Skip to main content

The IDScan Breach Investigation and Your Privacy

The IDScan Breach Investigation and Your Privacy

Rob Shavell

Last Updated: September 4, 2026

Reading time: 7 minutes

Multiple driver's licenses available for sale, depicting the recent IDScan breach investigation.

This is not another breach involving email addresses and passwords. A dark web service called Nexus claimed to have scans of more than 150 million U.S. driver’s licenses, actual government-issued identity documents including images of the front and back of each one. 

On August 31st, 2026, KrebsOnSecurity received a tip about Nexus, which claimed to possess identity documents belonging to 170 million people. Brian Krebs found driver’s licenses, identification cards, travel documents and medical cards being offered for sale. An ad on a Russian cybercrime forum called Exploit included Brian Krebs’s own Virginia driver’s license offered as proof of the quality of the goods. 

The next day, Krebs published about the apparent IDScan breach and the FBI inquiry into it. To date IDScan has not confirmed anything.

The breach is possibly ongoing. At the time it included 153 million U.S. and Canadian driver’s licenses (about 1.1 million of them Canadian), 10 million ID cards, 3 million travel documents and 579,000 medical cards. Some high value records, including Defense Secretary Pete Hegseth’s, were listed for as much as $100. The operators claimed they’d been exfiltrating data for more than a year, and the license count alone rose by about 400,000 over the first day Krebs started reporting on the apparent breach. 

Nexus went dark within hours of Krebs’s story. According to a subsequent update on KrebsOnSecurity, the login page now reads that the service is no longer available. 

This does not mean the data from the apparent IDScan.net breach is gone. Anything that was downloaded before Nexus’ shutdown is circulating, and the operators still have the database either way.

KrebsOnSecurity traced several ID exposures to a car rental company called Hertz, as well as a marijuana dispensary. Both Hertz and the dispensary may have used IDScan to verify customers. The FBI’s New Orleans field office opened an investigation into the breach and IDScan.net in particular. IDScan told Krebs it was investigating but has not answered specific questions or issued a statement. 

Why the IDScan.net breach investigation matters

What can a threat actor do with your ID?

  • Credit and identity theft: A driver’s license is one of the most common documents used to verify identity when opening new credit lines, so a leaked scan gives a criminal a running start at borrowing money in your name. 
  • Danger to domestic violence survivors: People who have relocated or changed their appearance to escape an abuser depend on being hard to find, and a license scan with a photo and an address means zero-privacy and high findability. 
  • Compounded risk when cross-referenced with data broker profiles: A leaked license becomes far more dangerous when paired with other personal details, like a home address, phone number or employer, all sold separately and inexpensively by data brokers. Together they’re enough to impersonate someone or locate them.
  • Risk to witness protection participants: Approximately 20,000 individuals in the United States have been given new identities after cooperating in serious criminal cases. The apparent IDScan.net breach makes it possible to connect a new name to an old face, and the purchasable data that was available on Nexus is perfect for that use case. 
  • Exposure of government and law enforcement personnel: Pete Hegseth’s license wasn’t the only one in there. Krebs found the FBI assistant director’s license, and what appeared to be common access cards that allow government employees access to secure facilities. Leaked IDs could bring targeted harassment, impersonation, compromise of people in sensitive positions, or worse.

The data broker advantage for threat actors

Data brokers collect and sell personal information, including your home address, your phone number, income status, marital status, relatives’ info, and much more. Just one profile on a data broker site costs a lot less than $100, and cybercriminals can not only cross-reference those profiles with exposed IDs to get a clear picture of who you are; they allow them to show up at your door or impersonate you. 

This matters. A recent report showed data breaches of just four major data broker databases fueled almost $21 billion in identity fraud losses. 

DeleteMe cleans up your digital footprint, which means cybercriminals have a harder time cross-referencing exposed datasets and IDs with the information on people search sites. The aftereffects of a breach are often long-term and far-reaching, which is why long-term data privacy and protection are important. Learn more at joindeleteme.com

What’s next for victims of the suspected IDScan breach? 

Right now, there’s no way to check whether your license was exposed. Nexus is offline and IDScan hasn’t said whose records were involved. You are more likely to be affected if you’ve rented a car, made a purchase as a marijuana dispensary or handed your license over to be scanned at a hotel, bank or retail counter in the past couple years. IDScan says it performs more than 21 million verifications a month at more than 20,000 locations. So the best course of action here is to assume you’ve been compromised and act accordingly. 

Lock it down. 

  • Change your passwords and enable MFA: Most people reuse weak passwords across sites. Use long passphrases instead, and turn on multi-factor authentication wherever you can. An authenticator app is always better than a code sent by text. 
  • Freeze your credit: A freeze stops anyone from opening new accounts in your name, which is the fastest thing a criminal can get done with your license. Make sure you freeze all three bureaus: Equifax, Experian and TransUnion. Bear in mind, cybercriminals can thaw a credit freeze using a breached ID scan paired with other personal info. Make sure transaction alerts are activated, and new account alerts, too, if you subscribe to a service that provides them. 
  • Watch out for highly personalized phishing emails and calls: Criminals use major breaches as an opportunity to trick you into responding to the very real details with a very fake fix. Remember, just because someone knows your information doesn’t make them legit. If you get a call from a business, hang up, look up their number and call them back. 
  • Monitor for fraud and unusual activity across accounts: Check your accounts and credit reports for anything unfamiliar to you. If you find fraud, report it to the FBI’s Crime Compliance Center at IC3.gov
  • Remove your personal information from data broker and people search sites: A leaked license is more dangerous when coupled with the kinds of information readily available on people search sites. Criminals move fast, and hate friction. It’s our job to make their job harder. 

If you’re reading this as a CISO or business owner, the problems can be manifold and circle around identity verification as it’s used to govern access to sensitive information. An attacker with a verified ID scan and the kinds of information available online can pass stringent help desk challenges, trounce a Know Your Customer check, and, yep, they can open an account in an employee’s name, too. 

Final Thoughts

Treat driver’s license verification as compromised for now, and pair it with a second factor that isn’t a document. If you need to use license verification, require the actual card, and not an image of it. 

When a breach happens, feeling powerless is normal, but there are steps you can take to protect yourself, and there are steps we can take to help. 

Stay safe out there. 

Learn more: 

SHARE THIS ARTICLE
CEO and co-founder of DeleteMe, Rob Shavell is one of the leading consumer and business privacy advocates in the United States today. His commentary on the business of privacy and privacy legislation…
CEO and co-founder of DeleteMe, Rob Shavell is one of the leading consumer and business privacy advocates in the United States today. His commentary on the business of privacy and privacy legislation…
Hundreds of companies collect and sell your private data online. DeleteMe removes it for you.

Our privacy advisors: 

  • Continuously find and remove your sensitive data online
  • Stop companies from selling your data – all year long
  • Have removed 35M+ records
    of personal data from the web
Special Offer

Save 10% on any individual and
family privacy plan
with code: BLOG10

Want more privacy
news?
Join Incognito, our monthly newsletter from DeleteMe that keeps you posted on all things privacy and security.
Icon mail and document

Don’t have the time?

DeleteMe is our premium privacy service that removes you from more than 750 data brokers like Whitepages, Spokeo, BeenVerified, plus many more.

Save 10% on DeleteMe when you use the code BLOG10.

Related Posts

Woman holding image of lock over her face, symbolizing identity protection

Why “Everyone Already Has My Data Anyway” Is a Myth

Cybersecurity experts can be a little bossy: “Protect your data! Change your passwords! Eat your vegetables!” The rest of us are pretty g…
Keegan Henckel-Miller
August 12, 2026

Meta’s Muse Image Backlash Isn’t the Win You Think It Is

Meta recently announced its Muse Image feature, which allowed anyone to tag public accounts and use the images displayed on those accounts to fuel AI…
Sarah Huard
July 30, 2026
Example of an ad in ChatGPT

The Problem with Ads in ChatGPT

When OpenAI’s ChatGPT first emerged in 2022, there were no ads. It was a free tool for anyone to use without popups or product recommendations. …
Sarah Huard
July 15, 2026