Pull to refresh
Logo
Hackers had a live feed of a U.S. ID-scan company's data for over a year

Hackers had a live feed of a U.S. ID-scan company's data for over a year

New Capabilities

A dark web service sold scans of 153 million driver's licenses; the FBI is investigating IDScan.net

September 4th, 2026: Live-feed scale emerges

Overview

Updated 5 days ago

A dark web service called Nexus has been selling scans of more than 153 million driver's licenses from the U.S. and Canada. The images match the work of IDScan.net, a Louisiana company that verifies IDs for Hertz, Target, FedEx and others.

The attackers kept a live feed of every document IDScan.net scanned for over a year. The trove grew by nearly 400,000 records in a single day after the breach became public, and it includes infrared and ultraviolet images that can defeat the very sensors meant to catch fakes.

Why it matters

Stolen scans include infrared and ultraviolet images that can defeat the fake-ID detectors meant to catch fraud.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

153M+
Driver's license records listed on Nexus
Scans cover people in the U.S. and Canada and grew by roughly 400,000 records in 24 hours after the breach became public.
400K
Records added in one day
The growth suggests the attackers kept live access to new scans even after the service was exposed.
21M
Monthly verifications by IDScan.net
The company processes scans at more than 20,000 locations worldwide for brands including Hertz, Target and FedEx.
13+ months
Duration of suspected live access
A scan of journalist Brian Krebs's license is timestamped June 2025, roughly 13 months before the breach became public.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

June 2025 September 2026

5 events Latest: September 4th, 2026 · 1 week ago
Tap a bar to jump to that date
  1. Live-feed scale emerges

    Latest Revelation

    Reports detail the year-long live feed; trove grows by 400,000 records in a day before Nexus goes offline.

  2. KrebsOnSecurity publishes findings

    Revelation

    Investigation links the leaked data to IDScan.net; officials including Secretary Hegseth are among those exposed.

  3. Nexus service launches

    Incident

    Service appears on Exploit forum offering 153 million license scans with Krebs's license as a free sample.

  4. Continuous exfiltration begins

    Breach

    Attackers begin siphoning IDScan.net scans; a timestamped license dated June 2025 confirms the start.

Scenarios

1

FBI traces breach to IDScan.net; charges filed

Possible Resolves by Jun 1, 2027

Discussed by: KrebsOnSecurity, CSO Online

The FBI's New Orleans field office is actively investigating. If investigators confirm IDScan.net as the source and identify the attackers behind Nexus, the Justice Department would announce charges. The operators advertised on the Russian cybercrime forum Exploit, which complicates prosecution but has not stopped past takedowns of similar services.

2

IDScan.net confirms breach; faces enforcement and lawsuits

Likely Resolves by Mar 1, 2027

Discussed by: Techdirt, Proof analysts

IDScan.net has not confirmed unauthorized access. If the company acknowledges the breach, affected individuals and state attorneys general could file class actions and consumer-protection claims. The Federal Trade Commission could also open an enforcement action over data-security practices at a company handling sensitive identity documents.

3

Stolen scans defeat KYC checks in a wave of fraud

Possible Resolves by Sep 1, 2027

Discussed by: FreightWaves analysts Katie Edwards and Merul Dhiman

The Nexus files include infrared and ultraviolet images that authentication systems use to confirm documents are genuine. Analysts warn criminals could print fraudulent licenses carrying real data that pass digital checks, enabling cargo theft, account takeover, and impersonation at banks and hotels. The 400,000-record daily growth suggests the trove will keep expanding as long as attackers retain access.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

May–September 2017

Equifax data breach (2017)

Hackers exploited a web application flaw at Equifax and accessed the personal data of about 147 million Americans over several months, including Social Security numbers, birth dates, and addresses.

Then

Equifax's CEO resigned, Congress held hearings, and the company paid at least $575 million in a settlement with federal and state regulators.

Now

The breach became the benchmark for identity-data exposure, prompting the FTC to expand its data-security enforcement and states to tighten breach-notification laws.

Why this matters now

Like Equifax, IDScan.net concentrates sensitive identity data in one vendor. The breach shows the same concentration risk and the same pattern of delayed public disclosure.

September 2022

Optus data breach (2022)

Australia's second-largest telecom was breached, exposing driver's license and passport numbers for more than 10 million customers, including identity documents rather than just account data.

Then

Optus faced a class action and government criticism; the Australian government debated new rules on data retention and breach disclosure.

Now

The incident pushed regulators to treat physical identity documents in corporate databases as high-risk data warranting stricter handling rules.

Why this matters now

Optus set the precedent for breaches that expose government-issued identity documents. The Nexus leak goes further by including the infrared and UV scan layers used to verify authenticity.

Sources

(9)