<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>IDScan.net - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/idscan.net/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Tue, 06 Oct 2026 07:35:51 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/idscan.net/index.xml" rel="self" type="application/rss+xml"/><item><title>153M Driver's Licenses for Sale: The IDScan.net Nexus Leak</title><link>https://phishfort.com/idscan-nexus-153-million-drivers-licenses-breach/</link><pubDate>Sun, 06 Sep 2026 14:00:00 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/idscan-nexus-153-million-drivers-licenses-breach/</guid><description><![CDATA[<p>In September 2026, a dark web identity theft service called Nexus offered searchable access to more than 153 million US and Canadian driver&rsquo;s license scans, plus millions of other ID documents. KrebsOnSecurity traced the likely source to IDScan.net, an identity verification provider used by rental counters and dispensaries, and the FBI&rsquo;s New Orleans field office opened an inquiry. Because ID scans cannot be changed like passwords, the data can fuel account opening fraud, account recovery attacks and targeted phishing for years.</p>]]></description><content:encoded><![CDATA[<p>In September 2026, a dark web identity theft service called Nexus offered searchable access to more than 153 million US and Canadian driver&rsquo;s license scans, plus millions of other ID documents. KrebsOnSecurity traced the likely source to IDScan.net, an identity verification provider used by rental counters and dispensaries, and the FBI&rsquo;s New Orleans field office opened an inquiry. Because ID scans cannot be changed like passwords, the data can fuel account opening fraud, account recovery attacks and targeted phishing for years.</p>
<p><strong>Summary</strong></p>
<ul>
<li>Nexus, advertised on the Russian-language cybercrime forum Exploit, claimed documents for more than 170 million people in North America.</li>
<li>The listing included more than 153 million driver&rsquo;s licenses, 10 million ID cards, 3 million travel documents and about 579,000 medical cards.</li>
<li>Some records included front and back images plus infrared (IR) and ultraviolet (UV) scans, the imagery ID verification systems use to validate physical documents.</li>
<li>Timestamps on stolen images matched ID scans at Hertz rental counters and a Planet13 dispensary, pointing to <a href="http://IDScan.net" target="_blank" rel="noopener noreferrer nofollow">IDScan.net</a> as the likely source.</li>
<li>Nexus went offline after the report, but the data is likely to resurface. Organizations that rely on ID documents should expect more convincing fraud and phishing.</li>
</ul>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1791211107306-pasted-image_hu_65034a716cd3e83f.webp 480w, /img/1791211107306-pasted-image_hu_9e065d773a2dc90e.webp 768w, /img/1791211107306-pasted-image_hu_ada14aab462c0bca.webp 1200w, /img/1791211107306-pasted-image_hu_437b21abc90c0852.webp 1600w, /img/1791211107306-pasted-image_hu_7618cd08d116eada.webp 2000w, /img/1791211107306-pasted-image_hu_faef77045f781e6e.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791211107306-pasted-image.png"
          srcset="/img/1791211107306-pasted-image_hu_cd896abeae1b27cf.png 480w, /img/1791211107306-pasted-image_hu_efa0f058a8d815b.png 768w, /img/1791211107306-pasted-image_hu_8132c9b841717d8c.png 1200w, /img/1791211107306-pasted-image_hu_e55ec87e2c9a6b19.png 1600w, /img/1791211107306-pasted-image_hu_b08856baacd6bac2.png 2000w, /img/1791211107306-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="1117"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="what-happened-in-the-idscannet-and-nexus-leak">What happened in the IDScan.net and Nexus leak?</h2>
<p>Nexus, a new identity theft service on the Exploit forum, sold searchable access to identity documents and claimed it had been continuously exfiltrating new data for more than a year. Security journalist Brian Krebs reported that the number of listed licenses grew by nearly 400,000 in 24 hours, which suggests an ongoing compromise rather than a one-time leak.</p>
<p>Krebs began investigating after a source told him his own Virginia driver&rsquo;s license was being offered as a free sample. By matching image timestamps with the dates and times people had their IDs scanned at Hertz counters and a Planet13 dispensary, he traced the apparent source to IDScan.net, a Louisiana-based identity verification company. TechCrunch also reported that the evidence pointed to a breach of a major ID verification service.</p>
<p>The listing claimed:</p>
<ul>
<li>
<p>More than 153 million driver&rsquo;s licenses.</p>
</li>
<li>
<p>More than 10 million ID cards.</p>
</li>
<li>
<p>More than 3 million travel or international identity documents.</p>
</li>
<li>
<p>About 579,000 medical cards.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1791211173192-pasted-image_hu_6f305e5d7be5d632.webp 480w, /img/1791211173192-pasted-image_hu_4b8a2c2e6cf1f78c.webp 768w, /img/1791211173192-pasted-image_hu_808d206fcbe6483c.webp 1200w, /img/1791211173192-pasted-image_hu_d2bb9de0394c889e.webp 1600w, /img/1791211173192-pasted-image_hu_42ce88f62bf01b3.webp 2000w, /img/1791211173192-pasted-image_hu_a326a2fabf74e31b.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791211173192-pasted-image.png"
          srcset="/img/1791211173192-pasted-image_hu_9aacee02c88e658.png 480w, /img/1791211173192-pasted-image_hu_4bcb93bc9a7bda5e.png 768w, /img/1791211173192-pasted-image_hu_784f2f9a7c98a55a.png 1200w, /img/1791211173192-pasted-image_hu_321d5a1be2cacf50.png 1600w, /img/1791211173192-pasted-image_hu_4684d61cce144ed.png 2000w, /img/1791211173192-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt="Leaked data breakdown"
          
          width="2048" height="1827"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
</li>
</ul>
<p style="text-align: center;"><em>Leaked data breakdown</em></p>
<p>Shortly after the KrebsOnSecurity report, Nexus replaced its login page with the message &ldquo;This service is no longer available.&rdquo;</p>
<h2 id="who-is-investigating-and-what-are-the-lawsuits-about">Who is investigating, and what are the lawsuits about?</h2>
<p>The FBI&rsquo;s New Orleans field office opened an inquiry into the incident. Krebs reported that records of high-ranking US government officials, reportedly including Defense Secretary Pete Hegseth, appeared in the dataset.</p>
<p>Consumers in California, Florida, Georgia and Louisiana filed lawsuits alleging that <a href="http://IDScan.net" target="_blank" rel="noopener noreferrer nofollow">IDScan.net</a> failed to protect sensitive data and likely violated Federal Trade Commission (FTC) data security guidelines. The plaintiffs seek damages and court-ordered security improvements.</p>
<h2 id="why-are-identity-verification-vendors-such-attractive-targets">Why are identity verification vendors such attractive targets?</h2>
<p>An identity verification vendor processes ID checks for thousands of businesses, so one compromise exposes all their customers. Attackers do not need to breach every rental counter, hotel or dispensary. They only need the shared service behind them.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791211146434-pasted-image_hu_7c2a32d51f015a39.webp 480w, /img/1791211146434-pasted-image_hu_16c7fb0cab8763b9.webp 768w, /img/1791211146434-pasted-image_hu_44181ac47020b03a.webp 1060w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791211146434-pasted-image.png"
          srcset="/img/1791211146434-pasted-image_hu_47391e6886fd848b.png 480w, /img/1791211146434-pasted-image_hu_46f0c46504625ba4.png 768w, /img/1791211146434-pasted-image.png 1060w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt="Partners of ID Scan"
          
          width="1060" height="418"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p style="text-align: center;"><em>Partners of ID Scan</em></p>
<p>ID scanning is now routine in car rentals, hotels, dispensaries, financial services, age-restricted platforms, travel and marketplace onboarding. Each use reduces fraud at the counter but adds to a central store of sensitive data. The more trust and scale a provider accumulates, the more valuable a compromise becomes.</p>
<h2 id="why-is-a-leaked-drivers-license-worse-than-a-leaked-password">Why is a leaked driver&rsquo;s license worse than a leaked password?</h2>
<p>A password can be reset, but a driver&rsquo;s license bundles a legal name, date of birth, address, photo, document number and issuing authority that a person cannot easily change. Many organizations still treat it as strong proof of identity.</p>
<p>Replacing the license changes the document number, but the exposed image and personal details can still be abused. That is why the impact of an ID document leak lasts much longer than a credential leak.</p>
<h2 id="what-can-attackers-do-with-stolen-id-scans">What can attackers do with stolen ID scans?</h2>
<p>Stolen ID scans give attackers verified personal details they can use to pass weak checks and make impersonation believable:</p>
<ol>
<li><strong>Account opening fraud:</strong> submitting stolen document images to open accounts or apply for credit.</li>
<li><strong>Account recovery attacks:</strong> sending a matching ID image to a support team to take over a victim&rsquo;s account.</li>
<li><strong>Targeted phishing:</strong> using real names, addresses and license details to make messages look legitimate, especially when combined with other breach data.</li>
<li><strong>Executive and public figure targeting:</strong> using exposed IDs of executives and officials for impersonation, doxxing or physical security threats.</li>
<li><strong>Bypassing weak KYC (Know Your Customer) checks:</strong> reusing images where verification only checks that a document looks valid, without liveness, device or behavior signals.</li>
</ol>
<h2 id="what-should-organizations-that-collect-id-documents-do-now">What should organizations that collect ID documents do now?</h2>
<p>Organizations that collect or rely on ID documents should reduce what they store and assume the leaked data will be used against their customers. In order of priority:</p>
<ol>
<li><strong>Review what you collect.</strong> If the business only needs a verification result, do not keep the document image.</li>
<li><strong>Minimize retention.</strong> Set clear retention windows and delete raw images once legal, compliance or fraud review needs end.</li>
<li><strong>Reassess vendor exposure.</strong> Ask verification providers what they store, for how long, whether they keep raw images, whether they support deletion or tokenized verification, and how they log and monitor access.</li>
<li><strong>Strengthen account recovery.</strong> Do not accept a government ID alone. Combine known-device checks, recent activity, step-up authentication and manual review for high-risk cases.</li>
<li><strong>Monitor for impersonation.</strong> Watch for lookalike domains, fake support portals, executive impersonation, fraudulent onboarding attempts, social media impersonation and credential harvesting pages that use breached personal data.</li>
<li><strong>Prepare customer guidance.</strong> Explain what happened, what data may be at risk and what people can realistically do.</li>
</ol>
<h2 id="what-should-individuals-do-if-their-id-may-be-exposed">What should individuals do if their ID may be exposed?</h2>
<p>People who think their license may be in the dataset should focus on blocking new-account fraud and spotting targeted phishing:</p>
<ul>
<li>Place a credit freeze with the major credit bureaus.</li>
<li>Monitor bank accounts and credit reports.</li>
<li>Be skeptical of messages that contain accurate personal details.</li>
<li>Watch for account recovery notices you did not request.</li>
<li>Use unique passwords and multi-factor authentication (MFA) on important accounts.</li>
<li>Report suspected identity theft at <a href="http://IdentityTheft.gov" target="_blank" rel="noopener noreferrer nofollow"><u>IdentityTheft.gov</u></a> in the US or through the <a href="https://www.priv.gc.ca/en/privacy-topics/identities/identity-theft/guide_idt/" target="_blank" rel="noopener noreferrer nofollow"><u>Office of the Privacy Commissioner of Canada</u></a>.</li>
</ul>
<h2 id="how-phishfort-helps-after-an-identity-data-leak">How PhishFort helps after an identity data leak</h2>
<p>Leaked identity data makes brand and executive impersonation more convincing. <a href="https://phishfort.com/product/executive-protection/" target="_blank" rel="noopener noreferrer nofollow"><u>PhishFort Executive Protection</u></a> detects and removes fake profiles and doxxing that target executives, and PhishFort Dark Web Monitoring watches underground sources for credential and identity data tied to your brand.</p>
<h2 id="frequently-asked-questions">Frequently asked questions</h2>
<h3 id="was-idscannet-hacked">Was IDScan.net hacked?</h3>
<p>KrebsOnSecurity traced the Nexus data to IDScan.net by matching image timestamps with real ID scans at Hertz and a Planet13 dispensary. The FBI&rsquo;s New Orleans field office opened an inquiry, and consumer lawsuits allege the company failed to protect the data.</p>
<h3 id="how-many-drivers-licenses-were-exposed-in-the-nexus-leak">How many driver&rsquo;s licenses were exposed in the Nexus leak?</h3>
<p>Nexus claimed more than 153 million US and Canadian driver&rsquo;s licenses, plus more than 10 million ID cards, 3 million travel documents and about 579,000 medical cards, covering more than 170 million people.</p>
<h3 id="what-can-criminals-do-with-a-scanned-drivers-license">What can criminals do with a scanned driver&rsquo;s license?</h3>
<p>Criminals can use stolen license scans to open accounts, pass weak KYC checks, take over accounts through support teams and make phishing messages more believable. Executives and officials face added impersonation and physical security risks.</p>
<h3 id="does-getting-a-new-drivers-license-protect-me">Does getting a new driver&rsquo;s license protect me?</h3>
<p>Only partly. A new license changes the document number, but the leaked image, name, address and date of birth can still be used for fraud, so credit freezes and monitoring remain important.</p>
<h2 id="sources">Sources</h2>
<ul>
<li><a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank" rel="noopener noreferrer nofollow">KrebsOnSecurity: FBI probes service selling 153M driver&rsquo;s licenses</a></li>
<li><a href="https://techcrunch.com/2026/09/02/it-sure-looks-like-hackers-breached-a-major-id-card-verification-service/" target="_blank" rel="noopener noreferrer nofollow">TechCrunch: It sure looks like hackers breached a major ID card verification service (September 2, 2026)</a></li>
<li><a href="http://USA.gov" target="_blank" rel="noopener noreferrer nofollow">USA.gov: Identity theft</a></li>
<li><a href="https://www.priv.gc.ca/en/privacy-topics/identities/identity-theft/guide_idt/" target="_blank" rel="noopener noreferrer nofollow">Office of the Privacy Commissioner of Canada: Identity theft guide</a></li>
</ul>
]]></content:encoded><category>News</category><category>phishing</category><category>security</category><category>IDScan.net</category><category>Nexus</category><category>driver's licenses</category><category>identity verification</category><category>data breach</category><category>dark web</category><category>identity theft</category><category>KYC</category><category>executive impersonation</category></item></channel></rss>