IDScan investigates suspected exposure of 150 million identity documents

Dark-web service claims access to identity documents
A suspected breach involving identity-verification provider IDScan may have exposed more than 150 million driver’s licences and passports belonging to people in the United States and Canada. The allegation emerged after the dark-web service Nexus advertised searchable identity records, claiming to add about 500,000 new documents each day from a major identity-verification company.
Independent security journalist Brian Krebs reported that the database contained authentic records after finding his own driver’s licence in its results. The listings could display customer photographs where available. Krebs also reported that US Secretary of Defense Pete Hegseth was listed on the service.
Working with security researcher Zach Edwards, whose identity document was also found in the database, Krebs identified Louisiana-based IDScan as the likely origin of the material. IDScan is used by technology and consumer brands to verify tens of millions of identity documents globally each month.
IDScan and the FBI are examining the allegation
IDScan chief operating officer Jillain Kossman told Krebs that the company was investigating. Chief executive Jimmy Roussel did not respond to a request for comment. Krebs also reported that the FBI field office in New Orleans was probing the suspected breach; the FBI did not immediately comment on the report.
Nexus went offline shortly after Krebs published his findings. Before it disappeared, an advertisement for the service on a Russian cybercrime forum said users could search the records and suggested the operators had near-real-time access to the verification provider’s systems. That claim has not been independently confirmed.
Document retention creates a high-value target
The incident allegation arrives as governments expand age-verification requirements that can require adults to upload an identity document before accessing a website or application. Identity checks are also commonplace in physical settings, including bars, cannabis stores and car-rental bookings.
Security experts and privacy advocates have long warned that retaining large collections of identity documents creates an attractive target for attackers. A compromised licence or passport can expose far more persistent personal information than a password and cannot be changed as easily.
For organisations that collect identity documents or use third-party verification services, the practical implication is to review what records are retained, how long they remain accessible and what safeguards suppliers apply to those records. They should also ensure their incident-response processes account for the distinct risks of exposed government-issued identification.

