News

FBI probes suspected IDScan breach of 153 million IDs

The FBI is looking into a suspected breach at a commercial ID-verification vendor after Nexus, a dark-web marketplace, advertised searchable access to about 153 million US and Canadian driver's licenses and passports. Krebs and Zach Edwards named Louisiana-based IDScan as the likely source. IDScan has not confessed. The advert claimed about 500,000 new documents a day, and Nexus went dark after Krebs published.

FBI probes suspected IDScan breach of 153 million IDs

The FBI is looking into a suspected leak of US and Canadian identity documents after a dark-web marketplace called Nexus advertised searchable access to about 153 million driver's licenses and passports. TechCrunch (Zack Whittaker, 2 September 2026) reported the story off Brian Krebs, who found his own license in the set. Secretary of Defense Pete Hegseth was listed too.

This is a suspected breach of a commercial ID-verification vendor, now under FBI review. It is not a company confession, not a court finding, and not a published CVE.

Krebs, working with researcher Zach Edwards, named Louisiana-based IDScan as the likely source. IDScan's COO Jillian Kossman told Krebs the company was investigating. CEO Jimmy Roussel did not comment to TechCrunch. That attribution is investigative. It is not a proven fact.

The FBI's New Orleans field office is probing. An FBI spokesperson said the bureau is "looking into the incident" and declined to say more. The Department of Defense said it is "aware of these reports and is evaluating them."

What the 153 million headlines skip is the cadence. A post advertising Nexus on a known Russian cybercrime forum said the site added about 500,000 new documents a day from a "major identity verification company," which is a near-real-time access claim, not a one-time dump. Ars Technica (Dan Goodin) said his own license appeared within hours of a car-rental scan, and that Krebs watched the listing grow by almost 400,000 in 24 hours.

Nexus went offline shortly after Krebs published. Once the marketplace went dark, there was no public way for people to check whether their ID was in the set.

The suspected source sits in the same third-party pattern as the Thomson Reuters C-Track court-records incident: a vendor holding official documents for many customers, not the customer's own network. It also lands as governments push age-verification rules that send adults to upload IDs, the same retention fight visible in the TikTok COPPA settlement and Meta's youth settlement with the states. If you already contract for zero-retention processing, treat ID scans the same way. Do not keep them longer than the check requires.

No ransom note is public. Nobody has assigned a CVE. IDScan has not said it was breached.

This week, a compliance or security lead should put every ID-verification vendor on the record for retention windows and current breach status, freeze any age-gate or KYC flow that uploads a license or passport you do not strictly need, and watch for FBI or IDScan customer notices before you assume your scan pile is clean.

Subscribe to Techpresso

Free daily newsletter, read in 5 minutes.

Subscribe free