A dark web identity theft service calling itself Nexus surfaced on the Russian-language cybercrime forum Exploit in late August 2026, advertising bulk access to scanned government identity documents covering roughly 170 million people across North America. The headline inventory: more than 153 million US and Canadian driver's licences, over 10 million identification cards, more than 3 million travel documents and international IDs, and at least 579,000 medical or health cards. KrebsOnSecurity, which broke the story on September 1 after the seller offered Brian Krebs's own Virginia licence as a free sample, reported that the New Orleans field office of the FBI opened an official inquiry into the source of the images that same day. Reporting across outlets converges on Louisiana identity verification vendor IDScan.net as the likely source, and Atlas21 reports the company told customers it was investigating information suggesting data may have been exposed and that it may be involved. As of publication no party has confirmed a breach on the record, and the record counts remain seller claims, not audited totals.
What Happened
The timeline is tight. On Monday, August 31, 2026, a new user on Exploit posted a sales thread for a service offering digital scans of identity documents on more than 170 million people in North America. Krebs was alerted to it because the seller had used his own driver's licence as the free preview. Records on the platform were browsable before purchase with "pertinent information redacted," according to the forum post quoted by ACS Information Age, and "customer photos are displayed if available."
Krebs published on September 1. SecurityWeek reported on September 3 that the Nexus platform was shut down shortly after that article went live, and ACS Information Age confirmed the former login page had been replaced with the message "this service is no longer available." SecurityWeek noted the FBI inquiry proceeded regardless of the takedown.
Attribution to IDScan.net came from ground-truthing rather than any disclosure. Krebs searched the data for consenting friends and family, then traced where those individuals had handed over ID documents around the time of compromise. The recurring touchpoints were third parties such as Hertz rental counters and the Planet13 cannabis dispensary chain, both of which pointed back to the same verification vendor. IDScan.net is a New Orleans firm selling ID fraud prevention, access management, age verification, ID-activated door locks and mobile scanners; per SecurityWeek it claims over 21 million verifications per month across more than 20,000 locations in roughly a dozen industries including banking and fintech, gaming, automotive, hospitality and law enforcement.
ACS Information Age frames the sequence as the listing appearing "days before a major identity services provider confirmed it was investigating a security incident." That is the closest thing to a victim-side acknowledgement in the available reporting, and it is an investigation notice, not a breach confirmation. SecurityWeek said it emailed IDScan for comment and had received no response at the time of writing.
What Was Taken
Treat every number here as a seller claim that partially survived spot-checking, not as a verified victim count.
The categories are consistent across sources: 153 million-plus US and Canadian driver's licences, 10 million-plus identification cards, 3 million-plus travel documents and international IDs, and 579,000 to roughly 580,000 medical or health cards. ACS Information Age adds a fifth category the other outlets do not list, roughly 600,000 Common Access Cards, employment authorisations or residence cards. Since that figure appears in a single non-primary source, treat it as unconfirmed.
The two aggregate figures in circulation do not reconcile cleanly. The Exploit advertisement and the follow-on coverage at Atlas21, Block Stream Media and The Crypto Post all cite roughly 170 million records or individuals. Krebs's own arithmetic points higher: a blank search on Nexus returned approximately 11.5 million pages at roughly 15 results per page, which works out to something north of 170 million rows, and he concluded the operators were "likely not exaggerating." SecurityWeek paraphrased the same blank-search test as returning "approximately 153 million results." Shattered.io makes the sharpest caveat and it is the right one: no reporting has established a single deduplicated combined total distinct from the four category figures, so the categories should be read as separate operator claims rather than a victim headcount. One person who handed a licence to two different merchants may appear more than once.
Geography is lopsided. Canadian driver's licences account for only about 1.1 million of the total per Krebs, with the largest single concentration in Ontario at 473,673 records. The overwhelming bulk is American.
The per-record contents are what elevate this above a routine dump. Cybersecurity researcher Dr. Marilyne Ordekian, quoted by Atlas21 and by Block Stream Media and The Crypto Post, described material including photographs, home addresses, dates of birth, and infrared and ultraviolet scans of the documents. Krebs reported that high-ranking US government officials are among the exposed, including the driver's licence of Defense Secretary Pete Hegseth. The CyberSec Guru additionally claims senior FBI leadership are in the set; that detail appears in only one non-primary source and should be treated as unverified.
Why It Matters
Ordekian's framing is the one defenders should internalise. "With breaches leaking passwords, one can reset their credentials and move on," she said. Government identity documents carry information that follows a person for years or permanently: the photograph, the home address, the date of birth. There is no rotation path.
The UV and IR scans are the genuinely novel exposure. Those captures exist to verify that a physical document is authentic, the security layer underneath the printed face. Ordekian's warning is that criminals hold "not just your ID, but also have the blueprint and the technical layer used to prove your ID is genuine." Her assessment of the blast radius: "Every ID-gated system, be it opening a bank account, a cryptocurrency exchange account, renting a car, verifying a wire transfer etc (anything that relies on this type of ID for identity verification) is now a potential attack surface which can be exploited."
Artem Popov, head of fraud prevention products at Sumsub, made the operational counterpart argument. A photograph of a document should never be the sole element in an onboarding decision, and liveness detection is needed to confirm a physical human is present. Popov also flagged the permanence problem from the biometric side: biometric data cannot be reissued after compromise.
There is a structural lesson underneath the fraud risk. If the attribution holds, the exposure did not come from any of the retailers, dispensaries, rental counters or banks where these documents were presented. It came from the shared verification layer sitting behind all of them. Consumers had no relationship with that vendor and no way to opt out of it. Every organisation that outsourced its KYC image handling inherited a concentration of risk it did not directly control, and the retention of scans after a verification decision has already been rendered is the part that turned a transient check into a permanent liability.
The Attack Technique
The intrusion method is not established. What exists is the sellers' own account and one detailed third-party theory.
The Nexus operators claimed on Exploit that the data was continuously exfiltrated over the course of roughly a year from a "major identity verification company" servicing numerous Fortune 500 clients, and that the breach was still active at the time of listing. That claim appears consistently across Krebs, SecurityWeek, ACS Information Age and the Block Stream Media and Crypto Post reporting, but it originates entirely with the threat actor and carries the usual credibility discount.
The CyberSec Guru published a longer technical account attributing the compromise to an API gateway and edge computing weakness at the vendor, reached through metadata forensics, timestamp analysis and cluster analysis that ruled out TSA as a source and isolated the point of failure. That analysis appears in a single non-primary outlet, is not corroborated by Krebs or SecurityWeek, and has not been confirmed by IDScan.net or the FBI. Do not build a detection hypothesis on it.
What the corroborated evidence supports is narrower and still useful: the victim-side pattern Krebs documented shows compromised individuals whose documents were captured at physically distinct merchants, which is consistent with collection at a centralised platform tier rather than at individual customer endpoints. The takedown of the marketplace after publication does not indicate the underlying access was closed.
What Organizations Should Do
- Inventory your ID-image supply chain. Identify every vendor, kiosk, door-access system, age-verification tool or onboarding SDK that captures or forwards government ID scans on your behalf, including systems procured by individual store locations rather than corporate IT. If you use IDScan.net or a reseller of its hardware or software, contact them directly for incident status rather than waiting for a notification.
- Stop treating a document image as proof of identity. Per Popov's guidance, add liveness detection so onboarding confirms a physically present human, and pair document capture with an independent signal. Assume an attacker presenting a pixel-perfect front, back, IR and UV capture of a real licence is now a realistic threat model, not a theoretical one.
- Purge retained scans and move to tokenized verification results. If a verification decision has been rendered, the underlying image is a liability with no remaining business value. Enforce short retention windows, store the pass/fail assertion rather than the artefact, and audit whether your vendors do the same.
- Prioritise transition to cryptographic and NFC-based document verification. Chip-based reads and digitally signed mobile credentials cannot be replayed from a stolen image the way a flatbed scan can. This is the only mitigation that structurally survives the UV/IR exposure.
- Raise scrutiny on high-value ID-gated flows now. Account opening, crypto exchange onboarding, wire verification, credit applications and rental fulfilment should get elevated manual review and step-up authentication for the foreseeable future, with particular attention to accounts opened using licences from Ontario and US states where concentration appears highest.
- Brief executives and cleared personnel individually. With a sitting Defense Secretary's licence reportedly in the set, organisations with senior officials, board members or security-cleared staff should assume targeted impersonation attempts and pre-establish out-of-band verification for any request that would normally be validated with an ID photo.
Monitor for further disclosure from IDScan.net and for FBI New Orleans output. Until a party with direct visibility speaks on the record, the record counts, the exfiltration window and the intrusion vector all remain claims rather than findings.
Sources: Nexus claims access to 170 million identity records | FBI Probes Service Selling 153M+ Drivers Licenses | 153 Million Driver License Images Offered on Dark Web | 153 million driver licences exposed on dark web Information Age ACS | Nexus Dark Web Service Sells 153M Driver Licenses 2026 | Nexus ID Breach Exposes a Blueprint for Fraud, Experts Warn – Block... | Nexus ID Breach Exposes a Blueprint for Fraud, Experts Warn - The C... | Nexus Breach: 153 Million Driver’s Licenses Exposed The CyberSec Guru