A dark web identity theft service calling itself Nexus surfaced on the Russian-language cybercrime forum Exploit in late August 2026, advertising searchable access to digital scans of government-issued identity documents on roughly 170 million people across North America. The headline figure inside that total is more than 153 million US and Canadian driver's licenses, each reportedly stored as a six-image set capturing the front and back of the card in visible, infrared, and ultraviolet light. KrebsOnSecurity broke the story on September 1 and reported the same day that the FBI's New Orleans field office had opened a formal inquiry into the source of the images. The suspected origin is IDScan.net, a Louisiana-based identity verification provider, which has told customers it is investigating reports that data may have been exposed. As of this writing IDScan.net has not confirmed a breach, and the 153 million and 170 million figures are the sellers' claims, not a verified count of unique victims.
What Happened
The timeline is tight. On Monday, August 31, a source alerted Brian Krebs to a new Exploit user advertising access to identity document scans on more than 170 million people in North America. The seller's pitch was aggressive enough to include Krebs' own Virginia driver's license as a free sample in the initial sales thread. Nexus itself went live on September 1, and the FBI's New Orleans office opened its inquiry the same day.
Krebs did not take the seller's word for it. A blank search against Nexus with no parameters returned approximately 11.5 million pages of results at roughly 15 results per page, which lines up with the advertised 153 million. He then searched for licenses belonging to more than a dozen friends and family members with their permission and found nine of them. The timestamps on those records matched days when those people had rented cars, visited a cannabis dispensary, or otherwise handed an ID to a business that scans documents. Krebs' own record carried a timestamp matching a June 2025 flight and car rental. TFTC, summarising the same reporting, put the caveat plainly: the 153 million figure belongs to Nexus and is not a confirmed victim count, but the corroboration was strong enough to rule out a fabricated database posted for attention.
Working with security researcher Zach Edwards, whose own ID card appeared in the data, Krebs traced the likely source to IDScan.net. Information Age reports that the trail ran through third parties including Hertz and the cannabis dispensary chain Planet 13, both of which appear in IDScan.net's customer and partner lists. Security Affairs adds Target, FedEx, Motorola Solutions, Caesars Entertainment, and financial services firm Jack Henry to the roster of IDScan.net clients. TFTC notes the company's own published scale: more than 21 million verifications per month across more than 20,000 locations, using scanners that read documents under infrared and ultraviolet light, precisely the image types found attached to Nexus records.
The exposure is not limited to private citizens. Krebs reported that the driver's license of US Defense Secretary Pete Hegseth was among the records available, one of several high-ranking government officials found in the set. A Department of Defense spokesperson told TechCrunch the department is "aware of these reports and is evaluating them."
By Tuesday evening the Nexus site had gone dark. Both Information Age and TFTC report its login page was replaced with the message "This service is no longer available." Whether that reflects law enforcement pressure, operational security, or a planned rebrand is unknown. The data does not disappear with the storefront.
What Was Taken
The composition of the claimed dataset is consistent across the reporting, and it is the qualitative content rather than the raw count that makes this incident unusual.
- More than 153 million US and Canadian driver's licenses. The bulk are American; Krebs found roughly 1.1 million Canadian licenses, with the heaviest concentration in Ontario at 473,673 records.
- More than 10 million additional identification cards.
- More than three million travel documents and international IDs.
- At least 579,000 medical cards. Information Age and iDropNews both note marijuana dispensary cards among the document types.
- Information Age additionally reports roughly 600,000 Common Access Cards, employment authorisations, or residence cards. That figure appears in that source alone and should be treated as a single-source claim.
Each driver's license record reportedly contains six images: front and back under visible, infrared, and ultraviolet light, plus a capture timestamp. The Exploit advertisement stated that "customer photos are displayed if available" and that records could be previewed before purchase with pertinent information redacted.
Dr. Marilyne Ordekian, the cybersecurity researcher who reviewed the material, told Bitcoin.com News that the reported contents include photographs, home addresses, and dates of birth alongside the UV and IR imagery. Her framing is the one defenders should internalise: with a password breach there is an escape hatch, because you reset the credential and move on. Government identity documents contain attributes that follow a person for years or permanently, and they cannot be reset. Ordekian described the infrared and ultraviolet scans as "a security measure used to verify authenticity," used "to authenticate a physical document as genuine," and warned that criminals now potentially hold not just the ID but the blueprint and the technical layer used to prove it is real.
Where Accounts Differ
Two figures diverge across the reporting and neither should be quietly rounded away.
Total record count. The 170 million figure is the count of people covered by the seller's full advertised set of identity documents, reported by Krebs, Security Affairs, atlas21, and Bitcoin.com News. The 153 million figure is specifically driver's licenses. Coverage that leads with one number or the other is describing different things, not disagreeing. TechCrunch, notably, characterised the offering as "more than 150 million driver's licenses and passports," a slightly looser framing than the itemised breakdown in the other sources.
Daily growth rate. Security Affairs, citing Krebs, reports the total was increasing by roughly 400,000 records per day at the time of publication. TechCrunch reports the Exploit advertisement claimed Nexus added "about half a million new documents daily." Both descriptions come from the operators' own claims rather than independent measurement, so the honest reading is a claimed accrual somewhere in the 400,000 to 500,000 per day range.
Attribution status. No source in this set is a confirmation from IDScan.net that it was breached. atlas21 reports the company told customers it was investigating information suggesting data may have been exposed and that it may be involved. Information Age describes a major identity services provider confirming it was investigating a security incident. TechCrunch reports that CEO Jimmy Roussel did not return its request for comment. The link between Nexus and IDScan.net rests on Krebs' victim interviews and timestamp correlation, which is strong circumstantial evidence, corroborated independently by Edwards, but it is not a victim admission and should not be written up as one.
Why It Matters
Identity verification vendors are a concentrated failure point, and this incident is what that concentration looks like when it fails. A single provider processing tens of millions of verifications monthly across more than 20,000 locations accumulates a dataset that no individual retailer, bar, dispensary, or rental counter could ever assemble on its own. The organisations that sent customers through IDScan.net checkpoints are downstream victims here too, and many of them are Fortune 500 brands with no direct visibility into how long those images were retained or where they lived.
The presence of infrared and ultraviolet captures raises the ceiling on what an attacker can do with this material. Standard document forgery has to guess at hidden security features. A forger holding authenticated UV and IR reference imagery for a real license does not have to guess. Ordekian's point about criminals obtaining "the technical layer used to prove" a document is genuine is the operative risk: this data degrades the reliability of document-image-based verification generally, not just for the individuals in the set.
Artem Popov, head of fraud prevention products at Sumsub, made the corollary argument to both atlas21 and Bitcoin.com News. A photograph of a document should never be the only element used for onboarding. He identifies liveness detection as the necessary second factor, confirming the person is physically present rather than replaying a stolen image set. Popov also flagged the permanence problem from the biometric angle: biometric data carries indefinite risk because it cannot be reissued after a compromise.
There is a policy dimension that at least one outlet raised directly. TFTC argues the incident is a predictable consequence of KYC and AML regimes that compel ordinary people to hand sensitive documents to private companies, which then pool them into high-value targets. That is an editorial position rather than a finding, but the structural observation underneath it holds regardless of where you land politically: mandated collection creates honeypots, and honeypots get cracked.
Finally, the presence of a sitting Defense Secretary and other senior officials in the dataset moves this out of pure consumer fraud territory and into a counterintelligence question. A searchable index of authenticated government ID imagery for high-ranking officials has obvious value to state actors, independent of whether anyone ever monetises it as fraud.
The Attack Technique
Root cause has not been established publicly, and no source in this set describes an initial access vector. What is on the record is the operators' own characterisation, and it is significant for defenders.
The Nexus operators claimed the data was continuously exfiltrated over the course of more than a year from a "major identity verification company" serving numerous Fortune 500 firms. The claimed daily growth of roughly 400,000 to 500,000 new documents implies near real-time access to a production system rather than a one-time dump. TechCrunch drew the same inference from the advertisement, noting the daily addition rate implies the attackers had ongoing access to the identity verification company's systems at the time of the sale.
Krebs' timestamp correlation supports the long-dwell theory. His own record carried a June 2025 timestamp, more than a year before the marketplace surfaced, and the records he verified for friends and family matched specific real-world ID-scanning events spread across time. That pattern is consistent with a persistent pipeline harvesting from a live document store or processing path, not with a single smash-and-grab against a backup.
Treat the following as the working hypothesis rather than confirmed fact: a compromise of a document processing or storage tier at an identity verification provider, undetected for roughly twelve months or more, with steady exfiltration continuing up to and possibly past the point of public exposure. The FBI investigation, opened September 1 out of New Orleans, remains open.
What Organizations Should Do
Inventory your identity verification supply chain. Determine which vendor or vendors scan IDs on your behalf, at which physical locations, what image formats they capture including IR and UV, how long they retain those images, and where retention is contractually bounded. If you cannot answer the retention question today, that is your first finding.
Stop treating a document image as sufficient proof of identity. Popov's guidance is the practical takeaway from this incident. Add liveness detection or another factor that confirms physical presence, so that possession of a stolen image set, however authentic, is not enough to complete onboarding or account recovery.
Raise the bar on account recovery flows specifically. Help desk and self-service recovery paths that accept a photographed license as identity proof are now the softest target in most enterprises. Attackers holding front, back, IR, and UV imagery plus name, address, and date of birth can satisfy most knowledge-based checks outright. Introduce out-of-band verification for high-value account changes.
Query your vendor directly and in writing. Ask IDScan.net or your equivalent provider whether your customer records are implicated, what the exposure window was, and what notification obligations they are assuming. atlas21 reports the company has been messaging customers about the investigation; if you have not received that communication and you are a customer, chase it.
Prepare for downstream fraud rather than credential stuffing. The threat model here is synthetic identity creation, account takeover via document-based recovery, and fraudulent lending or rental applications, not password reuse. Tune fraud detection for new-account patterns that use legitimate-looking document images with mismatched behavioural signals, and watch for velocity anomalies across your onboarding funnel.
Assume the data persists despite the takedown. Nexus disappearing behind a "this service is no longer available" notice removes a storefront, not a dataset. Build detection and response on the assumption that the material is in circulation and will resurface under another brand.
Sources: Nexus claims access to 170 million identity records | Dark Web Service Nexus Sells 153M+ Driver's Licenses | FBI Probes Service Selling 153M+ Drivers Licenses | It sure looks like hackers breached a major ID card verification se... | Nexus ID Breach Exposes a Blueprint for Fraud, Experts Warn | 153 million driver licences exposed on dark web Information Age ACS | 153 Million Driver's Licenses Leaked on Dark Web Nexus | The Identity Verification Honeypot Has Been Cracked Open · TFTC