What happened
A new identity theft service called Nexus appeared on the Russian cybercrime forum Exploit at the end of August, advertising digital scans of identity documents for more than 153 million people in the United States and Canada. According to Krebs on Security, the service also lists more than 10 million identification cards, over 3 million travel documents and international IDs, and at least 579,000 medical cards.
The service claims it has been continuously exfiltrating data for over a year, and the record count is growing. The number of drivers license records listed jumped by nearly 400,000 in a single 24 hour period, which suggests freshly stolen data is being added on a regular schedule. The records include front and back scans, plus infrared and ultraviolet versions, with date and time stamps attached to each image file.
Krebs on Security traced the timestamps to real-world events and pointed to idscan.net, a New Orleans based identity verification company, as the apparent source. The company says it performs more than 21 million verifications monthly at over 20,000 locations, and its customer list includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment. The FBI's New Orleans field office has opened an official investigation into an apparent breach involving idscan.net, which confirmed it is looking into the matter but has not issued a substantive statement. Licenses belonging to U.S. Defense Secretary Pete Hegseth and an FBI assistant director are among the records for sale.
Why this is a GRC story
This is third-party risk at national scale. A single identity verification vendor sits inside the onboarding flow of thousands of businesses, and its data is only as safe as the weakest contract and the least monitored system in that chain. One compromise at a vendor concentrates the exposure of every customer that trusted it with identity documents.
The data type makes it worse than a typical credential dump. Drivers licenses are used to open credit lines, verify employment and pass KYC checks, so the scans enable account-takeover and fraud long after the breach itself. Researcher Larry Baldwin told Krebs the service could also expose people who cannot change their appearance, including domestic violence survivors and protected witnesses.
For GRC teams, the lesson is to treat identity data processors as critical vendors: inventory where customer documents flow, contract for breach notification and indemnities, and verify how the vendor stores and deletes the data. Researcher Zach Edwards put it bluntly: these systems put sensitive data into more and more third-party vendors, and there is not nearly enough oversight to make sure they are safe.
What to watch
Watch whether the FBI confirms the source breach, whether idscan.net and its customers trigger breach notification obligations, and whether stolen license data shows up in credit fraud and account-takeover attempts. The record count is still climbing, so the exposure may grow before it is contained.
Attribution: Analysis based on Krebs on Security's reporting and related public reporting. This article is original commentary, not a repost of the source material.
