Late last week, an identity-theft site on the dark web called Nexus claimed it could search through more than 150 million driver’s licenses and passports belonging to people in the United States and Canada. This week, the Louisiana company at the center of it all finally admitted what happened. IDScan, an identity verification service trusted by entertainment venues, cannabis dispensaries, and other businesses to check customer IDs, confirmed it suffered a breach that exposed more than 150 million driver’s license records.

Conceptual illustration of driver's license data being stolen from a secure identity verification vault
AI-generated image of an identity data breach for illustration purposes

The one data point that should worry everyone

You can get lost in the size of the number, so let me put it plainly: that’s roughly half the combined adult population of the United States and Canada. Brian Krebs, the independent security journalist who first reported the incident, said the dark web site allowed anyone to search driver’s license data and even view photos. He verified the authenticity by pulling up his own record. Even the U.S. Secretary of Defense, Pete Hegseth, was among the names on the list, and the Pentagon said it was evaluating the reports.

IDScan’s statement to TechCrunch is careful about the exact count. The company says it “holds over 150 million driver’s license records” on its system and that hackers stole driver’s licenses from its cloud, including people’s full names, driver’s license numbers, and identity numbers from other government documents like passports. The FBI confirmed it’s investigating.

This wasn’t a quick smash-and-grab

Here’s the part that makes this breach different from the typical stolen-email-list story. The Nexus site advertised that it had been “exfiltrating new data for over a year into our private database,” according to Krebs. That’s not a one-night exploit; that’s a persistent backdoor that gave attackers near real-time access to a company’s identity verification systems.

Think about what that means operationally. The hackers weren’t just grabbing a static database of old records. They had a live pipeline streaming new driver’s license scans as customers walked into bars, dispensaries, or any of the businesses that use IDScan. For a full year, new identity documents were being copied out of the system almost as fast as they were created. The forum post advertising the site claimed it was adding roughly half a million new documents daily.

Why identity verification is such a tempting target

The uncomfortable truth is that identity verification services handle the most sensitive data most of us will ever hand to a company — not our email addresses or passwords, but our faces and government-issued IDs. A stolen password can be reset. A stolen driver’s license number, date of birth, and photo can’t.

This is why I always tell people to treat their personal data as if it’s already out there somewhere. If you’re running a service that touches customer identity documents, you’re holding a target that sophisticated criminals will spend a year trying to reach. And as I’ve written about AI-driven spear phishing and why traditional email security isn’t enough, attackers are getting more automated and more patient. A breach like this feeds directly into the shift where AI doesn’t just help hackers — it runs the attacks.

What happens with 150 million stolen IDs

Identity verification breaches are especially dangerous because the stolen data is the raw material for fraud. With a matching photo and ID number, attackers can attempt to open financial accounts, take over existing ones, or create synthetic identities that are notoriously hard to detect. The Identity Theft Resource Center’s president, James E. Lee, told TIME that this could be one of the most extensive single leaks of driver’s license data, and that the data will have value to cybercriminals for years.

The reach matters too. IDScan isn’t a household name, but its corporate customers span entertainment, retail, transportation, and finance. You may never have heard of the company, yet its breach could surface your data in a dark web search years from now.

What you should actually do right now

First, don’t panic, but do treat this as a reason to tighten your identity hygiene. A few practical steps:

  • Monitor your credit and financial accounts. Watch for unfamiliar accounts or inquiries that might indicate someone is trying to use your identity.
  • Freeze your credit if you can. A credit freeze blocks most new account openings in your name, which is the single most effective thing you can do.
  • Watch for phishing. A breach like this often triggers a wave of scams claiming to “help” affected users. Verify anything that arrives unsolicited, using the same caution I described in how to verify whether a message is really a scam.
  • Check the accounts tied to your identity. Tools like holehe can show you which accounts are linked to your email, so you know what’s worth securing.

What this means for businesses

If you run a business that collects ID scans — a bar verifying age, a car rental agency, an online KYC flow — this is a direct warning about contract design. When you outsource identity verification to a third party, you’re handing them your customers’ most sensitive data. That decision needs to come with questions about how that vendor stores, encrypts, and limits access to the data, and how long it retains records it no longer needs.

Identity data you collect because you’re legally required to verify someone should not sit around indefinitely. The longer it’s stored, the larger the blast radius when — not if — the vendor gets hit. The threat landscape has shifted so dramatically that security can’t be an afterthought bolted onto a system after the fact, and the tools for checking compromised accounts have never been more important to use. If you’re wondering how to check whether your accounts were already caught up in a breach, that’s a good place to start for your personal safety too.

The bottom line

IDScan confirming this breach is the beginning, not the end. The data is already circulating, the FBI is investigating, and security researchers are still mapping the full scope. For the rest of us, the lesson is sobering: the companies we trust to verify our identities are holding the most valuable thing we own, and sometimes they don’t even know it’s been stolen for a year.

Treat your identity as if it’s already compromised, secure what you can, and stay alert to the scam wave that always follows a breach this big. That’s the only defense that doesn’t depend on a vendor you’ve never heard of doing the right thing.

Filed under Tech & Gadgets
Last Update: September 11, 2026 by Felix AlterEgo
0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted