The IDScan Breach Investigation and Your Privacy
Rob Shavell
Reading time: 7 minutes
This is not another breach involving email addresses and passwords. A dark web service called Nexus claimed to have scans of more than 150 million U.S. driver’s licenses, actual government-issued identity documents including images of the front and back of each one.
On August 31st, 2026, KrebsOnSecurity received a tip about Nexus, which claimed to possess identity documents belonging to 170 million people. Brian Krebs found driver’s licenses, identification cards, travel documents and medical cards being offered for sale. An ad on a Russian cybercrime forum called Exploit included Brian Krebs’s own Virginia driver’s license offered as proof of the quality of the goods.
The next day, Krebs published about the apparent IDScan breach and the FBI inquiry into it. To date IDScan has not confirmed anything.
The breach is possibly ongoing. At the time it included 153 million U.S. and Canadian driver’s licenses (about 1.1 million of them Canadian), 10 million ID cards, 3 million travel documents and 579,000 medical cards. Some high value records, including Defense Secretary Pete Hegseth’s, were listed for as much as $100. The operators claimed they’d been exfiltrating data for more than a year, and the license count alone rose by about 400,000 over the first day Krebs started reporting on the apparent breach.
Nexus went dark within hours of Krebs’s story. According to a subsequent update on KrebsOnSecurity, the login page now reads that the service is no longer available.
This does not mean the data from the apparent IDScan.net breach is gone. Anything that was downloaded before Nexus’ shutdown is circulating, and the operators still have the database either way.
KrebsOnSecurity traced several ID exposures to a car rental company called Hertz, as well as a marijuana dispensary. Both Hertz and the dispensary may have used IDScan to verify customers. The FBI’s New Orleans field office opened an investigation into the breach and IDScan.net in particular. IDScan told Krebs it was investigating but has not answered specific questions or issued a statement.
Why the IDScan.net breach investigation matters
What can a threat actor do with your ID?
- Credit and identity theft: A driver’s license is one of the most common documents used to verify identity when opening new credit lines, so a leaked scan gives a criminal a running start at borrowing money in your name.
- Danger to domestic violence survivors: People who have relocated or changed their appearance to escape an abuser depend on being hard to find, and a license scan with a photo and an address means zero-privacy and high findability.
- Compounded risk when cross-referenced with data broker profiles: A leaked license becomes far more dangerous when paired with other personal details, like a home address, phone number or employer, all sold separately and inexpensively by data brokers. Together they’re enough to impersonate someone or locate them.
- Risk to witness protection participants: Approximately 20,000 individuals in the United States have been given new identities after cooperating in serious criminal cases. The apparent IDScan.net breach makes it possible to connect a new name to an old face, and the purchasable data that was available on Nexus is perfect for that use case.
- Exposure of government and law enforcement personnel: Pete Hegseth’s license wasn’t the only one in there. Krebs found the FBI assistant director’s license, and what appeared to be common access cards that allow government employees access to secure facilities. Leaked IDs could bring targeted harassment, impersonation, compromise of people in sensitive positions, or worse.
The data broker advantage for threat actors
Data brokers collect and sell personal information, including your home address, your phone number, income status, marital status, relatives’ info, and much more. Just one profile on a data broker site costs a lot less than $100, and cybercriminals can not only cross-reference those profiles with exposed IDs to get a clear picture of who you are; they allow them to show up at your door or impersonate you.
This matters. A recent report showed data breaches of just four major data broker databases fueled almost $21 billion in identity fraud losses.
DeleteMe cleans up your digital footprint, which means cybercriminals have a harder time cross-referencing exposed datasets and IDs with the information on people search sites. The aftereffects of a breach are often long-term and far-reaching, which is why long-term data privacy and protection are important. Learn more at joindeleteme.com.
What’s next for victims of the suspected IDScan breach?
Right now, there’s no way to check whether your license was exposed. Nexus is offline and IDScan hasn’t said whose records were involved. You are more likely to be affected if you’ve rented a car, made a purchase as a marijuana dispensary or handed your license over to be scanned at a hotel, bank or retail counter in the past couple years. IDScan says it performs more than 21 million verifications a month at more than 20,000 locations. So the best course of action here is to assume you’ve been compromised and act accordingly.
Lock it down.
- Change your passwords and enable MFA: Most people reuse weak passwords across sites. Use long passphrases instead, and turn on multi-factor authentication wherever you can. An authenticator app is always better than a code sent by text.
- Freeze your credit: A freeze stops anyone from opening new accounts in your name, which is the fastest thing a criminal can get done with your license. Make sure you freeze all three bureaus: Equifax, Experian and TransUnion. Bear in mind, cybercriminals can thaw a credit freeze using a breached ID scan paired with other personal info. Make sure transaction alerts are activated, and new account alerts, too, if you subscribe to a service that provides them.
- Watch out for highly personalized phishing emails and calls: Criminals use major breaches as an opportunity to trick you into responding to the very real details with a very fake fix. Remember, just because someone knows your information doesn’t make them legit. If you get a call from a business, hang up, look up their number and call them back.
- Monitor for fraud and unusual activity across accounts: Check your accounts and credit reports for anything unfamiliar to you. If you find fraud, report it to the FBI’s Crime Compliance Center at IC3.gov
- Remove your personal information from data broker and people search sites: A leaked license is more dangerous when coupled with the kinds of information readily available on people search sites. Criminals move fast, and hate friction. It’s our job to make their job harder.
If you’re reading this as a CISO or business owner, the problems can be manifold and circle around identity verification as it’s used to govern access to sensitive information. An attacker with a verified ID scan and the kinds of information available online can pass stringent help desk challenges, trounce a Know Your Customer check, and, yep, they can open an account in an employee’s name, too.
Final Thoughts
Treat driver’s license verification as compromised for now, and pair it with a second factor that isn’t a document. If you need to use license verification, require the actual card, and not an image of it.
When a breach happens, feeling powerless is normal, but there are steps you can take to protect yourself, and there are steps we can take to help.
Stay safe out there.
Learn more:
- Try out our free scan to see where your information might be exposed on top data broker sites, putting you at greater risk online.
- Discover what to do if your credit card is used fraudulently.
- Learn about the Canvas hack, a data breach with significant implications for student privacy.
Our privacy advisors:
- Continuously find and remove your sensitive data online
- Stop companies from selling your data – all year long
- Have removed 35M+ records
of personal data from the web
Save 10% on any individual and
family privacy plan
with code: BLOG10
news?
Don’t have the time?
DeleteMe is our premium privacy service that removes you from more than 750 data brokers like Whitepages, Spokeo, BeenVerified, plus many more.
Save 10% on DeleteMe when you use the code BLOG10.




