A dark web identity theft service calling itself Nexus is advertising more than 153 million scanned driver’s licenses from people across the United States and Canada, according to reporting published this week. The listing, which surfaced on the Russian-language cybercrime forum Exploit, also includes over 10 million identification cards, more than 3 million travel documents and international IDs, and at least 579,000 medical cards. The FBI’s New Orleans field office has opened an investigation into the source of the material, and multiple outlets tracing the data trail point to a Louisiana-based identity verification company widely reported to be IDScan.net.

This is a breaking story, and several details remain unconfirmed by the company or by law enforcement. What is clear: a criminal marketplace claims to hold a staggering volume of government-issued identity documents, and the scale alone makes this one of the largest identity document exposures reported in 2026.

What Happened: Nexus Lists 153 Million Driver’s License Scans

Reports dated September 1 and 2, 2026 describe a new dark web identity theft service, Nexus, that appeared this week offering bulk access to scanned government identity documents. The headline figure is more than 153 million driver’s licenses, a number that, if accurate, would dwarf the individual account counts tied to most breaches reported this year. Nexus is not selling account credentials or password dumps. It is selling images: front-and-back scans of physical ID cards, the kind captured by age-verification kiosks, rental car counters, and retail checkout systems.

Alongside the driver’s licenses, Nexus advertises more than 10 million identification cards, over 3 million travel documents and international IDs, and at least 579,000 medical cards. Reporting has not established a single combined total distinct from these four categories, so readers should treat each figure as a separate claim made by the service’s operators rather than a single deduplicated count of victims.

Inside the Nexus Listing: IDs, Travel Documents, and Medical Cards

What sets this listing apart from a typical stolen-data dump is the presentation. According to KrebsOnSecurity’s review of the Nexus introductory post, buyers can inspect sample records before paying. The service’s operators wrote that “records are available to preview before purchase with pertinent information redacted,” and that “customer photos are displayed if available.” That preview model mirrors how legitimate data brokers demonstrate product quality, except the product here is a stranger’s driver’s license photo and personal details.

The operators also claimed a long-running pipeline rather than a single smash-and-grab. Per the same KrebsOnSecurity report, Nexus stated it has “been continuously exfiltrating new data for over a year into our private database.” If that claim holds up, it suggests sustained, undetected access to a data source rather than a one-time theft, which would explain why the volume climbed into the hundreds of millions before anyone noticed.

The Louisiana Connection: IDScan.net Under Scrutiny

Multiple outlets trace the data to a widely used identity verification company based in Louisiana. Reporting citing Brian Krebs’s investigative work, built on timestamp analysis and other technical indicators, names IDScan.net as the likely source. IDScan.net builds ID-scanning hardware and software used at bars, retailers, and rental counters to check ages and verify identity documents. Its reported customer list includes Hertz, Target, FedEx, and Planet13, a marijuana dispensary chain, though there is no confirmation that these specific customers’ scanned records are part of the Nexus listing.

It is important to separate two distinct claims here. First, that IDScan.net is the likely technical source of the leaked images, based on independent research rather than a company admission. Second, that a breach at IDScan.net is “ongoing,” a characterization Nexus’s own operators used and that Krebs relayed. Neither claim has been formally confirmed by IDScan.net or by law enforcement as of this writing, and readers should treat the company’s role as reported, not established.

IDScan.net Responds: “Working Urgently” to Confirm Scope

IDScan.net has acknowledged the situation in a customer notice reported by KrebsOnSecurity. The company wrote: “Earlier today, September 1, we received information suggesting that certain information may have been exposed and that IDScan.net may be implicated.” That statement stops well short of confirming a breach. It confirms only that the company became aware of the allegations and is checking them.

The same notice added: “We are working urgently to validate that information and determine whether any unauthorized access occurred, and the scope of such activity.” That is a standard early-stage incident response posture: acknowledge awareness, avoid premature conclusions, and promise a scoping process. It leaves open whether the eventual finding confirms a full-scale breach, a smaller intrusion later inflated by criminal marketing copy, or something in between.

FBI New Orleans Opens a Formal Investigation

The FBI’s New Orleans field office, whose jurisdiction covers Louisiana, has opened an investigation into the source of the leaked images and the Nexus service itself, according to multiple reports. Federal involvement at this stage typically focuses on identifying the intrusion vector, preserving evidence, and determining whether the activity crosses state or national borders, which it clearly does given the claimed US and Canadian scope of the victim pool.

An open FBI investigation does not equal a criminal charge or a conviction, and no individual has been named as a suspect in connection with Nexus in the reporting reviewed for this story. Anyone who suspects their identity documents were exposed can file a report with the FBI’s Internet Crime Complaint Center (IC3), which routes tips to the appropriate field office.

Timeline: How the Story Broke Over Labor Day Weekend 2026

The Nexus listing appeared on the Exploit forum this week, ahead of the wider reporting that followed on September 1 and 2. IDScan.net’s customer notice is dated September 1, the same day Krebs published his findings tying the timestamps to the company. The FBI’s New Orleans investigation was reported as active by September 2, alongside coverage from Cybernews and other outlets that picked up the story once Krebs’s research began circulating.

DateDevelopment
Late Aug. 2026Nexus service reportedly begins advertising on the Exploit cybercrime forum
Sept. 1, 2026IDScan.net sends customer notice acknowledging a possible security incident
Sept. 1, 2026KrebsOnSecurity publishes timestamp analysis linking the leak to IDScan.net
Sept. 2, 2026FBI New Orleans field office investigation confirmed in press reports
Sept. 2, 2026Cybernews and other outlets expand coverage of the 153M-record claim

Why Identity Verification Vendors Are Now Prime Targets

Identity verification companies sit in an unusual spot in the data supply chain. A retailer checking a customer’s age at the register does not need to store that scan forever, but many verification vendors retain copies for compliance, dispute resolution, or model training. That retention turns a single vendor into a concentration point holding scans from dozens of unrelated brands. One compromised vendor can expose the customers of every retailer, rental agency, and dispensary that used its kiosks.

That concentration risk is not new. Security researchers have warned for years that age-verification and ID-scanning middleware creates a single point of failure across otherwise unrelated businesses. What changed this week is the scale of the alleged exposure and the operators’ claim of a year-long, undetected pipeline, which, if true, points to a monitoring gap rather than a single misconfigured server.

Historical Context: A Pattern of ID Verification and Data Broker Breaches

Large-scale exposure of identity documents is not a new phenomenon, though the reported volume here stands out. Shattered.io has tracked a steady run of major breaches through 2026, including the Manchester Airports Group breach affecting 8.7 million people, the McKesson incident where ShinyHunters claimed 284 million records, and the Rockstar Games breach tied to the same ShinyHunters group, which stole 78.6 million records. Each of those cases involved account or customer data. The Nexus listing is different in kind: it deals in physical identity documents, which are far harder for a victim to simply reset than a password.

A driver’s license cannot be rotated the way a compromised password can. Replacing one requires a trip to a state DMV, a new number, and in some states a waiting period. That is the core reason security teams treat ID-document leaks as more severe than typical credential breaches, even when the headline record count is comparable.

Nexus Listing By the Numbers

Document TypeVolume Advertised by NexusReported Region
Driver’s licenses153,000,000+United States & Canada
Identification cards10,000,000+United States & Canada
Travel documents / international IDs3,000,000+United States & Canada
Medical cards579,000+United States & Canada

These figures come directly from Nexus’s own advertising copy as relayed by researchers, not from an independent audit of the underlying files. Criminal marketplaces routinely inflate record counts to boost buyer interest, so the true number of unique, valid documents could turn out lower once investigators verify the data. It could also turn out higher if the “ongoing” collection claim is accurate and additional records surface later.

Market Impact: A Trust Problem for the ID Verification Industry

The identity verification market has grown fast on the back of age-verification laws, know-your-customer rules in finance, and rental and retail fraud prevention. A breach at a major vendor threatens that growth story directly, since the entire pitch to retailers and regulators is that outsourcing ID checks to a specialist is safer than handling it in-house. If a specialist vendor turns out to be the weak link, business customers have a strong incentive to ask harder questions about data retention before signing new contracts.

Expect procurement teams at large retailers and rental chains to add breach-notification and data-retention clauses to vendor contracts in the coming months. Cyber insurance underwriters are also likely to scrutinize ID-verification vendors more closely during renewal season, given the high per-record liability tied to government identity documents compared with ordinary account data.

Comparing Nexus to Other Major 2026 Data Incidents

IncidentReported RecordsData Type
Nexus / IDScan.net (Sept. 2026)153M+ driver’s licenses (claimed)Government ID document scans
McKesson / ShinyHunters284M records (claimed by attackers)Customer and business records
Rockstar Games / ShinyHunters78.6M recordsAccount and user data
Manchester Airports Group8.7M peoplePassenger and traveler data
Hasbro436 employeesEmployee SSNs and HR data

Lined up against the rest of this year’s disclosures, the Nexus claim is the largest by raw record count and arguably the most sensitive by data type. Passwords get reset, credit cards get canceled, but a scanned driver’s license is a static document tied to a government-issued number that follows a person for years. It sits closer in severity to the exposure of medical and personal data seen in the Hasbro breach that exposed employee Social Security numbers, where the compromised data was similarly permanent rather than easily replaced.

What It Means for Hertz, Target, FedEx, and Other Reported Customers

Reports naming Hertz, Target, FedEx, and Planet13 as IDScan.net customers do not mean those companies’ customer scans are confirmed to be inside the Nexus listing. It means these brands are among the businesses known to use IDScan.net’s verification products, which makes them logical candidates for follow-up questions from regulators and reporters. None of these companies has been named in the reporting reviewed here as having independently confirmed exposure of its own customer data.

Large retailers and rental agencies typically respond to this kind of vendor-side uncertainty by demanding a written scope assessment from the vendor before making any public statement of their own. Expect a quiet period from the named brands while IDScan.net completes the review it described in its customer notice, followed by individual statements only if the vendor confirms specific customer data was involved.

Expert and Industry Perspectives

The clearest on-record perspective so far comes from the parties directly involved rather than outside analysts, since the story is only a day or two old at publication time. Nexus’s own operators, quoted by KrebsOnSecurity, described their process in blunt commercial terms: “records are available to preview before purchase with pertinent information redacted,” and “customer photos are displayed if available.” That framing, lifted straight from e-commerce, underscores how professionalized dark web data markets have become.

IDScan.net’s own statement, also relayed by KrebsOnSecurity, captures the tension every breached or possibly-breached company faces in the first 48 hours: acknowledge enough to seem transparent without confirming a scope that has not yet been verified. The company told customers it received information “suggesting that certain information may have been exposed” and is “working urgently to validate that information and determine whether any unauthorized access occurred, and the scope of such activity.”

What to Do If You Think Your ID Was Exposed

There is no consumer-facing lookup tool confirmed to check specifically against the Nexus listing at this time. Until IDScan.net or law enforcement publishes a verified breach notification, the most useful steps are general identity-protection hygiene rather than anything specific to this case. Shattered.io’s guide to checking whether your data has leaked online walks through the same general lookup tools referenced below in more depth.

  • Check whether your email or accounts appear in known breaches using a free service such as Have I Been Pwned.
  • Place a fraud alert or credit freeze with the major credit bureaus if you have recently had your ID scanned at a rental counter, retailer, or dispensary that may use third-party verification software.
  • Watch for new-account fraud alerts, since a scanned driver’s license combined with a name and date of birth is enough for many identity theft schemes.
  • Use the Federal Trade Commission’s IdentityTheft.gov portal to build a personal recovery plan if you confirm misuse.
  • Report suspected identity theft to the FBI’s Internet Crime Complaint Center at ic3.gov, which forwards relevant tips to field offices, including the one leading this investigation.

Predictions: Where the Nexus Investigation Goes From Here

Based on how similar vendor-breach investigations have unfolded in 2026, a few outcomes look likely over the next several weeks.

  • IDScan.net will likely issue a follow-up statement within one to two weeks, either confirming a breach with a defined scope or disputing the timestamp-based attribution.
  • At least one state attorney general, probably in Louisiana or a state with strong breach-notification laws such as California or New York, will likely open a review once the vendor confirms any scope.
  • Named customers such as Hertz, Target, or FedEx will probably issue carefully worded statements distancing their own systems from the alleged leak while confirming their vendor relationship with IDScan.net.
  • The true record count will likely be revised, in either direction, once independent researchers or law enforcement gain access to a sample of the Nexus database beyond the marketing preview.
  • Expect renewed legislative attention on data retention limits for ID-verification vendors, an issue several state privacy bills have targeted in 2026 but not yet resolved at the federal level.

The Bigger Picture for Data Verification and Trust

The Nexus story lands at an awkward moment for an industry built entirely on the promise of trust. Age-verification laws in several US states now require the exact kind of scanning that IDScan.net provides, which means demand for these services is not going away even if this particular vendor takes a reputational hit. The more likely outcome is consolidation around vendors that can prove stronger data minimization practices, meaning they delete scans quickly instead of retaining them indefinitely.

For now, the story remains fluid. The headline number, 153 million, comes from the criminals selling the data, not from an audited disclosure. That does not make it fiction, but it does mean the final, verified scope of this incident may look different once IDScan.net, the FBI, or independent researchers publish their own findings. Shattered.io will keep tracking this story alongside the rest of its cybersecurity coverage as new details emerge.

Frequently Asked Questions

What is Nexus?

Nexus is a dark web identity theft service that appeared on the Exploit cybercrime forum in late August or early September 2026. It advertises bulk access to scanned driver’s licenses, identification cards, travel documents, and medical cards, primarily from people in the United States and Canada.

Is IDScan.net confirmed to be the source of the leak?

Not formally. Reporting citing timestamp analysis by security researcher Brian Krebs points to IDScan.net as the likely source, and the company has acknowledged receiving information suggesting it may be implicated. IDScan.net has not confirmed a breach or its full scope as of this reporting.

How many people are affected by the Nexus data listing?

Nexus claims more than 153 million driver’s licenses, over 10 million identification cards, more than 3 million travel documents, and at least 579,000 medical cards. These are figures advertised by the criminal service itself and have not been independently audited.

Is the FBI investigating the Nexus breach?

Yes. The FBI’s New Orleans field office has opened an investigation into the source of the leaked images and the Nexus service, according to multiple reports published September 1 and 2, 2026.

Were Hertz, Target, and FedEx customer records leaked?

Those companies are reported as customers of IDScan.net, meaning they use its ID-verification products. There is no confirmation that their specific customer records are part of the Nexus listing, and none of these companies had issued a public statement on this incident at the time of this report.

Can I check if my driver’s license is part of the Nexus leak?

No verified public lookup tool exists for this specific listing yet. General breach-checking tools such as Have I Been Pwned can confirm whether your email has appeared in other known breaches, but they do not currently index the Nexus dark web listing.

What should I do if I recently had my ID scanned at a retailer or rental counter?

Consider placing a fraud alert or credit freeze with the major credit bureaus, monitor your accounts for new-account fraud, and use resources like IdentityTheft.gov if you find evidence of misuse. There is no evidence yet tying any specific retailer’s scans to this leak, but the general precautions apply any time an ID-scanning vendor faces a security incident.

How does this compare to other 2026 data breaches?

By raw record count, the Nexus claim of 153 million-plus driver’s licenses is larger than the Rockstar Games breach (78.6 million records) and the Manchester Airports Group breach (8.7 million people), though smaller than the 284 million records ShinyHunters claimed in the McKesson incident. Unlike those cases, Nexus deals specifically in government ID document scans rather than account or customer records.