On September 2, 2026, TechCrunch published a report by security journalist Brian Krebs that disclosed a massive data breach affecting the identity‑verification service IDScan. The breach, first seen on a dark‑web marketplace called Nexus, exposed more than 150 million driver’s licences and passports belonging to residents of the United States and Canada.
Scale of the breach
The Nexus site claimed to host “more than 150 million driver’s licences and passports belonging to people who live in the United States and Canada.”
"an identity theft site called Nexus, which launched on the dark web this week, claimed to allow users to search through more than 150 million driver’s licenses and passports belonging to people who live in the United States and Canada."The figure of 150 million is presented in the TechCrunch article as the total number of records available for search as of the breach disclosure date (September 2026). No further breakdown by country or document type is provided in the source.
How the breach was uncovered
Krebs’ investigation began when he discovered his own driver’s licence listed in the Nexus database. He wrote that finding his personal record “confirmed that the data was authentic.”
"Krebs found that his own driver’s license was among the searchable records in the database, confirming that the data was authentic."The authenticity of the data was further corroborated by the presence of a photo of Secretary of Defense Pete Hegseth, also listed on the site.
"Secretary of Defense Pete Hegseth was also among the people whose photos were listed on the identity search site."These confirmations give weight to the claim that the breach involved real, unaltered government‑issued IDs rather than fabricated data.
IDScan identified as the likely source
Working with security researcher Zach Edwards—who also had his ID card stolen in the breach—Krebs traced the leak back to IDScan, a company that provides real‑world verification of government‑issued identity documents for merchants, rental agencies, and other service providers. The TechCrunch piece notes that IDScan “is likely hacked and its vast stores of people’s ID cards were exfiltrated.”
"If you have handed over your driver’s license, passport, or other form of identity document to verify your information in the real world, like at a bar, a weed store, or when booking a car rental, there’s a good chance it’s now been stolen in a suspected massive data breach. That’s according to a jaw‑dropping report by independent security journalist Brian Krebs, who says a company used to verify government‑issued identity documents in the real world was likely hacked and its vast stores of people’s ID cards were exfiltrated."IDScan’s chief operating officer, Jillian Kossman, confirmed to Krebs that the company was investigating the incident, while the chief executive, Jimmy Roussel, did not respond to a request for comment.
"IDScan chief executive Jimmy Roussel did not return TechCrunch’s request for comment, but the company’s chief operating officer Jillian Kossman told Krebs that the company was investigating."
Official response and open questions
The breach has attracted federal attention. A spokesperson for the FBI’s New Orleans field office confirmed that the bureau is “looking into the incident,” though no further details were released.
"The FBI’s field office in New Orleans is also probing the breach. A spokesperson for the FBI confirmed that the bureau is ‘looking into the incident,’ but declined to comment further."The Department of Defense is also aware of the breach, according to the TechCrunch article, but the agency has not provided additional commentary.
Several key questions remain unanswered. The exact proportion of U.S. versus Canadian records has not been disclosed. The timeline of the breach—when the data was exfiltrated, how long it remained on Nexus before the site went offline, and whether any other dark‑web forums have mirrored the data—has not been fully mapped. IDScan has not released a formal statement detailing the technical vector of the intrusion, the scope of internal controls that failed, or the steps it will take to remediate the breach.
Implications for identity‑verification services
The breach arrives at a moment when governments worldwide are tightening age‑verification laws that require citizens to upload the same types of ID documents that were stolen. The exposure of authentic driver’s licences and passports raises concerns about the security of centralized ID‑verification platforms that many businesses rely on for compliance.
For consumers, the breach means that personal identifiers—photos, document numbers, and other data points—could be used for identity theft, fraud, or targeted phishing attacks. The inclusion of a high‑profile official such as Secretary of Defense Pete Hegseth underscores that no individual is immune from exposure when their data is stored in a single, high‑value repository.
Regulators may look to this incident as a case study for future guidance on data‑handling practices for identity‑verification providers. The FBI’s involvement suggests that law‑enforcement agencies consider the breach a national‑security concern, given the potential for forged IDs to be used in illicit activities.
What remains unknown
- The precise number of records that were actually downloaded versus those merely listed on Nexus.
- Whether any of the exposed data has already been used in fraudulent transactions.
- The identity of the actors behind Nexus and whether they are linked to any known hacking groups.
- How many of the 150 million records are from the United States versus Canada.
- The timeline of IDScan’s internal detection—when the company first became aware of the breach.
Until these details emerge, businesses that rely on IDScan’s verification service will need to reassess their risk exposure and consider supplemental identity‑checking measures. Consumers should monitor credit reports and be alert for unsolicited communications that reference personal identification details.
As the investigation unfolds, the breach serves as a stark reminder that the convenience of real‑world ID verification carries a hidden cost: the concentration of millions of authentic government documents in a single digital vault creates a lucrative target for cyber‑criminals.
