· via TechCrunch
Dark web site offering 150 million stolen IDs points to breach at verification firm IDScan
A dark web identity search site claiming access to more than 150 million US and Canadian driver's licenses and passports has been traced to verification provider IDScan, according to reporting by Brian Krebs.

What happened
Independent security journalist Brian Krebs has uncovered evidence pointing to a suspected breach at a company that verifies government-issued identity documents, according to a TechCrunch report on his findings.
At the center of the story is Nexus, an identity theft service that appeared on the dark web this week. Krebs reports that it advertised searchable access to more than 150 million driver's licenses and passports belonging to people in the United States and Canada. A promotion for the site, posted on a well-known Russian cybercrime forum, claimed roughly half a million new documents were being added every day and credited the supply to a "major identity verification company" — a detail that, as TechCrunch observes, suggests the intruders had ongoing access to the victim's systems rather than pulling off a one-time theft of archived files. Customer photographs were included where they existed.
The data appears to be genuine. Krebs located his own driver's license among the searchable records, and US Secretary of Defense Pete Hegseth was among the people whose photos were listed on the site. A Department of Defense spokesperson told TechCrunch it is "aware of these reports and is evaluating them."
How IDScan became the prime suspect
Teaming up with security researcher Zach Edwards — whose own identity card also turned up in the cache — Krebs traced the likely source of the leak to IDScan, a Louisiana-based provider of identity document scanning and verification technology. According to TechCrunch, the company is relied on by major technology and consumer brands and is involved in verifying tens of millions of identities around the world each month. Its products sit in the exact places where people routinely hand over licenses and passports: bars, cannabis dispensaries, rental counters and similar real-world checkpoints.
IDScan chief executive Jimmy Roussel did not respond to TechCrunch's request for comment. Chief operating officer Jillain Kossman told Krebs the company is investigating, and Krebs reports that the FBI's New Orleans field office is also probing the incident. The FBI did not respond to TechCrunch's inquiry. Shortly after Krebs published his findings, the Nexus site went offline.
Why it matters
The scale is exceptional. TechCrunch notes that, by most accounts, this would be the biggest documented theft of identity documents in years. Unlike a leaked password, a driver's license or passport cannot simply be reset, so everything exposed in this kind of breach remains a permanent resource for identity thieves. The inclusion of photographs compounds the damage, handing criminals raw material for account takeover, synthetic identity fraud and highly convincing phishing.
The timing is also significant. Governments are rolling out age verification laws that increasingly require adults to upload identity documents to websites and apps before granting access. Security experts and privacy advocates have long argued that companies amassing these documents and holding them for extended periods create concentrated targets, and that the eventual breach harms every customer who ever scanned an ID at a bar or rental desk.
Important caveats remain. IDScan has not confirmed an incident, and the attribution rests on the analysis by Krebs and Edwards rather than an admission from the company. But if the findings hold, the case will stand as a defining example of the hidden cost of centralizing identity documents for compliance — a cost that only becomes visible once the data is already gone.
- #data-breach
- #cybersecurity
- #identity-verification
- #privacy
- #dark-web