confirmed.
The Attack Technique
The intrusion vector has not been disclosed by any source and IDScan has not confirmed a breach at all. What is observable is the behaviour rather than the entry point.
The operators describe an active, live breach rather than a one time dump, and the daily record growth of roughly 400,000 to 500,000 documents while the marketplace was online is consistent with that claim. That pattern suggests either persistent access to production infrastructure, valid credentials or API keys against a document storage backend, or a compromised integration partner sitting in the data flow. Full record structure including six spectral images and capture timestamps points at access to the primary verification pipeline or its archive, not scraped fragments assembled from multiple sources.
The monetisation model is notable in its own right. Rather than dumping the data, the actors built a searchable, index-driven identity theft service with per-record retrieval and free samples used as marketing on Exploit. That is a productised fraud supply chain, and it lowers the skill floor for downstream abuse considerably. Anyone treating this as a leak to be scraped is misreading it. It was a service.
What Organizations Should Do
- Inventory your identity verification supply chain. If you use IDScan or any third party KYC, age verification or ID capture vendor, determine exactly what document imagery they retain, for how long, and where. Many organizations do not know that full front and back multispectral scans are stored rather than discarded post verification.
- Push for retention minimisation contractually. Require vendors to delete document imagery after a successful verification unless a specific regulatory obligation requires retention, and require proof. Data that is not stored cannot be exfiltrated for a year.
- Stop treating a document scan as sufficient proof. Add a genuine second factor to identity verification flows: liveness detection with challenge response, cryptographically verifiable mobile driver's licences where available, or out of band confirmation against an authoritative source. Assume the attacker holds a perfect copy of the document.
- Instrument egress, not just ingress. Set volumetric alerting on document and image stores. A sustained outbound flow of hundreds of thousands of records per day should be a paging alert, not something discovered when a marketplace advertises it.
- Raise the bar on account recovery and high value onboarding. Fraud teams should expect synthetic and impersonation attempts backed by accurate name, address, DOB and photograph combinations. Knowledge based authentication against these fields is now effectively worthless for the affected population.
- Prepare notification and legal posture now if you are a downstream customer. With litigation already filed in Louisiana and an open FBI inquiry, organizations that routed customer IDs through the affected provider should get counsel and comms aligned before the scope becomes public rather than after.
Sources: Nexus ID Breach Exposes a Blueprint for Fraud, Experts Warn | FBI Probes Service Selling 153M+ Drivers Licenses | 153 Million Driver License Images Offered on Dark Web | Dark Web Service Nexus Sells 153M+ Driver's Licenses | IDScan sued over alleged data breach affecting 153 million drivers | It sure looks like hackers breached a major ID card verification se... | FBI probes report of data breach exposing millions of drivers ... | F.B.I. Investigates Sale of Millions of Stolen Driver's Licenses