Unverified claim: On August 31, 2026, a new Exploit forum user advertised the Nexus service and claimed access to more than 153 million US and Canadian driver’s-license scans, according to KrebsOnSecurity. Evidence reviewed by Krebs points toward New Orleans identity-verification vendor IDScan.net as the suspected source, but IDScan has not confirmed a breach. Spokesperson Jillian Kossman said the company was investigating. Every count and attribution below must therefore be treated as an unverified actor sale and suspected vendor compromise, not a company-confirmed IDScan.net data breach.
What the Nexus seller claimed
Nexus appeared through a sales thread posted by a newly registered account on the Russian-language Exploit cybercrime forum. The seller initially described a collection exceeding 160 million or 170 million North American identity documents. A closer view of the service reportedly showed more than 153 million driver’s licenses from the United States and Canada, over 10 million other identification cards, more than three million travel documents or international IDs, and at least 579,000 medical cards.
Those figures describe searchable document images, not merely rows containing names and addresses. A driver’s-license scan can expose a portrait, signature, date of birth, home address, license number, physical characteristics, expiration date, barcode data, and issuing jurisdiction. Some verification systems capture both sides of a license and additional infrared or ultraviolet images used to test security features. That makes this suspected IDScan.net incident materially different from an ordinary contact-list leak.
The seller claimed the collection was still growing because information had been continuously exfiltrated for more than a year. Krebs reported that roughly 400,000 license scans appeared to have been added within one 24-hour period. That observation, if accurate, suggests access to an active processing pipeline rather than a historical backup copied once and left unchanged. IDScan has not confirmed either the continuing-access claim or the reported growth rate.
Why IDScan.net became the suspected source
Krebs did not base the IDScan attribution only on the seller’s marketing. The reporting compared document timestamps and transaction context with known places where people had their identification scanned. Some records reportedly lined up with Hertz vehicle rentals, while others matched visits to Planet 13, a large cannabis dispensary where age and identity checks are routine.
The images also reportedly appeared in infrared and ultraviolet pairs consistent with IDScan’s document-authentication workflow. Those formats are important because most consumers do not independently create specialized IR and UV copies of their licenses. A paired set is more likely to originate from equipment or software designed to inspect identification documents for fraud indicators.
IDScan publicly promotes identity-verification and age-verification technology. Its trust materials have named organizations including Hertz, Target, FedEx, Motorola Solutions, and Jack Henry. Planet 13 previously announced an exclusive arrangement involving IDScan technology. Caesars Entertainment later told Krebs it was not a current IDScan client, illustrating why a name on a marketing page should not be treated as proof that a particular person’s record entered the alleged corpus through that organization.
The overlap is compelling investigative evidence, but it is not the same as forensic confirmation. A third-party integration, reseller, shared storage platform, customer system, stolen credential, or another vendor in the transaction chain could potentially create similar artifacts. Until IDScan or investigators publish verified findings, the correct description remains a suspected IDScan source behind an unverified Nexus sale.
A timeline of the suspected 2026 ID-document breach
- Approximately 2025 onward: Nexus claimed that its operators had continuously collected identity documents for more than a year. No victim or law-enforcement agency has independently confirmed that starting point.
- August 31, 2026: A new Exploit forum account advertised Nexus and offered access to a vast North American identity-document collection.
- September 1, 2026: The FBI’s New Orleans field office told KrebsOnSecurity it had opened an investigation.
- After publication: Nexus became unavailable and displayed a message saying the service was no longer available.
- At publication time: IDScan said it was investigating but had not fully confirmed the alleged intrusion, affected organizations, document count, or exposure window.
Nexus going dark does not establish that its operators deleted the data. Criminal services regularly disappear after publicity, rebrand, restrict access, or sell collections privately. Copies may already have been downloaded by customers or partners. People potentially affected should not interpret the shutdown message as evidence that the underlying driver’s-license scans are safe.
What data may be exposed
The most serious alleged material is the document imagery itself. A front-and-back driver’s-license set may reveal the holder’s full legal name, residential address, date of birth, photograph, signature, license number, issue and expiration dates, and machine-readable barcode. Depending on the jurisdiction, it may also show height, eye color, restrictions, endorsements, or other identifiers useful for answering verification questions.
The seller also claimed millions of identity cards and travel documents. Those categories could include state or provincial ID cards, passports, residency documents, or other government-issued credentials, although the exact composition has not been independently verified. Nexus reportedly contained medical cards as well, potentially exposing member identifiers, insurer or program names, and information that can make healthcare or benefits fraud more convincing.
An image is valuable because criminals can combine visual fields with information from older breaches. A phone number from one leak, an email address from another, and a license scan from Nexus could form a stronger identity package than any source alone. The photograph and signature can also support forged applications, synthetic identities, account recovery attempts, rental fraud, or impersonation during remote verification.
Why encryption and password resets are not the central issue
This was not described as a password database incident. Changing an IDScan password, a Hertz password, or a retail account password does not replace a license number, portrait, date of birth, or signature. Password hygiene still matters, especially when phishing follows breach publicity, but the primary response must focus on identity fraud and new-account monitoring.
A driver’s license can be reissued, yet the practical protection varies by jurisdiction. A replacement may keep the same underlying number, and old document details may remain useful in weak verification systems. Consumers should ask their motor-vehicle agency what remedies are available when a license image, rather than the physical card, may have been compromised.
Who should consider themselves potentially at risk
No verified victim list has been published. Nexus allegedly covered the United States and Canada at extraordinary scale, so the potential population extends beyond direct IDScan customers. A person may never have heard of IDScan while a business used its software behind an age check, rental counter, identity-verification portal, financial workflow, delivery process, or regulated retail transaction.
As a precaution, anyone whose driver’s license was scanned during a Hertz rental, cannabis-dispensary visit, retail identity check, delivery verification, or similar transaction since roughly 2025 should consider the possibility that the image entered the alleged corpus. That does not mean every scan from those businesses was exposed. It means the Nexus claims and timestamp correlations are broad enough to justify heightened monitoring.
Employees and contractors may also face risk if workplace identity checks fed documents into the same ecosystem. The seller’s reported inventory included travel and medical documents, indicating that the alleged collection was not limited to consumer age checks. Organizations should determine whether they integrated IDScan directly, used a service provider that did, or retained duplicate images in connected systems.
The most likely abuse paths
New-account and lending fraud
A high-resolution license can help a criminal pass document-upload steps used by lenders, banks, telecommunications providers, rental companies, and online marketplaces. Strong systems require live facial verification and device-risk checks, but weaker processes may accept a document image plus matching personal information.
Real ID and motor-vehicle phishing
Scammers can exploit public anxiety by sending messages claiming that a license must be replaced, upgraded, or revalidated after the breach. A message containing the correct license number, address, or expiration date can appear credible. Links may lead to fake motor-vehicle portals that collect Social Security numbers, payment cards, or selfie videos.
Account recovery and impersonation
Support desks sometimes request a license image to restore access. If an attacker already possesses that image, it can become a tool for hijacking email, financial, marketplace, or cryptocurrency accounts. The risk increases when the attacker also knows the victim’s phone number and can attempt SIM swapping.
Medical and insurance fraud
The claimed 579,000 medical cards could support fraudulent billing, prescription scams, or targeted calls impersonating an insurer. Even when a card alone cannot authorize treatment, the combination of a medical identifier and government ID can make social-engineering attempts harder to recognize.
What IDScan, customers, and investigators still need to establish
The central unanswered question is whether Nexus accessed IDScan infrastructure, a customer environment, a connected cloud repository, or several sources. Investigators also need to determine how access was obtained, when it began, whether it persisted after discovery, and whether security logs can reliably identify every document viewed or exported.
A trustworthy notification should distinguish unique people from document counts. One person may have multiple scans from different transactions, renewed licenses, or front-and-back images. The seller’s categories may overlap. A claim of 170 million records therefore does not necessarily mean 170 million unique individuals, just as 153 million license images may include repeat scans.
Affected businesses should disclose retention practices. Consumers reasonably expect an ID scan used for a momentary verification to be deleted when it is no longer required. If images were kept for years or centralized across customers, that architecture can turn routine identity checks into a large concentration of durable identity data.
What to do after the suspected IDScan.net breach
- Freeze your credit files. Place free security freezes with Equifax, Experian, and TransUnion in the United States, or use the appropriate protections available through Canadian credit bureaus. A freeze is stronger than routine monitoring because it can stop many lenders from opening an account before fraud occurs.
- Review new-account activity. Check credit reports, bank messages, mobile-carrier notices, insurance explanations of benefits, and mail for unfamiliar applications. Do not focus only on existing-card transactions; a license image is especially useful for creating new relationships.
- Treat Real ID messages as suspicious. Navigate directly to an official state, provincial, or federal website. Do not use links or telephone numbers supplied in an unsolicited text, email, social-media message, or call claiming that the breach invalidated your document.
- Assume a scan may be present if you used a relevant service. People who had identification scanned at a Hertz counter, dispensary, retailer, delivery checkpoint, or identity-verification kiosk since approximately 2025 should take precautions without waiting for definitive individual notice.
- Ask the issuing agency about replacement options. Explain that a digital image may have been exposed. Ask whether the license number can change, whether a fraud notation is available, and what documentation is needed if impersonation occurs.
- Strengthen high-value accounts. Use unique passwords and phishing-resistant multifactor authentication for email, banking, mobile-carrier, tax, healthcare, and cryptocurrency accounts. Add a carrier PIN and restrict unauthorized number transfers.
- Protect medical benefits. Review insurer statements and explanations of benefits for services you did not receive. Report unfamiliar claims quickly so incorrect information does not enter your medical history.
- Preserve evidence. Save suspicious correspondence, application notices, dates, telephone numbers, and screenshots. File reports with the relevant identity-theft authority, police agency, financial institution, or motor-vehicle department when concrete fraud appears.
What organizations using ID scanning should do
Businesses should inventory every point where identity documents are captured, including mobile applications, kiosks, scanners, support uploads, and third-party APIs. They should identify which party controls storage, how long images remain, whether specialized IR and UV files are retained, and whether customer contracts allow secondary use.
Access keys, service accounts, export functions, and administrative searches deserve immediate review. Monitoring should flag high-volume queries, blank searches, repeated exports, access from unusual infrastructure, and sudden retrieval of old records. Segmentation must prevent one compromised account from reaching an entire multi-customer archive.
Retention is the decisive control. If law or business necessity does not require a document image, delete it. When retention is required, separate tenants, encrypt records with narrowly controlled keys, restrict bulk access, and test whether a compromised integration can bypass normal user-interface limits.
FBI scrutiny raises the stakes but does not confirm the claim
The FBI New Orleans field office opening an investigation is significant because IDScan is based in the region and the alleged corpus spans jurisdictions. It does not prove Nexus’s attribution or counts. Law-enforcement investigations begin to preserve evidence and test claims; their existence should not be presented as a finding of liability.
Nexus’s rapid disappearance may complicate attribution while also creating opportunities. Infrastructure records, cryptocurrency transactions, forum messages, access logs, and copies supplied by researchers could help establish who operated the service and where the documents originated. The public needs verified results rather than further repetition of the seller’s marketing.
Where to track the verified record
BreachHistory maintains the canonical incident page at IDScan.net and Nexus 2026 incident record. The record distinguishes the actor’s claims from confirmed facts and should be updated if IDScan, the FBI, affected customers, or regulators publish findings.
Primary reporting is available from KrebsOnSecurity. Additional coverage from CyberInsider and Engadget documents the suspected IDScan attribution and Nexus shutdown.
The bottom line
The alleged scale is extraordinary, but precision matters. Nexus claimed a live collection containing more than 153 million driver’s-license scans and millions of other identity documents. Krebs found technical and transactional clues pointing to IDScan.net. IDScan said it was investigating, the FBI opened a probe, and Nexus went dark. None of those facts is equivalent to company confirmation.
Consumers do not need to wait passively. Credit freezes, new-account monitoring, stronger account recovery controls, skepticism toward Real ID phishing, and medical-benefit review directly address the ways document images can be abused. The right posture is serious but evidence-based: treat exposure as possible, treat criminal counts as unverified, and watch for findings that establish the true source and affected population.