A newly launched dark-web identity-theft service, Nexus, is offering scans of more than 153 million U.S. and Canadian driver’s licenses alongside millions of other identity documents. The operators claim to have continuously exfiltrated records from a major identity-verification provider for more than a year, and its inventory reportedly increased by nearly 400,000 license records within 24 hours. The listings include front-and-back document scans, including infrared and ultraviolet image formats.
Victim accounts and image timestamp correlations tied records to identity checks at travel locations, car-rental agencies, and marijuana dispensaries, pointing to Louisiana-based identity-verification provider idscan.net as a possible source; the attribution has not been conclusively confirmed. The FBI’s New Orleans field office opened an investigation into the apparent compromise, while idscan.net said it was investigating without providing substantive public details. The exposure creates risks of identity and new-account fraud, biometric misuse, stalking, and physical harm, particularly for government personnel and people seeking to protect their identity or location.

See attribution, scope, and your downstream exposure.
13 events from the most recent confirmed update back to the earliest known activity.
Law firm Markovits, Stock & DeMarco reported that IDScan began notifying some business customers about the alleged incident around September 1. IDScan had not publicly confirmed a compromise or disclosed the number of affected individuals.
A new user advertised the Nexus dark-web identity-theft service on the Russian cybercrime forum Exploit. Nexus claimed to offer more than 153 million U.S. and Canadian driver's-license scans along with millions of other identity documents.
idscan.net announced an exclusive national identity-verification agreement with Planet13 dispensaries.
Plaintiffs from California, Florida, Georgia, and Louisiana filed four proposed class-action lawsuits in the U.S. District Court for the Eastern District of Louisiana over the alleged idscan.net exposure linked to Nexus. They seek damages and an injunction requiring stronger security controls.
The Department of Defense said it was aware of reports that Secretary of Defense Pete Hegseth's information appeared in the Nexus identity-document database and was evaluating them.
Nexus shut down shortly after Brian Krebs reported on the marketplace and displayed a message stating that the service was no longer available.
idscan.net stated that it initiated incident-response procedures related to the suspected exposure, involving its cyber insurer, outside counsel, an independent forensic firm, and preservation of relevant logs.
The FBI's New Orleans field office opened an official investigation into the apparent breach involving idscan.net.
idscan.net told reporters it was investigating the apparent exposure, but did not provide substantive answers or an official public statement on the suspected breach.
Brian Krebs reported viewing a preview of U.S. Secretary of Defense Pete Hegseth's information in the Nexus identity-document database, adding a specific high-profile individual to those reportedly affected by the suspected exposure.
Victim timestamp comparisons, Hertz and Planet13 customer overlap, and the presence of infrared and ultraviolet document images pointed to idscan.net as a possible source of Nexus data. The reporting did not conclusively confirm idscan.net as the source.
The service's advertised driver's-license inventory reportedly increased by nearly 400,000 records over 24 hours, suggesting continuing data acquisition or uploads.
Nexus operators claimed they had continuously exfiltrated identity-document data for more than a year from a major identity-verification provider serving Fortune 500 customers. The claimed source was not conclusively established.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
27 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourceinfosecurity-magazine.com
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcecybernews.com
Open sourcemalware.news
Open sourcekrebsonsecurity.com
Open sourceidscan.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.