2026-09-06 · view entry permalink →
A dark-web identity-theft storefront sells 153 million+ driver's-license scans traced to identity-verification vendor IDScan.net; FBI opens a formal investigation
A dark-web identity-theft storefront called Nexus appeared on the Russian cybercrime forum Exploit around 2026-08-31, advertising searchable access to more than 153 million U.S. and Canadian driver's-license scans, 10 million ID cards, 3 million travel documents and 579,000 medical cards; Krebs on Security observed the driver's-license count grow by nearly 400,000 records over the 24 hours before publication (Krebs on Security, 2026-09-01). Krebs on Security verified the data against volunteers' own licenses: each record carries six image files (front and back, plain, infrared and ultraviolet scans) with an embedded capture timestamp; of more than a dozen volunteers whose licenses were checked, nine were found in the database, and each of those nine had a timestamp matching a point where they had physically handed a license to a clerk operating a document-scanning terminal, at a car-rental counter or a cannabis dispensary among the observed examples. That scanning technology traces to IDScan.net, a Louisiana-based identity-verification vendor whose own documentation states its systems perform more than 21 million verifications a month at more than 20,000 locations worldwide (Krebs on Security, 2026-09-01); the Nexus operators themselves claimed to have been continuously exfiltrating new data for over a year. IDScan.net has acknowledged it is investigating the matter but had issued no public statement naming a root cause as of this writing.
The FBI's New Orleans field office opened a formal investigation on 2026-09-01, confirmed directly to Krebs by FBI cyber-division leadership on a briefing call (Krebs on Security, 2026-09-01) and independently to Reuters (BleepingComputer, 2026-09-04); the Nexus service went offline within hours of Krebs's story publishing (Krebs on Security, 2026-09-01), though the underlying dataset remains in criminal hands (BleepingComputer, 2026-09-04). By 2026-09-04, multiple U.S. law firms had opened class-action investigations, and IDScan reportedly began notifying some business customers around 2026-09-01 (BleepingComputer, 2026-09-04).
This is a vendor-concentration and data-retention failure, not a classic network intrusion narrative: IDScan.net retained multi-year, multi-modal document scans captured at thousands of downstream client locations, and the exposure surfaced through independent victim-side timestamp correlation, not vendor detection, by the operators' own account, exfiltration had run undetected for over a year. No access vector into IDScan.net's own systems has been confirmed publicly by any party.
We have been continuously exfiltrating new data for over a year into our private database
the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.
Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.
A threat actor this week started offering on the dark web digital scans of over 153 million US and Canadian driver’s licenses.