Massive ID Document Data Breach Suspected After Dark Web Site Emerges with 150M Records

Identity verification company IDScan under scrutiny as hackers claim real-time access to driver's licenses and passports

edit
By LineZotpaper
Published
Read Time2 min
A dark web site called Nexus has appeared offering searchable access to over 150 million driver's licenses and passports, mostly from the United States and Canada, and security researchers believe the data was stolen from IDScan, a Louisiana-based identity verification company used by major consumer brands. The site went offline shortly after the story broke, and the FBI is investigating.

A security researcher has uncovered what appears to be a major data breach of an identity document verification service, with criminals offering access to more than 150 million driver's licenses and passports on the dark web.

According to a report by independent security journalist Brian Krebs, a dark web site called Nexus launched this week claims to let users search through a vast database of identity documents belonging to people in the U.S. and Canada. A post advertising the site on a known Russian cybercrime forum said Nexus adds about half a million new documents daily, implying the hackers have near real-time access to the verification company's systems. The advert also states that “customer photos are displayed if available.”

Krebs confirmed the data's authenticity by finding his own driver's license among the records. Secretary of Defense Pete Hegseth was also listed with his photo on the site.

A spokesperson for the Department of Defense told TechCrunch it is “aware of these reports and is evaluating them.”

Working with security researcher Zach Edwards, whose ID was also stolen, Krebs identified the likely source as IDScan, a Louisiana-based identity verification service. IDScan is relied on by major tech and consumer brands to verify tens of millions of people's IDs worldwide each month.

IDScan CEO Jimmy Roussel did not respond to TechCrunch's request for comment, but the company's COO Jillian Kossman told Krebs the company is investigating. The FBI's field office in New Orleans is also probing the breach, according to Krebs, though an FBI spokesperson did not confirm the investigation to TechCrunch.

Nexus went offline shortly after Krebs' report was published.

The breach comes as governments increasingly roll out age-verification laws that require uploading identity documents. Security experts and privacy advocates have long warned that storing vast amounts of personal IDs creates a major security risk. By all accounts, this would be the largest known single breach of identity documents in recent years.

§

Analysis

Why This Matters

  • Massive scale of exposure: Over 150 million driver's licenses and passports, with half a million new documents added daily, means anyone who has submitted an ID to a bar, weed store, car rental, or online age-verification service could be affected.
  • Real-time access: The claim that hackers have ongoing, near real-time access to the verification company's systems suggests the breach is not a one-time dump but a persistent compromise.
  • Policy implications: This breach validates long-standing warnings from privacy advocates about the dangers of centralized ID storage, especially as age-verification laws expand.

Background

IDScan is one of many companies that verify government-issued identity documents for businesses that need to confirm a customer's age or identity in the physical world—such as bars, cannabis retailers, and car rental agencies. The company processes tens of millions of IDs each month for major brands. The dark web site Nexus, which launched this week, offered a searchable database of stolen records and claimed to be adding new documents daily. Security researcher Brian Krebs confirmed the data was real by finding his own driver's license in the database. The site went dark shortly after his report.

Key Perspectives

  • Security Researchers: The breach appears authentic and ongoing. Krebs and Edwards identified IDScan as the likely source based on data patterns. The claim of half a million new docs daily suggests deep, active access to IDScan's systems.
  • IDScan: The company's COO said it is investigating, but it has not confirmed or denied the breach. CEO Roussel did not comment.
  • Law Enforcement: The DoD is evaluating the reports; the FBI's New Orleans field office is probing the breach, according to Krebs.
  • Privacy Advocates: They have long warned that requiring ID uploads for age verification creates a high-risk central repository. This breach is a textbook example of that risk.

What to Watch

  • Whether IDScan confirms the breach and reveals how hackers gained access.
  • Any additional dark web postings or sales of the data, or ransom demands.
  • Legal and regulatory fallout, including potential class-action lawsuits and renewed debate over age-verification mandates.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.