Suspected IDScan breach may expose 150 million IDs

A dark web site claimed access to passports and driver’s licenses from the US and Canada, putting fresh focus on how ID verification data is stored.
A suspected breach at a major identity verification service may have exposed driver’s licenses, passports, and other ID documents used to confirm identities in everyday transactions. The alarm was raised after a dark web site began advertising access to a huge searchable database of identity records, apparently pulled from a company that checks government-issued documents in real time.
The case stands out not just because of the claimed scale, but because it appears to involve highly sensitive personal data that people hand over for routine services such as age checks, car rentals, or in-person verification. If the report is accurate, the incident could affect millions of people in the United States and Canada. It also adds pressure on businesses that store identity documents for long periods.
A dark web site claimed access to 150 million records
According to independent security journalist Brian Krebs, a new identity theft site called Nexus appeared on the dark web this week and claimed to let users search through more than 150 million driver’s licenses and passports.
The records were said to belong to people in the United States and Canada. A post promoting the site on a Russian cybercrime forum claimed that Nexus was adding around half a million new documents every day, apparently taken from a “major identity verification company.”
That points to something potentially more serious than a one-time leak. If the claim is true, the attackers may have had ongoing access to the company’s systems and could have been pulling in fresh documents in near real time.
The site’s advertisement also said customer photos were shown when available, making the possible breach even more sensitive. Krebs said he found his own driver’s license among the searchable records, which helped confirm that the material was genuine.
Secretary of Defense Pete Hegseth was also among the people whose photos were listed on the site, according to the report.
Krebs and a researcher linked the records to IDScan
Working with security researcher Zach Edwards, whose ID card was also reportedly stolen in the breach, Krebs identified the likely source as IDScan, a Louisiana-based identity verification service.
IDScan is used by major tech and consumer brands to verify the identities of tens of millions of people around the world each month, according to the source text. As IT-PUB News notes, that makes the possible breach especially significant because the company sits in the middle of a process many businesses use to decide whether a person is old enough, legitimate enough, or authorized enough to use a service.
The company’s chief executive, Jimmy Roussel, did not respond to TechCrunch’s request for comment. Chief operating officer Jillian Kossman told Krebs that the company was investigating the matter.
The FBI also appears to be involved. Krebs said the bureau’s field office in New Orleans is probing the breach, and an FBI spokesperson later confirmed that the agency is “looking into the incident,” while declining to comment further.
A spokesperson for the Department of Defense told TechCrunch that it is “aware of these reports and is evaluating them.”
The report puts age checks and ID storage under scrutiny
The report comes as governments roll out more age-verification rules, many of which depend on adults uploading identity documents to prove they are old enough to access a website or app.
That shift has already raised privacy concerns because it pushes more companies to collect and hold copies of passports, driver’s licenses, and other official IDs. Security experts and privacy advocates have long warned that this creates a tempting target for hackers, especially when the documents are stored in large volumes.
This suspected breach is likely to sharpen those concerns. Identity documents are not like ordinary account passwords. They can be used to impersonate people in the physical world as well as online, which is why the theft of such records can have lasting consequences for the people involved.
The source text does not say how the records could be misused, but the risk is plain enough: once these documents are copied and shared, they cannot be changed the way a password can.
Nexus went offline after the report appeared
Krebs reported that Nexus went offline shortly after his story was published. The source does not say whether that happened because of law enforcement activity, technical problems, or something else.
Even without that detail, the timing added to the sense that the site had exposed something significant. By all accounts, the incident would be the largest known single breach of identity documents in some time.
That is what makes the report so notable. A breach involving one company’s customer data is already serious. A breach involving a service that handles identity checks for major brands, and possibly stores millions of government-issued IDs, raises broader questions about how the digital identity industry protects the most sensitive documents people submit.
At the center of the story is a basic tension in online verification. Businesses want a fast way to confirm age and identity, while users are often required to hand over official documents to get access to services. The more data these systems collect, the more damaging a breach can become.
For now, the claims remain under investigation. But the report has already put a harsh spotlight on a central problem in digital identity: the same systems built to prove who someone is can also become a valuable store of personal data for criminals.