IDScan Breach Exposes 153 Million U.S. & Canadian Driver’s Licenses via ‘Nexus’

A data breach tied to IDScan.net has implicated more than 170 million identity documents—over 153 million of which are driver’s licenses—from the U.S. and Canada, after they appeared for sale through a cybercrime service called “Nexus.” The vendor claims to have been continuously harvesting this data for over a year. The identity verification provider confirmed an unauthorized access incident around September 1, 2026, and is now coordinating with federal authorities and offering remedies to those affected.

How the Breach Surfaced

The breach was exposed when security journalist Brian Krebs was tipped off about a new identity document marketplace being advertised on Exploit, a Russian-language dark web forum. The seller offered a driver’s license as a verification sample—raising suspicion and enabling researchers to trace the source to a widely used verification vendor. While this activity was noticed on August 31, the company detected the breach itself just a day later, on September 1. IDScan.net immediately brought in third-party forensics and began shoring up its internal systems.

Scale and Types of Data Stolen

According to Nexus, the exposed trove includes documents of more than 170 million individuals in North America. Among these are over 153 million driver’s licenses, more than 10 million additional ID cards, over 3 million travel and international documents, and around 579,000 medical cards. Canadian data alone exceed 1.1 million entries, nearly half a million of which are from Ontario. The haul also reportedly includes commercial driver’s licenses, government access cards, marijuana dispensary IDs, and military-style credentials (like Common Access Cards), indicating the breach affects a wide array of regulated and sensitive documentation.

Risk, Response, and What to Do

IDScan.net says that cloud accounts containing customers’ full names along with driver’s license or other government-ID numbers were accessed by the third party. The company is notifying those potentially exposed and is offering free credit monitoring and identity protection. Affected individuals are encouraged to watch for suspicious activity in financial statements and to consider freezing credit files with bureaus to prevent unauthorized account creation. IDScan.net has opened dedicated contact channels—by phone and mail—for anyone with questions or concerns about exposure.

Broader Implications

The incident has captured attention from the FBI’s New Orleans field office, which has launched an official investigation. What makes this breach especially concerning is the vendor’s claim that data exfiltration has been ongoing for over a year, with a noticeable influx of new records—about 400,000 driver’s licenses—appearing in just 24 hours during the investigation. It suggests the breach may still be in progress, rather than being limited to historical data.

This breach underlines the stakes in entrusting critical identity verification to third-party vendors. When such services are compromised, the fallout can reach both ordinary individuals and high-profile figures alike. Among those affected is U.S. Defense Secretary Pete Hegseth, illustrating how deeply national security might be implicated when even a single vendor’s perimeter is breached.

Moving forward, this event should trigger a reevaluation of how businesses and governments handle identity data. Stronger access controls, more regular audits of verification partners, and faster detection mechanisms are becoming essential. Individuals in the compromised categories should act now—monitor credit, secure identity records, and demand accountability from providers.

For all those impacted, the takeaway is clear: the integrity of identity information isn’t just a customer service issue—it’s a national security concern. Vigilance, both by organizations and the individuals they serve, will be the first line of defense in such breaches.