A major identity verification service has reportedly suffered a significant data breach, exposing over 150 million driver’s licenses and passports belonging to U.S. and Canadian residents. An identity theft site called Nexus, which recently appeared on the dark web, claimed to provide access to these stolen documents, adding approximately 500,000 new records daily. The Nexus listings even included customer photos when available, with the breach confirmed to involve authentic data, including records of notable individuals such as Secretary of Defense Pete Hegseth.
Investigations led by security journalist Brian Krebs and researcher Zach Edwards suggest that the compromised data likely originated from IDScan, a Louisiana-based company that verifies government-issued ID documents for numerous tech and consumer companies worldwide. IDScan is responsible for validating tens of millions of IDs each month, though its CEO Jimmy Roussel has not commented publicly. The firm’s chief operating officer, Jillian Kossman, stated that the company was actively investigating the incident. Meanwhile, the FBI’s New Orleans field office is reportedly involved in probing the breach.
Nexus took its illicit service offline shortly after Krebs published his report, but the revelation highlights the growing risks associated with companies storing vast quantities of sensitive identity information. The breach emerges amid increasing regulatory demands for online age verification, which often require users to upload government-issued IDs for access to various digital services. Experts and privacy advocates have long warned that such centralized storage of identification data can create significant vulnerabilities to hackers.
This incident is regarded as one of the largest known single breaches of identity documents in recent years. Apart from the potential for identity theft and fraud on a massive scale, the breach raises urgent concerns about data security practices across industries relying on digital ID verification. As the breach continues to be scrutinized by both law enforcement and cybersecurity professionals, affected individuals and organizations alike are urged to remain vigilant against potential misuse of compromised identity credentials.
Start the discussion with a take, question, or market read.