FBI Probes Alleged Leak of 170 Million Identity Documents from IDScan.net
A dark web marketplace claimed to sell high-fidelity scans of millions of North American IDs, including that of US Defense Secretary Pete Hegseth.
The FBI's New Orleans field office has launched an official inquiry into a massive leak of identity documents allegedly stolen from IDScan.net. The breach, which surfaced via a dark web marketplace, potentially exposes the personal data of millions of North Americans.
A dark web service known as Nexus claimed to be selling scans of over 170 million identity documents. According to the hackers, the haul included 153 million driver's licenses from North America, 10 million ID cards, 3 million international travel cards, and 579,000 medical cards. The stolen records were not limited to ordinary citizens; the data reportedly included the driver's license of US Defense Secretary Pete Hegseth. The Nexus service was shut down shortly after journalist Brian Krebs reported the story.
The Scale of Exposure
IDScan.net, a Louisiana-based identity verification firm, operates on a global scale, performing more than 21 million verifications every month across 20,000 locations worldwide. The company provides critical verification infrastructure for a diverse array of major corporations and regulated industries, including Target, FedEx, Hertz, and various marijuana dispensaries.
What elevates this incident beyond a standard data leak is the nature of the stolen files. The breach included high-fidelity infrared (IR) and ultraviolet (UV) scans of the identity documents. These specific imaging layers are typically used by security professionals and businesses to detect fraudulent IDs and verify authenticity, meaning the hackers have acquired the very tools used to prevent identity theft.
Industry Implications
Security experts have described the event as a catastrophic failure. Because IDScan.net is embedded in the workflows of high-volume retailers and regulated sectors, a significant portion of the North American population may have been affected. The availability of IR and UV scans significantly increases the risk of sophisticated fraud, as criminals can use these high-fidelity images to create near-perfect counterfeit documents that could bypass traditional security checks.
Current Status
While the Nexus marketplace has been taken offline, the FBI continues to investigate the origin of the images to confirm the exact point of failure. It remains to be seen whether the data was exfiltrated directly from IDScan.net's servers or through a vulnerability in the network of locations that utilize their verification software. For now, the focus remains on the potential for widespread identity theft resulting from the exposure of these high-security document scans.