According to reports by cybersecurity expert Brian Krebs, the online verification service IDScan has been hacked, resulting in the sale of digital scans of over 153 million driver’s licenses and other identification documents on the dark web platform called Nexus. The documents primarily belong to citizens of the United States and Canada. Nexus, a criminal platform operating on the dark web, was exposed in early September 2026. A cybercriminal promoted it on a Russian-speaking forum called Exploit, even offering a scan of Krebs’ own driver’s license as a “free sample” to verify the authenticity of the data. The database included not only driver’s licenses but also over 10 million identity cards, around 3 million travel documents, and more than 579,000 medical cards, including those for cannabis dispensaries. It is also reported to have included identification documents of high-ranking officials, such as the U.S. Secretary of Defense and FBI agents. The Nexus database was updated in real time, adding about 500,000 new documents daily, suggesting an active and direct leak from a third-party system. Investigations have linked this breach to IDScan.net, a company specializing in identity verification and fraud prevention. The company provides scanning services for large retailers like Target, FedEx, and Hertz, as well as for cannabis dispensaries. When customers presented their identification at a counter, the image was intercepted or siphoned. Unlike traditional data breaches involving passwords or emails, Nexus offered high-resolution scans of both sides of documents, profile photos, infrared and UV verification images, and location timestamps. The platform functioned like a paid search engine, enabling dark web buyers to search for specific individuals or purchase batches of documents to bypass identity verification processes (KYC) used by banks, credit agencies, and online platforms. The FBI’s New Orleans office has launched a criminal investigation into the breach, and IDScan.net has also initiated internal investigations, facing multiple legal challenges. Although the Nexus website was taken down from the dark web after the breach was exposed, experts warn that the compromised database may still be circulating among criminal networks. This incident has raised concerns about the reliability and effectiveness of online identity verification systems, which governments have increasingly promoted. Centralizing millions of identification documents for verification creates attractive targets for hackers. When these systems are breached, they can be exploited for identity theft rather than preventing it. Previous incidents have shown the risks of such centralized databases. For example, an unsecured database from a subsidiary of IDScan’s competitor, IDMerit, exposed over a billion records and sensitive personal information online, effectively providing cybercriminals with a ready-made identity theft toolkit. Similarly, a breach at a subcontractor of Discord led to the leak of approximately 70,000 photos of identification documents that were originally collected for age verification to protect minors. Despite these risks, governments continue to push for the widespread use of online identity verification. The European Union, for example, has announced plans to implement identity verification for internet users, possibly through a digital identity card.