Security journalist Brian Krebs reported on September 1, 2026, that a suspected massive data breach at identity verification company IDScan may have exposed more than 150 million driver’s licenses and passports belonging to US and Canadian citizens. The breach came to light after a dark web identity theft site called Nexus launched this week, claiming to offer searchable access to the stolen documents, including customer photos when available.
Krebs, who runs the security blog KrebsOnSecurity, said he confirmed his own driver’s license was among the searchable records, validating the authenticity of the leaked data. The report also noted that Secretary of Defense Pete Hegseth’s photo was listed on the site, though a Department of Defense spokesperson did not immediately comment.
Also read: X Moves All US Creator Payouts to X Money, Dropping Stripe for Instant Payments
The suspected source: IDScan
Working with security researcher Zach Edwards, whose ID was also compromised, Krebs identified the likely source of the breach as IDScan, a Louisiana-based company that verifies government-issued identity documents for major tech and consumer brands worldwide. IDScan processes tens of millions of identity verifications each month, making it a prime target for cybercriminals seeking large volumes of sensitive personal data.
IDScan’s chief executive Jimmy Roussel did not return TechCrunch’s request for comment, but chief operating officer Jillain Kossman told Krebs that the company was investigating the incident. The FBI’s field office in New Orleans is also reportedly probing the breach, though an FBI spokesperson did not respond to inquiries.
Also read: Apple Maps Renames Lake Ontario to 'Lake America' for U.S. Users, Following Google
The Nexus site, which advertised on a known Russian cybercrime forum, claimed to add about half a million new documents daily, suggesting the hackers had near real-time access to IDScan’s systems. The site went offline shortly after Krebs’s report was published, a common tactic to avoid scrutiny and preserve the stolen data for future use.
Why this breach matters for identity verification
This incident highlights the growing risks associated with the proliferation of age verification laws and the reliance on third-party identity verification services. Governments worldwide are increasingly requiring adults to upload government-issued IDs to access websites and apps, particularly for age-restricted content and purchases. Security experts and privacy advocates have long warned that storing vast amounts of identity documents for extended periods creates a honeypot for hackers.
The breach is believed to be the largest known single theft of identity documents in recent years, surpassing previous incidents that affected millions of records. The data includes not only names and ID numbers but also photos, which can be used for identity fraud, synthetic identity creation, and bypassing biometric security measures.
For consumers, the exposure of driver’s licenses and passports raises the risk of financial fraud, tax identity theft, and even criminal impersonation. The stolen data can be used to open bank accounts, apply for loans, or obtain government benefits in victims’ names.
What to watch for next
As investigations continue, IDScan customers and affected individuals should monitor for official breach notifications and consider placing fraud alerts on their credit files. The FBI’s involvement suggests a federal investigation is underway, which could lead to charges if the perpetrators are identified.
This breach also reignites the debate over data minimization and retention policies. Companies that collect identity documents should consider deleting data after verification is complete, rather than storing it indefinitely. Regulatory bodies may face increased pressure to mandate stricter data protection standards for identity verification services.
The full scope of the breach may not be known for some time, but the incident serves as a stark reminder that the convenience of digital identity verification comes with significant privacy and security trade-offs. As more services require ID uploads, the potential for large-scale data theft will only grow.
This article is for informational purposes only and does not constitute financial, legal, or security advice. The situation is developing, and details may change as investigations proceed.