A suspected massive data breach at Louisiana-based identity verification company IDScan may have exposed more than 150 million driver’s license and passport photos belonging to people in the United States and Canada, according to a report published in early September 2026 by independent security journalist Brian Krebs.
A dark web site called Nexus launched this week claiming to let users search a database of stolen identity documents sourced from a “major identity verification company.” A post advertising Nexus on a known Russian cybercrime forum said the site added approximately 500,000 new documents daily, suggesting the attackers may have had near real-time access to the compromised systems. Customer photos were also listed as searchable where available.
Krebs confirmed the data was authentic after finding his own driver’s license in the database. Security researcher Zach Edwards, whose ID was also found in the breach, assisted in identifying IDScan as the likely source. IDScan is used by major tech and consumer brands to verify tens of millions of IDs worldwide each month — including at bars, cannabis retailers, and car rental agencies.
Secretary of Defense Pete Hegseth was among those whose photos appeared on the site. A Department of Defense spokesperson told TechCrunch it is “aware of these reports and is evaluating them.” IDScan’s chief operating officer Jillian Kossman told Krebs the company was investigating. The FBI’s field office in New Orleans is also reported to be probing the breach. IDScan’s CEO did not respond to TechCrunch’s request for comment.
Nexus went offline shortly after Krebs’ report was published.
Security experts and privacy advocates have long warned that companies retaining large volumes of identity documents over extended periods create significant targets for hackers. The breach arrives as governments are increasingly enacting age verification laws that require users to upload identity documents to access certain websites and apps. By most accounts, this would be the largest known single breach of identity documents in recent memory.
Source: TechCrunch