IDScan Confirms the Breach Behind Nexus's 153 Million IDs
Security / news
IDScan Confirms the Breach Behind Nexus's 153 Million IDs
Brian Krebs traced dark-web listings of driver's licenses to the identity-verification vendor's cloud platform, and the FBI opened a probe the same day his report went up.

IDScan.net confirmed Sept. 8 that an unauthorized party had accessed its cloud platform, a week after security reporter Brian Krebs traced a dark-web service selling more than 153 million U.S. and Canadian driver's licenses back to the identity-verification vendor.
Krebs wrote Sept. 1 on Krebs on Security that a service called Nexus, advertised on the Russian cybercrime forum Exploit, was selling the licenses alongside more than 10 million identification cards, more than three million travel documents and at least 579,000 medical cards. A blank search on the site returned about 11.5 million pages of results, which Krebs said supported Nexus's own count. The seller told Krebs it had "been continuously exfiltrating new data for over a year," and the listed license total grew by nearly 400,000 records in a single day while he watched it.
How Krebs traced the leak to IDScan.net
Krebs matched infrared and ultraviolet scan pairs in the leaked images, a signature of IDScan's kiosks, to specific transactions: license photos captured at Hertz rental counters and at marijuana dispensaries that use IDScan hardware to check customer age. IDScan says its scanners perform more than 21 million verifications a month at more than 20,000 locations for clients including Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment, plus more than 1,000 dispensaries in 19 states.
Searching Nexus for Canadian licenses alone returned about 1.1 million results, with the largest share, 473,673, from Ontario.
Who's exposed, and who's investigating

Krebs found a listing for the driver's license of U.S. Defense Secretary Pete Hegseth, one of several senior government officials whose licenses turned up in the database. He wrote that the FBI added him to a call with a half-dozen agents, including leaders from its cyber division, the same day its New Orleans field office opened a formal investigation into IDScan.net.
The disclosure lands the same month CISA flagged critical, unauthenticated bugs in Cisco's Secure Email Gateway and ConnectWise's ScreenConnect as under active exploitation, a reminder that a single vendor's back-end platform can expose far more than the product a customer thinks they are using.
What IDScan is offering, and what it isn't saying
IDScan said in its Sept. 8 notice that an unauthorized party "may have accessed and/or copied certain customer information, including full names and drivers license or other government-issued identification numbers," and that it is offering free credit monitoring and identity protection to those affected. In a separate statement reported by Help Net Security, IDScan said it "took immediate steps to secure our systems and engaged a team of third-party specialists" and is cooperating with federal law enforcement. Jillian Kossman, IDScan's marketing and operations leader, told Krebs the company could not share further detail while its investigation continued.
IDScan has not said which of its systems or locations was the point of entry, how the intruders got in, or whether the year-long exfiltration Nexus described matches its own internal timeline. The FBI's New Orleans field office has not said when its investigation will conclude.
| Document type | Records listed on Nexus |
|---|---|
| Driver's licenses (U.S./Canada) | 153 million+ |
| Identification cards | 10 million+ |
| Travel documents | 3 million+ |
| Medical cards | 579,000+ |
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.