
If the reports are accurate, a major identity verification service may have suffered one of the most sensitive breaches in recent memory, exposing driver’s licenses, passports, and other government-issued ID documents collected from people in the United States and Canada. The alleged theft appears to involve a huge trove of real-world identity checks, the kind used at bars, cannabis dispensaries, car rental counters, and other places where businesses routinely ask customers to prove who they are.
The alleged breach centers on a dark web search site called Nexus
The story comes from independent security journalist Brian Krebs, who reported that a dark web site called Nexus appeared this week and claimed to offer searches across more than 150 million driver’s licenses and passports. According to the report, the records belonged to people in the U.S. and Canada, and the searchable database included customer images where available.
What makes the allegation especially alarming is the suggestion that the data may have been arriving continuously. A post advertising the site on a known Russian cybercrime forum said Nexus was adding about half a million new documents every day, allegedly sourced from a “major identity verification company.” If true, that would point to a breach that may have reached into live systems rather than a one-time historic leak.
Krebs said he found his own driver’s license in the searchable database, giving the claim a concrete and highly personal proof point. He also reported that Secretary of Defense Pete Hegseth was among the people whose photos were listed on the site. A spokesperson for the Department of Defense told TechCrunch that it is “aware of these reports and is evaluating them.”
How investigators traced the data to IDScan
Working with security researcher Zach Edwards, whose ID card was also reportedly stolen in the breach, Krebs identified the likely source as IDScan, a Louisiana-based identity verification company. According to the report, the company is used by major technology and consumer brands to verify tens of millions of people’s IDs around the world each month.
IDScan has not publicly confirmed that it was breached, and TechCrunch said chief executive Jimmy Roussel did not return a request for comment. However, the company’s chief operating officer Jillian Kossman told Krebs that the firm was investigating. Krebs also reported that the FBI’s field office in New Orleans is probing the incident. TechCrunch said a spokesperson for the FBI did not respond to its inquiry.
Shortly after Krebs’s report went live, Nexus went offline. That does not by itself prove anything, but the timing is consistent with a criminal service being disrupted, taken down, or temporarily hiding after attracting attention.
Why this kind of data is so valuable to attackers
Identity documents are a gold mine for criminals because they can be used for fraud long after a breach is discovered. A driver’s license or passport scan often contains a full name, home address, date of birth, document numbers, and a photo, which can be combined with other leaked information to impersonate victims.
In some cases, the documents are used directly in account takeovers, synthetic identity fraud, or scams that rely on passing remote verification checks. Because identity verification services often collect both the document image and a selfie or live photo, a leak can also expose biometric-style reference material that may be difficult or impossible to replace.
- Driver’s licenses can reveal name, address, date of birth, and license number.
- Passports can expose passport number, nationality, and other identifying details.
- Customer photos, when stored, add another layer of personal data that can be abused.
- Document scans may remain useful to criminals for years after the original theft.
Identity verification services are becoming a bigger target
The alleged breach lands at a moment when identity checks are becoming more common across the internet and in physical businesses. Governments and platforms are increasingly rolling out age-verification laws and policies that require adults to upload identity documents to prove they are old enough to access a website or app. That trend has made the collection of ID scans a routine part of doing business for more companies than ever before.
Security researchers and privacy advocates have warned for years that concentrating large volumes of identity documents in a single repository creates an obvious target. Unlike a password, a government ID cannot simply be reset. If a company stores these documents for long periods of time, a successful intrusion can turn a narrow operational breach into a long-lasting privacy disaster.
That concern is especially acute when the data comes from real-world verification flows. People may hand over a license at a bar or dispensary with little expectation that the image will be retained, indexed, or later exposed through a cyberattack. The alleged Nexus database suggests that many consumers may never have realized how widely their documents had been copied and stored.
What the reports say and what remains unconfirmed
At this stage, the core claims come from reporting and from the dark web advertising described in the source material. Krebs said he verified that at least some of the records were authentic by locating his own driver’s license in the database. That adds weight to the allegation, but public confirmation from the company allegedly affected has not yet been provided in the source material.
It is also important to separate what has been reported from what has not. The available information does not yet prove exactly how the breach happened, whether the attacker had direct access to live systems, how long the data collection lasted, or whether every record in the database came from the same source. Those are the kinds of details investigators would need to confirm before a full technical picture emerges.
Still, even the narrower claims are serious. A database of more than 150 million identity document records, with fresh additions said to arrive daily, would represent an enormous concentration of sensitive personal data. The fact that the alleged records included photos makes the potential harm more immediate, because images can be used to support both identity theft and social engineering.
Why this may be one of the largest identity document breaches in years
By all accounts, the incident described in the report would be the largest known single breach of identity documents in some time. The scale matters not just because of the number of records, but because of the type of records involved. Government-issued IDs are among the most sensitive personal documents people hand over, and they are often shared with the assumption that they will be handled briefly and securely.
If the alleged breach is confirmed, it could renew scrutiny on how identity verification firms store, retain, and protect scans of licenses and passports. It could also sharpen the debate over whether laws and business practices are moving faster than the safeguards needed to support them. For now, the public picture is still developing, but the early signs point to a breach that could affect millions of people and create years of downstream fraud risk.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 3, 2026 at 1:52 am
9 views

