Skip to content
Breaking:

Breach at IDScan Exposes Over 150 Million Identity Documents, Researchers Report

A dark web marketplace is offering access to U.S. and Canadian driver's licenses and passports allegedly exfiltrated from the identity verification provider.

By The Company Wire3 min read
Share
IDScan — Breach at IDScan Exposes Over 150 Million Identity Documents, Researchers Report
IDScan — Breach at IDScan Exposes Over 150 Million Identity Documents, Researchers Report. Photo: TechCrunch.

Millions of government-issued credentials may have been stolen following a major cyber attack against an identity verification vendor, according to details uncovered by independent security journalist Brian Krebs and first reported by TechCrunch. The compromised records include official identity cards collected during standard identity verification checks across retail and online services.

The security breach surfaced after an illicit dark web portal named Nexus began advertising searchable records containing over 150 million driver's licenses and passports belonging to residents of the United States and Canada. Promotional posts published on a Russian cybercrime forum stated that Nexus ingests roughly 500,000 newly compromised identity records each day from a major verification provider, suggesting attackers maintain ongoing, near real-time access to internal corporate networks.

Operators of the Nexus portal claimed that customer photographs associated with identity documents are displayed when available. Krebs validated the authenticity of the exfiltrated dataset by discovering his own driver's license details within the searchable repository. The exposed database also included identity records and photographs belonging to U.S. Secretary of Defense Pete Hegseth.

A spokesperson for the U.S. Department of Defense did not immediately respond to requests for comment regarding the exposure of senior government official records within the leaked database.

Krebs collaborated with cybersecurity researcher Zach Edwards—whose own identity card was similarly identified within the leaked files—to determine the likely point of exfiltration. Their analysis traced the exposed records to IDScan, an identity verification software firm headquartered in Louisiana. IDScan's platform is utilized by major technology companies and consumer brands to process tens of millions of identity documents globally each month.

IDScan Chief Executive Officer Jimmy Roussel did not respond to requests for comment submitted by TechCrunch. However, IDScan Chief Operating Officer Jillain Kossman informed Krebs that the company is actively conducting an internal investigation. Additionally, Krebs reported that the FBI's field office in New Orleans has launched an inquiry into the intrusion. An FBI spokesperson did not immediately respond to TechCrunch's request for comment.

If fully verified, the intrusion would represent one of the largest single breaches of personal identification credentials recorded in recent years. The leak occurs alongside an expanding rollout of state and federal age-verification statutes that require users to upload official identification cards to gain access to online services. Cybersecurity experts and privacy groups have routinely warned that accumulating vast stores of government credentials within commercial databases creates vulnerable, high-value targets for malicious threat actors.

Sources

  1. TechCrunch

Company: IDScan

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.