By MFJ Staff | Sources: KrebsOnSecurity, and Malwarebytes
Key takeaway: A breach at your ID-verification vendor is effectively a breach of your own customers’ data — vet retention practices before you route ID scans through a third party.
A dark web marketplace called Nexus began advertising more than 153 million U.S. and Canadian driver’s licenses tied to identity-verification vendor IDScan.net, prompting the FBI’s New Orleans field office to open an investigation.
The listing surfaced August 31, 2026, on the Russian-language cybercrime forum Exploit, first reported by KrebsOnSecurity and also reported by Malwarebytes; the FBI opened its inquiry September 1. Beyond the 153 million driver’s licenses, the seller claimed more than 10 million other ID cards, 3 million travel documents, and 579,000 medical cards. Some records in the database were separately tagged with source notations for military Common Access Cards and commercial driver’s licenses, distinct from the medical-card figure. Unlike a typical credential leak, the exposed files reportedly include front-and-back scans plus infrared and ultraviolet images with timestamps — the same data captured when a physical ID is checked at a register.
IDScan.net, a New Orleans-based identity-verification provider, serves clients including Hertz, Target, FedEx, Motorola Solutions, financial services firm Jack Henry, and Caesars Entertainment, along with more than 1,000 marijuana dispensaries across 19 states. Investigators, including Krebs, matched leaked scans to real rental and travel dates to confirm several licenses were authentic. Nexus went offline shortly after the reporting.
“These systems are putting sensitive data into more and more third-party vendors, and we don’t have nearly the oversight to ensure they are safe,” said researcher Zach Edwards. An IDScan.net spokesperson, Jillian Kossman, said the company could not yet share details but called outside reporting “welcome, and helpful to our team’s investigation.”
Why it matters: For merchants, especially those in age-restricted categories like alcohol, tobacco, vaping, or cannabis, the case is a direct prompt to ask any ID-verification vendor exactly what it stores after a scan, for how long, and whether it retains full document images at all. Lighter-weight age checks that confirm a yes/no match without storing scans carry far less exposure if a vendor is breached.
Source: KrebsOnSecurity; Malwarebytes












