A suspected data breach at a prominent identity verification company may have exposed more than 150 million driver’s licenses and passports from users in the United States and Canada, according to a recent investigation.
What’s reported
An identity theft website on the dark web going by the name Nexus is claiming to provide searchable access to over 150 million driver’s licenses and passports. The site ads state it adds roughly 500,000 new documents daily. It also says records are originating from a “major identity verification company,” implying near-real-time data exfiltration. In at least one case, customer photos were included when available. Security researchers found that some specific IDs listed—such as that of a certain high-profile government secretary and a cybersecurity reporter—were genuine, confirming the leak is not a hoax.
Likely source and response
Investigators believe the breach stems from IDScan, a company based in Louisiana that provides identity verification services globally to both tech and consumer brands. A spokesperson for the company did not respond to questions; however, the chief operating officer stated that the organization is currently looking into the claims. The U.S. Federal Bureau of Investigation has also launched an inquiry through its New Orleans filed office.
Broader implications
This event takes place amid growing regulatory pressure, as governments increasingly require age verification through uploads of government-issued IDs. Experts have long warned that holding large troves of ID documents raises the stakes of a breach: these kinds of leaks can lead to identity theft, fraud, and widespread privacy violations.
So far, Nexus has taken the site offline after these revelations. There is no public confirmation from IDScan verifying the scope of the breach, nor have they clarified which or how many clients or individuals were affected.
This appears to be the single largest incident to date involving identity documents. If confirmed, the fallout could ripple across industries depending on such verification services.
The full extent and motive are still being pieced together, but this incident underscores the risks in centralized storage of sensitive identity data. It’s a wake-up call for companies, regulators, and individuals to demand stronger security, stricter oversight, and transparent reporting.