TechNewsReel
Live

FBI Probes Breach of 153 Million U.S. and Canadian Identity Documents

A dark web service selling digital scans of passports and licenses likely stems from a breach at identity verification firm IDScan.

TechNewsReel Newsroom · September 4, 2026

The FBI's New Orleans field office is investigating a massive data breach after a dark web service began selling digital scans of more than 153 million government-issued identity documents. The leak, which includes passports and driver's licenses from the United States and Canada, represents one of the largest compromises of official identification in history.

The stolen data was offered for purchase through a dark web entity known as "Nexus." Reports from Krebs on Security and TechCrunch indicate the breach likely originated from IDScan, a Louisiana-based identity verification company utilized by various major brands. The scale of the exposure is immense; the database contains high-profile targets, including U.S. Defense Secretary Pete Hegseth. An FBI spokesperson confirmed that the bureau is currently "looking into the incident."

The Risk of Centralized Identity Storage

This breach arrives as governments increasingly implement age-verification laws that mandate citizens upload sensitive identity documents to third-party services. Security experts have long cautioned that this trend creates "honeypots"—centralized repositories of high-value data that serve as primary targets for sophisticated cybercriminals. By consolidating millions of official documents in a single location, companies like IDScan inadvertently increase the systemic risk to the populations they serve.

Implications for Global Security

The nature of this breach is particularly damaging because it involves digital scans—actual photos of the documents—rather than simple text-based data. These images are considered the "gold standard" for Know Your Customer (KYC) protocols used by banks, cryptocurrency exchanges, and other digital services to prevent fraud. With access to these high-fidelity scans, bad actors can execute highly sophisticated identity theft, bypassing security checks that rely on visual verification of government IDs.

Next Steps in the Investigation

Federal investigators are now working to determine the exact point of entry used by the attackers and whether the breach was a one-time exfiltration or an ongoing compromise. While the FBI continues its probe, security researchers are monitoring the dark web to see if the Nexus service expands its offerings or if the dataset is leaked publicly. It remains to be fully confirmed how long the attackers had access to IDScan's systems and whether other verification providers have been similarly targeted.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.