ZeroHour
Cyber Security Newspublished ()ingested Guru Baran
Part of a story covered by 4 sources: “IDScan confirms cloud breach linked to dark-web 'Nexus' listing of 153M+ driver's license scans; FBI New Orleans opens formal investigation” — merged summary and timeline →

IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web

criticalData breach exploited in the wildimportance 92
AI summary · glm-5.3-flash

IDScan.net confirms a breach after a marketplace advertised over 153 million US and Canadian driver's licenses, possibly exfiltrated continuously for over a year.

The Louisiana identity-verification firm detected unauthorized access on or around September 1, 2026, after the 'Nexus' identity theft service on the Exploit forum began advertising 170M+ people's records, including 153M+ driver's licenses, 10M+ ID cards, 3M+ travel documents, and 579,000 medical cards. Canadian records exceed 1.1 million, and the trove includes commercial licenses, Common Access Cards, and dispensary IDs, with a record for US Defense Secretary Pete Hegseth reportedly included. Nexus operators claim continuous exfiltration for over a year, with the license count growing by nearly 400,000 in 24 hours, suggesting the intrusion may be active. The FBI's New Orleans field office has opened a formal inquiry, and IDScan.net is offering free credit monitoring.

  • Nexus claims continuous exfiltration for over a year; driver's license count grew by nearly 400,000 in 24 hours.
  • Trove spans US and Canadian documents, including commercial licenses, Common Access Cards, medical and dispensary IDs.
  • FBI's New Orleans field office opened a formal inquiry; IDScan.net is cooperating with law enforcement.
  • A record for US Defense Secretary Pete Hegseth was reportedly part of the leaked dataset.
  • Canadian records exceed 1.1 million, with nearly 474,000 from Ontario alone.
VendorsIDScan.net
Threat actorsNexus
VictimsIDScan.net
OrganizationsFBIExploit forum
Full article821 words · extracted from cybersecuritynews.com · click to collapse

IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500 clients, has confirmed a data breach after a criminal marketplace began advertising more than 153 million driver’s licenses from the United States and Canada.

The company disclosed that it detected unauthorized access to its systems on or around September 1, 2026, and immediately began securing its environment while bringing in third-party forensic specialists to determine the scope of the intrusion.

IDScan.net Data Breach

The breach came to light not through IDScan.net’s own disclosure timeline alone, but through investigative reporting from security journalist Brian Krebs, who was alerted on August 31 to a new identity theft service called “Nexus” being advertised on the Russian-language cybercrime forum Exploit .

The seller offered Krebs his own Virginia driver’s license as a free sample to prove the data was genuine, a tactic that ultimately helped researchers trace the leak back to a widely used identity verification vendor.

The Federal Bureau of Investigation’s New Orleans field office has since opened a formal inquiry into the source of the leaked images, and IDScan.net says it is cooperating with federal law enforcement.

Nexus claims to hold identity documents on more than 170 million people across North America, including upwards of 153 million driver’s licenses, over 10 million identification cards, more than 3 million travel and international documents, and at least 579,000 medical cards .

A blank search on the platform returned roughly 11.5 million results pages, a figure consistent with the advertised totals, and researchers found that Canadian records alone exceeded 1.1 million, with Ontario accounting for nearly 474,000 of them .

Notably, the trove includes commercial driver’s licenses, Common Access Cards used for government facility entry, and even marijuana dispensary identification cards, suggesting the stolen dataset spans a far broader swath of government-issued and regulated IDs than a typical retail breach.

Perhaps most alarming is the claim from the operators behind Nexus that they have been “continuously exfiltrating new data for over a year” into a private database, with customers able to preview redacted records and photos before purchasing full access.

Krebs observed the platform’s driver’s license count climb by nearly 400,000 records within a single 24-hour window, suggesting the breach may still be active rather than a one-time historical dump.

High-profile individuals have reportedly been swept up in the exposure as well, including a record for U.S. Defense Secretary Pete Hegseth, underscoring the national security implications of a leak touching government officials alongside ordinary consumers .

Incident ParameterDisclosed Technical Details & ScopeOperational & Risk Implications
Affected EntityIDScan.net (Louisiana-based identity verification provider)Outsources ID validation for retail, hospitality, and Fortune 500 clients
Exposed Database Size170M+ total records; 153M+ driver’s licenses, 10M+ ID cardsSpans US and Canadian documents (1.1M+ Canadian, ~474K in Ontario)
Document TypesDriver’s licenses, CAC government cards, medical & dispensary IDsExtends beyond consumer retail IDs to military and regulated credentials
Illicit Marketplace“Nexus” service advertised on Exploit forumOffers searchable previews with front/back, infrared, and UV scans
Breach Activity WindowContinuous exfiltration claimed over 1+ year; ~400K added in 24hActive intrusion rather than a static legacy repository leak
Law Enforcement & TriageFBI New Orleans field office formal inquiry; external forensicsMandatory credit monitoring offered; cloud account access investigated

In its official notice, IDScan.net stated that an unauthorized third party may have accessed or copied customer information stored in accounts on its cloud platform, primarily full names and driver’s license or other government-issued identification numbers.

The company noted that while full access to the stolen data on dark web marketplaces required payment, it is notifying potentially impacted individuals out of caution and offering free credit monitoring and identity protection services.

Affected individuals can enroll or ask questions by calling 1-833-516-2980 between 8 a.m. and 8 p.m. ET on weekdays, or by writing to the company’s Metairie, Louisiana address.

IDScan.net urges anyone notified of exposure to stay vigilant against identity theft and fraud by closely reviewing credit reports and account statements for unfamiliar activity or billing errors.

Because driver’s license numbers are often used to verify identity for financial accounts, government benefits, and even notarized transactions, security researchers recommend freezing credit files with major bureaus and monitoring for new account applications in one’s name.

The incident illustrates a growing risk in the identity verification industry itself: as more businesses outsource “know your customer” checks to third-party scanning vendors, a single compromised provider can expose sensitive identity documents belonging to millions of people who never directly interacted with the breached company.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/idscan-confirms-data-breach/