3 SEP 2026 — A dark-web service called Nexus advertised more than 150 million driver's licences and passports belonging to US and Canadian residents, drawn from the identity verification firm IDScan, with roughly 500,000 new documents added daily. Daily additions mean this was not a historical dump. Somebody had live access, and an identity document cannot be rotated the way a password can.

What is known

IDScan, based in Louisiana, provides identity verification used by a range of technology and consumer brands. The Nexus site, advertised on a Russian cybercrime forum, offered searches against the collection and displayed customer photographs where available.

The security journalist Brian Krebs confirmed the data was genuine by finding his own driver's licence in it. The researcher Zach Edwards also found his own credentials. A photograph of US Defense Secretary Pete Hegseth appeared in the records.

IDScan's chief operating officer Jillian Kossman said the company was investigating. Chief executive Jimmy Roussel did not respond to requests for comment. The FBI's New Orleans field office is investigating. Nexus went offline shortly after Krebs published.

150m+Driver's licences and passports advertised
~500,000New documents claimed to be added each day
VerifiedTwo researchers found their own documents in the set
OfflineNexus went down after publication, which is not the same as access ending

Daily additions change the tense of this story

A stolen database is a photograph of a moment. Whatever was in it when it was taken is what the attacker has, and the exposure is bounded by the date of the copy.

A collection growing by half a million documents a day is different. It implies a live feed, meaning an attacker either had continuing access to IDScan's systems or was tapping a pipeline that was still running when the advertisement was written.

The site going offline after Krebs published should not, therefore, be mistaken for containment. Taking down a storefront removes the shop window; it says nothing about whether the supply behind it was interrupted, and a service that reappears under another name a month later is the normal pattern.

These identifiers do not rotate

Every piece of breach advice assumes the compromised thing can be replaced. Change the password, reissue the card, revoke the token.

A driver's licence number stays with a person for years and a passport number for a decade, and replacing either requires attending an office, paying a fee and having a reason a clerk accepts. Being on a criminal list is not usually accepted as one, and in most jurisdictions there is no process for reissue on the grounds that your document was leaked.

The photograph is worse. A person's face is the credential in every remote verification system that asks for a selfie against a document, and a leaked pair of document and photograph is precisely the input those systems check. Nothing about that can be revoked.

What a person can actually do about it

The honest starting point is that the options are poor. Admitting that is more useful than a list of steps that do not address the real exposure.

A credit freeze at each bureau prevents new accounts being opened in your name and is free in the United States and Canada. It does not stop a document being used where the check is a photograph against a scan rather than a credit file, which covers most account openings at platforms, marketplaces and crypto exchanges.

Beyond that, the realistic posture is monitoring rather than prevention. Treat any contact that already knows your licence number as unverified rather than as proof of legitimacy, since that number is now precisely what an impersonator has. And if a document was issued recently enough that reissue is plausible for another reason — a change of address, an expiry within a year — taking it is worth more than it usually would be.

The concentration was the selling point

The argument for a third-party verification service is straightforward and sound. A merchant that checks identity itself has to store scans of documents, secure them and comply with the rules about holding them. Outsourcing that to a specialist means fewer copies in fewer places, handled by an organisation that does nothing else.

That reasoning holds until the specialist is breached, at which point every customer's verification history is in one place for the attacker as well. The efficiency and the exposure are the same property viewed from opposite sides.

This does not make the outsourced model wrong. It means the provider's security is not a procurement detail for its customers; it is the entire risk they thought they had transferred, and very few of them audit it.

Why this arrives here next

The region is building exactly this architecture. Malaysia is rolling out age verification for social media using national identity credentials, the Philippines has been extending PhilSys into platform age checks, and Singapore's Singpass is the assumed identity layer for a growing list of private services.

We reported on Malaysia's under-16 social media restrictions implemented through identity verification and on the Philippine approach using PhilSys. Both push verification through a small number of providers, which is the structure that produced this incident.

The design question to ask now, rather than later, is whether a verification provider needs to retain the document at all. A system that checks a credential and stores only the result — verified, over 18, matched — holds nothing worth stealing at this scale. A system that keeps the scan builds the asset that turns up on a forum later.