Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
▣ Breach NEXUS-IDENTITY-VER 2026-09-19

IDScan.net: Dark Web Portal Nexus Sells 153M+ Identity Document Scans

"A dark web identity-theft service branded "Nexus" surfaced on the Russian-language cybercrime forum Exploit on August 31, 2026, advertising searchable access to scanned government identity documents covering upwards of…"

A dark web identity-theft service branded "Nexus" surfaced on the Russian-language cybercrime forum Exploit on August 31, 2026, advertising searchable access to scanned government identity documents covering upwards of 153 million people in the United States and Canada. KrebsOnSecurity broke the story and traced the likely source to IDScan.net, a New Orleans-based identity verification vendor whose customer list includes Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and financial services provider Jack Henry. Per Security Affairs, the FBI's New Orleans field office opened a formal investigation on September 1. Record counts vary by source: Krebs and Security Affairs cite 153 million driver's licenses, ZeroFox's flash report puts the actor's total claim at "over 160 million breached identity documents," and the seller's own launch thread quoted by Krebs boasted of data on "more than 170 million people in North America." Note also that despite the framing of this breach as an American exposure, the advertised corpus spans both U.S. and Canadian license holders, so the count of affected Americans is lower than the headline figure.

What Happened

On August 31, a source alerted KrebsOnSecurity to a new Exploit forum user advertising a custom portal. ZeroFox Intelligence identifies the actor handle as "databroker1" and characterizes them as untested, meaning the persona has no established reputation or transaction history on the forum. The Nexus portal was not a static dump for sale but a working search interface: prospective buyers could query the database and preview redacted identity documents before paying.

The seller's pitch included a free sample, and the sample chosen was Krebs' own Virginia driver's license, which he subsequently located in the database. That detail is what elevated the listing from an untested claim to something investigators took seriously within a day.

Attribution to a specific victim organization is assessed rather than confirmed by the threat actor. The seller referred only to an unnamed major identity verification provider and its enterprise clients, several of them Fortune 500 companies. ZeroFox assesses it is "very likely" IDScan.net; Krebs traced the data to the same company independently.

Accounts differ on IDScan.net's own posture, largely as a function of timing. As of ZeroFox's September 3 flash report, the company had made no public statement, though customers were posting on social media about receiving an email describing an investigation into a "potential security incident." Help Net Security's later coverage is headlined as IDScan confirming a breach. TechCrunch's framing remained hedged: "It sure looks like hackers breached a major ID card" vendor. No regulator filing, vendor advisory, or national CERT bulletin appears among the available sources, so every element of this brief rests on press reporting and commercial threat intelligence rather than on primary disclosure.

ZeroFox reports the Nexus portal is no longer active, and assesses roughly even odds that the operator reactivates it after a cooling-off period once public scrutiny fades.

What Was Taken

The advertised inventory, consistent across Krebs, Security Affairs, and ZeroFox with minor rounding differences:

The sensitivity here is not in the row count but in the file format. Each record reportedly contains six images per license: front and back captured in visible light, infrared, and ultraviolet, each carrying a date and time stamp. IR and UV captures are the security-feature layers that banks, casinos, rental agencies, and border control use to distinguish a genuine document from a forgery. A stolen database of demographic text can fuel synthetic identity fraud; a stolen library of multispectral document captures gives a forger the reference material to defeat the verification step itself.

The timestamps are also an investigative artifact. Krebs reported that the timestamp on his own record corresponded to a June 2025 flight and car rental, tying individual captures to specific real-world transactions at specific merchants.

Why It Matters

Three things make this incident structurally worse than a conventional consumer data breach.

First, the data is non-rotatable. A driver's license number and the physical document behind it cannot be reset like a password or reissued like a card number without a trip to a state DMV and a new document number. The exposure window for any individual record is effectively the remaining life of that license.

Second, the compromise targets the control layer rather than the data layer. Identity verification vendors exist to be the trusted checkpoint between a customer and a high-value transaction. When the checkpoint's own evidence library leaks, every downstream control that depends on document authentication weakens at once, across every client of that vendor simultaneously.

Third, the exfiltration was reportedly ongoing, not historical. Both Krebs (via Security Affairs) and ZeroFox report the actor claimed persistent access maintained for over a year, with the corpus still growing at the time of publication. Daily growth figures differ by source: roughly 400,000 records per day per Security Affairs' account of the Krebs reporting, and approximately 500,000 documents per day per ZeroFox. Either figure implies a live collection pipeline rather than a one-time smash and grab. ZeroFox explicitly assesses the claimed persistence makes this an ongoing threat to personal identity data, not a closed event.

For any organization that outsources KYC, the practical lesson is that vendor scale is a liability multiplier. One compromised aggregator produces a breach larger than most of its clients could ever suffer on their own.

The Attack Technique

Initial access is not established in any of the available sources. The actor's own claim, reported consistently by ZeroFox and by Krebs via Security Affairs, is persistent access to an identity verification provider and to that provider's enterprise clients, sustained for more than a year with continuous exfiltration. That claim comes from the seller, not from a forensic report or an incident response finding, and should be treated as an unverified assertion by an untested forum persona.

What the data itself suggests is more concrete. Records containing IR and UV captures, six images per document, are the native output of physical ID scanning hardware deployed at points of service such as rental counters, casino floors, and retail age-verification stations. Krebs' record aligning with a June 2025 flight and car rental points toward collection at or through those capture endpoints and their upstream processing pipeline, rather than toward a single database theft. The claim of access to "enterprise clients" alongside the vendor is consistent with a compromise of the shared platform or its client-facing integration layer, but no source confirms which. Credit Cards House frames the harvesting pattern the same way based on the image and timestamp forensics, though as a single OTHER-tier source that reading is corroborative rather than independent.

No CVE, malware family, or intrusion vector has been published.

What Organizations Should Do

  1. Inventory your identity verification dependencies. Determine whether your organization uses IDScan.net directly or through a reseller, integrator, or point-of-sale platform, and whether scanned documents from your customers were retained by the vendor rather than processed and discarded. If you received a "potential security incident" notice, escalate it to a formal vendor incident review rather than filing it.
  2. Stop treating document authenticity as sufficient proof of identity. Where document scans currently gate high-value actions such as account recovery, credit issuance, or SIM changes, add a second uncorrelated factor: liveness detection, out-of-band verification against an authoritative issuer, or transactional history checks. Assume an attacker may hold a perfect multispectral copy of the genuine document.
  3. Tighten account recovery and help desk workflows now. These are where stolen identity documents get monetized fastest. Require step-up verification that cannot be satisfied by presenting a document image, and instrument recovery attempts for anomaly detection.
  4. Push retention limits into vendor contracts. Require that scanned identity documents, especially IR/UV captures, be deleted after verification completes, with contractual audit rights and breach notification timelines. A vendor that keeps a multi-year image archive is building the exact asset that was advertised here.
  5. Monitor for reactivation. ZeroFox gives roughly even odds that the Nexus portal returns after the attention fades. Feed the Nexus branding, the databroker1 handle, and Exploit forum activity into dark web monitoring, and re-check whether your customer population appears in any relaunched instance.
  6. Prepare customer-facing guidance in advance. Affected individuals cannot rotate the exposed credential. The realistic advice is credit freezes, fraud alerts, heightened scrutiny of account recovery attempts, and awareness that in-person identity fraud using replica documents is now materially easier. Draft that messaging before you need it.

Sources: The Nexus Breach: How a Massive Identity Verification Failure Expos... | FBI Probes Service Selling 153M+ Drivers Licenses | Dark Web Service Nexus Sells 153M+ Driver's Licenses | 153 Million Driver License Images Offered on Dark Web | It sure looks like hackers breached a major ID card ... | IDScan confirms breach after 153 million driver's licenses ... | F.B.I. Investigates Sale of Millions of Stolen Driver's Licenses | Flash Report: Threat Actor Claims Access to Identity Data ZeroFox