TechNewsReel
Live

FBI Probes Suspected Breach of 153 Million ID Documents at IDScan

A dark web site claimed to have exfiltrated millions of passports and driver's licenses from the Louisiana-based verification service.

TechNewsReel Newsroom · September 2, 2026

The FBI has launched an inquiry into a suspected massive data breach involving a major identity verification service. The incident potentially exposes the sensitive government documents of millions of citizens across North America.

A dark web identity theft site known as Nexus claimed to have stolen more than 150 million driver's licenses and passports. According to security researcher Brian Krebs, the specific figure is 153 million documents originating from the United States and Canada. Security researchers Brian Krebs and Zach Edwards identified the likely source of the leak as IDScan, a Louisiana-based identity verification service utilized by various major consumer and tech brands. Following the public disclosure of the breach, the Nexus website went offline. The FBI's New Orleans field office is currently leading the investigation into the matter.

The Rise of Digital Verification

This breach comes at a time when governments are increasingly implementing age verification laws. These mandates often require adults to upload official identity documents to websites and mobile applications to prove their age or identity. Privacy advocates have long cautioned that the centralized storage of such high-fidelity documents creates an attractive, high-value target for cybercriminals, as a single successful intrusion can yield millions of verified identities.

Implications for Identity Theft

This event represents one of the largest known single breaches of government-issued identity documents. Unlike traditional data leaks that may only expose text-based information like Social Security numbers or email addresses, this breach allegedly includes actual photos of licenses and passports. Such high-fidelity materials provide hackers with the necessary tools to conduct sophisticated identity theft and fraud, making it significantly easier to bypass security checks at financial institutions or other regulated services.

Current Status

IDScan COO Jillain Kossman stated that the company was investigating the claims. While the Nexus site is no longer active, the scale of the alleged exfiltration remains a primary concern for security experts. It remains to be confirmed exactly how the attackers gained access to the systems and whether the full 153 million documents were successfully compromised.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.