via TechCrunch
Major ID Verification Service Breached: 150M+ Driver's Licenses and Passports Exposed
2026 cybersecuritydriver's license data leakidentity verification breachidscannexus dark webpassport data exposure
A suspected massive data breach at a major ID verification service may have compromised the driver's licenses, passports, and other identity documents of millions of people who used them for real-world verification—such as at bars, dispensaries, or car rental agencies.
According to a report by independent security journalist Brian Krebs, the breach involved the theft of a vast database of identity documents from a company that verifies government-issued IDs. The discovery came after a dark web identity theft service called Nexus launched this week, claiming to offer searchable access to over 150 million driver's licenses and passports belonging to U.S. and Canadian residents.
A promotional post on a known Russian cybercrime forum stated that Nexus added roughly half a million new documents daily, sourced from a 'major identity verification company,' suggesting hackers had near real-time access to the company's systems. The post also noted that 'customer photos are displayed if available.'
Krebs confirmed the data's authenticity by finding his own driver's license in the searchable records. Notably, U.S. Secretary of Defense Pete Hegseth was also among those whose photos appeared on the site. The Department of Defense did not immediately respond to requests for comment.
Working with security researcher Zach Edwards—whose ID was also stolen—Krebs identified the likely source as IDScan, a Louisiana-based identity verification service used by major tech and consumer brands to verify tens of millions of IDs monthly. IDScan's CEO, Jimmy Roussel, did not comment, but COO Jillain Kossman told Krebs the company was investigating. The FBI's New Orleans field office is also reportedly probing the breach, though the FBI did not confirm or comment.
Nexus went offline shortly after Krebs's report was published, but the incident underscores the risks of centralized ID verification. As governments worldwide expand age verification laws requiring adults to upload identification documents for website or app access, security experts and privacy advocates have long warned that storing such sensitive data in large repositories creates a tempting target for hackers. This breach, if confirmed, would mark one of the largest known single exposures of identity documents in recent history.
← Previous
Google Dodges Another Breakup Attempt in Antitrust Battle
Next →
Google Spared From Ad-Business Breakup, But Ordered to Overh...
