A dark-web marketplace offering access to more than 153 million driver’s license scans has now been linked to a breach involving identity-verification provider IDScan.net.
The Louisiana-based company said an unauthorized third party may have accessed or copied information stored in customer accounts on its cloud platform after it received reports of possible system tampering around Sept. 1.
The disclosure follows an investigation by cybersecurity journalist Brian Krebs, who connected an illicit search service known as Nexus to IDScan infrastructure. The marketplace reportedly offered access to millions of driver’s licenses and other identity documents from people across the U.S. and Canada.
Krebs traced Nexus data back to IDScan
The vendor disclosed the security lapse in an advisory dated Sept. 4, stating that it “received information” on or around Sept. 1 indicating system tampering.
“While the investigation is ongoing, IDScan.net has determined that an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud,” IDScan noted, adding that exposed records may include names, driver’s license details, and other government-issued ID numbers.
The disclosure followed an investigation by cybersecurity journalist Brian Krebs, who traced a commercial illicit search platform dubbed “Nexus” back to IDScan’s servers. The underground service peddled access to over 153 million driver’s licenses, 10 million ID cards, 3 million travel papers, and 579,000 medical cards across the U.S. and Canada.
The records reportedly included ordinary consumers as well as senior federal officials, including Defense Secretary Pete Hegseth.
The FBI confirmed inquiries into the incident, while IDScan faces a wave of class-action litigation.
Why stolen identity documents create long-term risk
This breach exposes a structural flaw in modern commerce: consumers hand physical cards to frontline staff at car rental desks, dispensaries, or gun shops without ever learning which third-party cloud ingests their biometric portrait and credential barcodes.
When large identity-verification providers retain those records across many customers, a single breach can potentially expose credentials collected through businesses that victims may never have realized were connected to the same underlying platform.
Why stolen identity documents create long-term risk
The dark-web marketplace shuttered shortly after discovery, but criminal actors may still retain duplicated snapshots. With full scans and numbers compromised, victims face persistent risks of loan fraud, account takeovers, and synthetic identity schemes.
IDScan stated it is offering complimentary credit monitoring and identity repair. The firm advised individuals to check credit files, request fraud alerts, or initiate credit freezes directly with Equifax, Experian, and TransUnion.
Because compromised government-issued information can remain useful long after a breach, victims should also be cautious of unexpected identity-verification requests, loan applications, or account-recovery messages that rely on details taken from an ID.
Other news: Hackers are abusing trusted Google services to disguise phishing links that steal Microsoft credentials and, in some cases, install ScreenConnect for persistent remote access to victims’ devices.





