A hacking forum listing has put a number in front of a problem security researchers have warned about for years: what happens when the company that verifies your identity gets breached. On September 11, 2026, the New York Post ran the headline “Massive hack gives scammers access to over 150 million drivers licenses,” pointing to a dark web service called Nexus that is advertising searchable scans of driver’s licenses, passports and other government-issued IDs. The vendor at the center of the story, Louisiana-based identity verification company IDScan.net, has confirmed a breach of its own cloud environment. What it has not confirmed is the headline number.

That gap between what a company admits and what a hacker advertises is the real story here, and it is one that will keep playing out as more of these cases surface. Below is a breakdown of what is confirmed, what is still just a claim, and why an ID verification breach carries different stakes than a typical password leak.

What IDScan.net Has Actually Confirmed

IDScan.net posted an incident notice acknowledging that an unauthorized third party accessed its cloud environment. The notice states that the intruder may have accessed and copied certain customer information, including full names, driver’s license numbers, and other government-issued identification numbers such as passport numbers. That is the extent of what the company itself has put in writing. IDScan.net’s notice does not publish a total count of affected records, and the company has not verified the scale of the data now circulating on the dark web.

IDScan.net operates as a business-to-business identity verification service. Rather than selling directly to consumers, it licenses scanning and age-verification tools to retailers, logistics firms, car rental companies and cannabis dispensaries that need to confirm a customer’s identity or age before a transaction. That business model is exactly why a breach here reaches so far beyond the company’s own name recognition. Most people who had their ID scanned through an IDScan.net-powered kiosk or app never signed up for IDScan.net directly. They interacted with a front-facing brand and never saw the vendor behind the scan.

Inside Nexus: The Marketplace Selling the Data

The data itself surfaced on Nexus, a dark web identity theft service advertised on Exploit, a Russian-language cybercrime forum long used to broker stolen databases, malware kits and network access. Nexus is being marketed as a searchable lookup tool rather than a raw file dump, which is a meaningful distinction. A searchable interface lets a buyer query a name or partial number and pull a matching scan on demand, the same convenience a legitimate verification company offers, just pointed at fraud instead of compliance.

Forum listings like this are marketing copy as much as they are evidence. Sellers on Exploit and similar forums have every incentive to inflate record counts, since a bigger number draws more buyers and a higher price. That does not mean the Nexus figures are fabricated. It means they have not been independently verified by IDScan.net, by law enforcement, or by any outside security firm, and reporters covering the story have been careful to frame the total as a claim rather than a confirmed fact.

Confirmed Facts vs. Hacker Claims

Separating what multiple outlets have verified from what only the seller has stated is the difference between reporting the story straight and amplifying a criminal’s sales pitch. Here is how the numbers currently break down.

ClaimStatusSource
IDScan.net cloud environment accessed by unauthorized third partyConfirmed by IDScan.netIDScan.net incident notice
Names, driver’s license numbers and passport numbers may have been copiedConfirmed by IDScan.netIDScan.net incident notice
FBI is investigating the reported sale of driver’s licensesConfirmedFBI statement reported by multiple outlets
153,347,439 identity documents for saleUnconfirmed, hacker-supplied figureNexus listing on Exploit forum
“More than 150 million” driver’s licenses exposedUnconfirmed, hacker-supplied figureNexus advertising, cited by New York Post
10 million-plus ID cards included in the troveUnconfirmed, hacker-supplied figureNexus advertising
Hertz, FedEx, Target and dispensaries used IDScan.net servicesReported client relationships, not confirmed as individually breachedReports naming IDScan.net’s customer base

The pattern in that table is common to breach disclosures generally. A company confirms categories of exposed data without a total count, while the party actually selling the data supplies a headline number nobody outside the transaction can check. Readers searching for “IDScan.net breach” or “150 million driver’s licenses hacked” today are mostly finding the same unverified figure repeated across outlets that all trace back to the same forum post.

The Client Roster Tied to the Breach

Reports on the incident name Hertz, FedEx, Target and marijuana dispensaries among the businesses that have used IDScan.net’s identity verification tools. None of these companies has been confirmed as individually breached. What connects them to the story is that each is a downstream user of the same verification infrastructure, the kind of B2B software relationship most customers never think about when they hand over a license at a rental counter or a delivery pickup window.

That is the structural risk in identity verification as an industry. A single vendor breach does not just expose one company’s customer list, it potentially touches everyone who scanned an ID at any business running that vendor’s software, across industries that have nothing else in common. A car rental counter and a dispensary counter share no supply chain, no executive team and no IT department, yet both can end up in the same incident report because they both bought the same verification tool.

The FBI Opens an Investigation

The Federal Bureau of Investigation has confirmed it is looking into reports that tens of millions of driver’s licenses tied to the United States and Canada are being sold on the dark web. An open FBI investigation does not validate the 150 million figure, but it does confirm the case has moved past a forum post and into a formal inquiry, the kind of step that typically follows corroborating evidence from victims, financial institutions, or the verification company itself.

Cross-border identity theft cases like this one are notoriously hard to prosecute. The seller operates through a Russian-language forum, the marketplace brand is Nexus, and the underlying data reportedly spans both US and Canadian license formats. Even a full confirmation of the breach scope will not necessarily translate into an arrest, since forums like Exploit have historically operated with minimal disruption from Western law enforcement.

What Data Is Reportedly at Risk

Per IDScan.net’s own notice, the categories of data that may have been accessed or copied include full legal names, driver’s license numbers, and other government-issued ID numbers such as passport numbers. That combination is more dangerous than a typical credential leak because a driver’s license number cannot be reset the way a password can. A leaked password gets changed in thirty seconds. A leaked license number stays valid until the physical document expires or the holder proactively requests a reissue, which in most US states requires proving identity theft occurred in the first place.

Scanned license images, if included in what Nexus is selling, raise the stakes further. A photo scan captures the license holder’s face, signature, birth date, address and the document’s security features in one file, which is precisely the input a fraudster needs to produce a convincing fake for account takeover, synthetic identity fraud, or bypassing know-your-customer checks at a bank or exchange that itself relies on document verification. Driver’s license standards themselves are set nationally by the American Association of Motor Vehicle Administrators, whose format specifications are what make a scanned license so easy to validate, and to forge, once the underlying data is exposed.

Why a Stolen Driver’s License Beats a Stolen Password

Security teams rank breach severity partly by how easy the exposed data is to change after the fact. Email addresses are cheap to rotate. Payment card numbers get reissued by the bank within days. Driver’s license numbers sit at the opposite end of that spectrum alongside Social Security numbers, static identifiers that follow a person for years and get reused across dozens of unrelated verification checks, from opening a bank account to renting a car to buying age-restricted products.

That durability is exactly what makes identity verification vendors attractive targets. A breach at a single payment processor yields card numbers with a shelf life measured in days once banks detect fraud and reissue. A breach at an identity verification company yields documents that remain useful to a fraudist for years, and that can be resold, reused, and recombined with data from other breaches to build a complete synthetic identity.

2026’s Run of Identity-Document Breaches

The IDScan.net case does not stand alone this year. Government ID and driver’s license data has shown up in several major incidents across 2026, each with its own disclosure pattern and its own gap between confirmed and claimed numbers.

IncidentData TypeReported ScaleVerification Status
IDScan.net / Nexus listingDriver’s licenses, passports, names150M+ claimedBreach confirmed by vendor, scale unconfirmed
Florida DMV-linked claimDriver and vehicle records~200K records claimedUnconfirmed by state agency
McKesson / ShinyHunters claimHealth and personal records284M records claimedUnconfirmed by company
Trezor email system breachCustomer email addresses347K emails sentConfirmed by Trezor
Roanoke phishing-linked breachSocial Security numbersNot fully disclosedConfirmed, scope limited

Two things stand out across that list. First, the biggest numbers in 2026’s breach headlines consistently come from the party selling the data, not the party that lost it, a dynamic that has held steady across identity verification, healthcare data and government records alike. Second, driver’s license and government ID data keeps surfacing as a distinct category from financial data, which suggests fraud crews are treating identity documents as a standalone commodity rather than a byproduct of financial breaches.

Market Impact: A Reckoning for ID-Verification Vendors

Identity verification has grown into its own software category over the past several years, driven by age-verification laws, know-your-customer rules in finance and crypto, and retailers wanting to cut fraud at checkout. That growth built a small set of vendors, IDScan.net among them, that now sit in the data path of an enormous volume of consumer transactions without most consumers ever hearing their name.

A confirmed breach at one of these vendors puts pressure on every company that outsources identity checks rather than building them in-house. Procurement teams at retailers, rental agencies and finance platforms are likely to start asking harder questions about where scanned ID data is stored, how long it is retained, and whether a vendor’s cloud environment has been independently audited, questions that a lot of vendor contracts currently leave vague. Expect the identity-verification sector to face the same kind of vendor-risk scrutiny that payment processors went through after the retail card breaches of the early 2010s, just with driver’s licenses and passports in place of card numbers.

The knock-on effect could reach further than IDScan.net’s direct customer base. Businesses that rely on IDScan.net-verified documents to satisfy their own compliance obligations, including age verification for restricted products, may need to demonstrate to regulators that they have a plan for customers whose underlying identity documents are now circulating on a criminal marketplace.

What to Do If You’ve Verified Your ID With a Third Party

There is no consumer-facing way to check whether a specific license number appears in the Nexus listing, since the marketplace is not indexed by mainstream breach-lookup tools like Have I Been Pwned and IDScan.net has not published a searchable notification tool of its own. That leaves a handful of practical steps that apply whether or not your specific record is confirmed in the leak.

1. Check your email against known breach databases (haveibeenpwned.com)
2. Place a fraud alert or credit freeze with all three credit bureaus
3. Monitor for a new driver's license application you did not file
4. Watch for account-opening notices from banks, lenders or crypto exchanges
5. Report suspected misuse at identitytheft.gov and file an IC3 complaint
6. Ask any business that used IDScan.net whether your record was affected
7. Consider requesting a replacement license number from your state DMV
   if you confirm your document was compromised

The credit freeze step matters more here than in a typical password breach, because the goal is blocking new-account fraud, not just changing a login. A frozen credit file stops most attempts to open new lines of credit using a stolen license as identity proof, which is the most common way stolen government ID data gets monetized. Victims can file a report directly at identitytheft.gov and submit a complaint through the FBI’s Internet Crime Complaint Center.

What Businesses Relying on ID Verification Vendors Should Do

Companies that use any third-party identity verification service, not just IDScan.net, have a narrower window to act than individual consumers. Security teams should confirm in writing whether their vendor stores raw document images or only extracted metadata, since the former carries far greater exposure if a breach occurs. Contracts should specify a maximum retention period for scanned documents, and procurement should push for evidence of independent security audits rather than accepting a vendor’s self-attestation. The FTC’s data breach response guide for businesses and NIST’s identity and access management guidance are useful starting points for vendor-risk reviews.

Legal teams at any business named as an IDScan.net customer should also expect customer inquiries and, depending on state law, may face notification obligations of their own even though the breach occurred at the vendor rather than in their own systems. Several states treat a vendor breach involving a business’s customer data as triggering the same disclosure rules as a direct breach.

Predictions: Where This Story Goes From Here

A few things are likely to play out over the coming weeks as the FBI investigation and public reporting continue.

  • IDScan.net will likely face pressure to publish a confirmed record count, either voluntarily or through regulatory or litigation discovery, narrowing the gap between its notice and the Nexus marketing claim.
  • At least one of the named client companies (Hertz, FedEx, Target or dispensary operators) will probably issue a public statement clarifying whether its own customers were affected, given the reputational exposure of being named without confirmation.
  • Expect state attorneys general, particularly in states with strong breach notification laws, to open inquiries into IDScan.net independent of the FBI’s federal investigation.
  • Watch for copycat or rebranded listings of the same dataset on other forums beyond Exploit, a common pattern once a large identity-document trove starts circulating.
  • This incident will likely accelerate calls for stricter data retention limits on identity verification vendors, similar to the rules already pushed for after previous large-scale ID document leaks.

None of these are guaranteed outcomes. They follow the pattern set by comparable breaches this year, where confirmed facts arrive slowly and in pieces while unverified numbers dominate the first weeks of coverage.

Frequently Asked Questions

Is the IDScan.net breach confirmed?

Yes, IDScan.net has confirmed that an unauthorized third party accessed its cloud environment and may have copied customer data including names, driver’s license numbers and other government ID numbers. The company has not confirmed a total record count.

Is the 150 million or 153 million figure confirmed?

No. That number comes from the Nexus listing on the Exploit forum, the marketplace selling the data. It has not been independently verified by IDScan.net, the FBI, or any outside security researcher.

What is Nexus?

Nexus is a dark web identity theft service advertised on the Exploit cybercrime forum. It offers searchable access to scanned identity documents rather than a simple file download.

Were Hertz, FedEx and Target hacked?

Reports name these companies as businesses that have used IDScan.net’s verification services, not as separately breached organizations. None of them has been confirmed as individually compromised.

Is the FBI investigating?

Yes. The FBI has confirmed it is investigating reports that tens of millions of US and Canadian driver’s licenses are being sold on the dark web.

How can I tell if my driver’s license data was exposed?

There is currently no public, searchable tool confirming individual records in the Nexus listing. The most practical steps are placing a credit freeze, monitoring for unauthorized new accounts, and contacting any business that used IDScan.net to ask directly.

What should I do if I think my license was compromised?

File a report at identitytheft.gov, submit a complaint to the FBI’s IC3, place a fraud alert or freeze with the major credit bureaus, and contact your state DMV about reissuing your license number if you confirm misuse.

Why is a driver’s license breach worse than a password breach?

A password can be changed instantly. A driver’s license number is a static identifier that stays valid for years and gets reused across financial, retail and government verification checks, which makes it far more durable and valuable to fraudsters once exposed.