Pull to refresh
Logo
Hackers had a live feed of a U.S. ID-scan company's data for over a year

Hackers had a live feed of a U.S. ID-scan company's data for over a year

New Capabilities

A dark web service sold scans of 153 million driver's licenses; the FBI is investigating IDScan.net

3 days ago: Live-feed scale emerges

Overview

Updated 1 hour ago

A dark web service called Nexus has been selling scans of more than 153 million driver's licenses from the U.S. and Canada. The images match the work of IDScan.net, a Louisiana company that verifies IDs for Hertz, Target, FedEx and others.

The attackers kept a live feed of every document IDScan.net scanned for over a year. The trove grew by nearly 400,000 records in a single day after the breach became public, and it includes infrared and ultraviolet images that can defeat the very sensors meant to catch fakes.

Why it matters

Stolen scans include infrared and ultraviolet images that can defeat the fake-ID detectors meant to catch fraud.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

153M+
Driver's license records listed on Nexus
Scans cover people in the U.S. and Canada and grew by roughly 400,000 records in 24 hours after the breach became public.
400K
Records added in one day
The growth suggests the attackers kept live access to new scans even after the service was exposed.
21M
Monthly verifications by IDScan.net
The company processes scans at more than 20,000 locations worldwide for brands including Hertz, Target and FedEx.
13+ months
Duration of suspected live access
A scan of journalist Brian Krebs's license is timestamped June 2025, roughly 13 months before the breach became public.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 3 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

June 2025 September 2026

5 events Latest: 3 days ago
Tap a bar to jump to that date
  1. Live-feed scale emerges

    Latest Revelation

    Reports detail the year-long live feed; trove grows by 400,000 records in a day before Nexus goes offline.

  2. KrebsOnSecurity publishes findings

    Revelation

    Investigation links the leaked data to IDScan.net; officials including Secretary Hegseth are among those exposed.

  3. Nexus service launches

    Incident

    Service appears on Exploit forum offering 153 million license scans with Krebs's license as a free sample.

  4. Continuous exfiltration begins

    Breach

    Attackers begin siphoning IDScan.net scans; a timestamped license dated June 2025 confirms the start.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

May–September 2017

Equifax data breach (2017)

Hackers exploited a web application flaw at Equifax and accessed the personal data of about 147 million Americans over several months, including Social Security numbers, birth dates, and addresses.

Then

Equifax's CEO resigned, Congress held hearings, and the company paid at least $575 million in a settlement with federal and state regulators.

Now

The breach became the benchmark for identity-data exposure, prompting the FTC to expand its data-security enforcement and states to tighten breach-notification laws.

Why this matters now

Like Equifax, IDScan.net concentrates sensitive identity data in one vendor. The breach shows the same concentration risk and the same pattern of delayed public disclosure.

September 2022

Optus data breach (2022)

Australia's second-largest telecom was breached, exposing driver's license and passport numbers for more than 10 million customers, including identity documents rather than just account data.

Then

Optus faced a class action and government criticism; the Australian government debated new rules on data retention and breach disclosure.

Now

The incident pushed regulators to treat physical identity documents in corporate databases as high-risk data warranting stricter handling rules.

Why this matters now

Optus set the precedent for breaches that expose government-issued identity documents. The Nexus leak goes further by including the infrared and UV scan layers used to verify authenticity.

Sources

(9)