A service sold 153 million driver's licenses scraped from an identity verification vendor
Nexus, advertised on a Russian cybercrime forum, sold access to more than 153 million US and Canadian driver's licenses that its operators say they exfiltrated from IDScan.net over more than a year. The FBI opened an investigation.
Brian Krebs reported that a service called Nexus, advertised on the Russian-language cybercrime forum Exploit, was selling lookups against more than 153 million US and Canadian driver's licenses and other identity documents. Its operators claimed to have been "continuously exfiltrating new data for over a year" from IDScan.net, a Louisiana identity verification provider that processes over 21 million verifications a month for customers including Hertz, Target, FedEx, and cannabis dispensaries. The New Orleans FBI field office opened an investigation. IDScan.net confirmed on September 8, 2026 that an unauthorized third party may have accessed and copied certain customer information. Nexus went offline shortly after Krebs published.
Why it matters
Identity verification vendors sit in an uncomfortable position: to prove a document is genuine they must collect it, and to handle disputes they tend to retain it. The result is a concentration of exactly the data that makes downstream identity fraud work, held by a company most of the affected people have never heard of and never chose.
A driver's license image is not a password. It cannot be rotated, it stays valid for years, and it is the knowledge base behind the identity questions that help desks still use to verify callers. That is the operational link back to help desk social engineering: a caller who can recite a license number, an address history, and a date of birth passes verification procedures at a great many organizations right now. Every large identity document dump makes knowledge-based verification worse, permanently.
Two things follow for practitioners. If you buy identity verification, the vendor's retention policy is part of your risk, so ask what is kept after a successful check and for how long. And if your help desk still verifies callers with facts a data broker can sell, move it to something the caller must hold rather than know, such as a push to an enrolled device or a verified manager callback. See the McKesson breach for where the other path ends.
Source: KrebsOnSecurity
Related on Start with Identity
- Blog1.6 million RingCentral records leaked, and the entry point was one phone call
ShinyHunters voice-phished a RingCentral employee out of their password in July, took 623GB, and dumped 280GB after the company refused to pay. Have I Been Pwne
- BlogThe McKesson breach resolves to 6.4 million people, not the 284 million claimed
ShinyHunters published the McKesson data after a 55.2 million dollar demand went unpaid. Have I Been Pwned counted 6.4 million unique email addresses, against t
- BlogJetBrains was breached through an unpatched copy of its own TeamCity
Attackers exploited CVE-2026-63077 against a JetBrains-run TeamCity server to breach the Cadence cloud service, taking AWS IAM credentials, source code, and sec
- ArticleIAM Vendor Selection Framework: From RFP to Production
A structured framework for IAM vendor selection covering RFP templates, evaluation criteria, proof of concept planning, total cost of ownership analysis, and de
- CVEAuth0 node-jws HS256 verification bypass via secret lookup
node-jws before 3.2.3 / 4.0.1 can accept an HS256 JWT when the caller looks up the secret from attacker-controlled input. Medium on paper, but it is a signature
- RankingBest Identity Verification for Enterprises: Top 5 IDV & KYC Platforms
The best enterprise identity verification platforms in 2026: Onfido, Jumio, Sumsub, Socure, and Persona. Ranked for global document coverage, biometrics, fraud,