CTIPilot

IDScan.net / Nexus 153M+ driver's-license dark-web marketplace

incident · incident:idscan-net-nexus-driver-license-breach-2026-09

A dark-web identity-theft service (Nexus) sold 153M+ driver's-license/ID scans traced by Krebs on Security to identity-verification vendor idscan.net; FBI New Orleans field office opened a formal investigation 2026-09-01; class-action suits followed.

Aliases: Nexus dark web ID service

Coverage timeline
1
first 2026-09-06 → last 2026-09-06
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-06/idscan-net-nexus-driver-license-dark-web-breach · ATT&CK page ↗

Story timeline

  1. 2026-09-06A dark-web identity-theft storefront sells 153 million+ driver's-license scans traced to identity-verification vendor IDScan.net; FBI opens a formal investigation
    active-threatsVictim-timestamp correlation, not vendor detection, exposed a year-long exfiltration from an ID-verification vendor used at 20,000+ locations worldwide

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (33%)
  • krebsonsecurity.com1 (33%)
  • securityweek.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about IDScan.net / Nexus 153M+ driver's-license dark-web marketplace (1)

2026-09-06 · view entry permalink →

NOTABLENATOB2

A dark-web identity-theft storefront sells 153 million+ driver's-license scans traced to identity-verification vendor IDScan.net; FBI opens a formal investigation

A dark-web identity-theft storefront called Nexus appeared on the Russian cybercrime forum Exploit around 2026-08-31, advertising searchable access to more than 153 million U.S. and Canadian driver's-license scans, 10 million ID cards, 3 million travel documents and 579,000 medical cards; Krebs on Security observed the driver's-license count grow by nearly 400,000 records over the 24 hours before publication (Krebs on Security, 2026-09-01). Krebs on Security verified the data against volunteers' own licenses: each record carries six image files (front and back, plain, infrared and ultraviolet scans) with an embedded capture timestamp; of more than a dozen volunteers whose licenses were checked, nine were found in the database, and each of those nine had a timestamp matching a point where they had physically handed a license to a clerk operating a document-scanning terminal, at a car-rental counter or a cannabis dispensary among the observed examples. That scanning technology traces to IDScan.net, a Louisiana-based identity-verification vendor whose own documentation states its systems perform more than 21 million verifications a month at more than 20,000 locations worldwide (Krebs on Security, 2026-09-01); the Nexus operators themselves claimed to have been continuously exfiltrating new data for over a year. IDScan.net has acknowledged it is investigating the matter but had issued no public statement naming a root cause as of this writing.

The FBI's New Orleans field office opened a formal investigation on 2026-09-01, confirmed directly to Krebs by FBI cyber-division leadership on a briefing call (Krebs on Security, 2026-09-01) and independently to Reuters (BleepingComputer, 2026-09-04); the Nexus service went offline within hours of Krebs's story publishing (Krebs on Security, 2026-09-01), though the underlying dataset remains in criminal hands (BleepingComputer, 2026-09-04). By 2026-09-04, multiple U.S. law firms had opened class-action investigations, and IDScan reportedly began notifying some business customers around 2026-09-01 (BleepingComputer, 2026-09-04).

This is a vendor-concentration and data-retention failure, not a classic network intrusion narrative: IDScan.net retained multi-year, multi-modal document scans captured at thousands of downstream client locations, and the exposure surfaced through independent victim-side timestamp correlation, not vendor detection, by the operators' own account, exfiltration had run undetected for over a year. No access vector into IDScan.net's own systems has been confirmed publicly by any party.

We have been continuously exfiltrating new data for over a year into our private database

Nexus service operator, quoted by Krebs on Security

the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.

Krebs on Security, citing idscan.net's own documentation

Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.

Krebs on Security 2026-09-01

A threat actor this week started offering on the dark web digital scans of over 153 million US and Canadian driver’s licenses.

SecurityWeek 2026-09-03
incident06 Sep 04:50Zmulti-sourceOpen finding ↗