Veriscan
Incident posture
Timeline
Summary
The FBI is investigating an alleged data breach in which digital scans of millions of driver’s licenses from the United States and Canada were offered for sale on a dark web service called Nexus. Independent journalist Brian Krebs first disclosed the leak, noting that the scans included his own license and that of U.S. Defense Secretary Pete Hegseth, and that many of the documents had recently been processed by businesses using equipment tied to the New Orleans‑based ID verification firm IDScan.net. The firm said an unauthorized third party may have accessed or copied certain customer information stored in its cloud, such as full names and driver’s license or other government‑issued identification numbers, and that it is notifying affected individuals, providing free credit monitoring, and cooperating with federal investigators.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On September 1, 2026, cybersecurity journalist Brian Krebs published a report detailing that a new user on the Russian cybercrime forum Exploit was offering paid access to digital scans of identity documents from more than 170 million people in North America through a service called Nexus. The report noted that the collection included digital scans of over 153 million driver’s licenses from the United States and Canada. Krebs provided an example of a Minnesota driver’s license issued to U.S. Defense Secretary Pete Hegseth and stated that he also located his own license scan and those of several relatives and friends among the offered data. He observed that the affected identification documents shared a common trait: each had recently been scanned by businesses that used scanning equipment linked to the New Orleans‑based ID verification firm IDScan.net. The FBI’s New Orleans field office confirmed to Fox 8 on September 6 that it was looking into the incident, declining to comment further due to the ongoing nature of the investigation.
In response to Krebs’s publication, IDScan.net issued a statement on its website saying that it had taken immediate steps to secure its systems after the report appeared. The company said it had engaged a team of third‑party specialists to help determine the full nature and scope of the potential unauthorized access. IDScan.net also stated that it was cooperating with federal law enforcement agencies investigating the breach. The firm explained that an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud. It noted that the types of information potentially involved could include full names and driver’s license or other government‑issued identification numbers. Although full access to the data required payment, IDScan.net said it was notifying potentially impacted individuals and providing them with free credit monitoring and identity protection services, offering a telephone number and mailing address for inquiries.
IDScan.net’s public description highlights that it scans hundreds of millions of identity documents each year to detect fake IDs and synthetic identities for clients that include car rental companies, casinos, marijuana dispensaries, lending companies, and retailers such as Target, FedEx and Motorola. The company emphasized that, while the investigation continues, it is taking precautionary measures to protect affected individuals. The FBI has not released additional details about the investigation’s progress or any potential attribution of the breach. The breach report remains under active review by federal authorities as of the date of the article.
Sources
Sources available to members: 1 source.