TechNewsReel
Live

IDScan Breach Exposes 153 Million Passports and Driver's Licenses

A massive leak of identity documents from US and Canada users has surfaced on the dark web, fueling risks of synthetic fraud.

TechNewsReel Newsroom · September 3, 2026

A massive data breach has exposed the personal identification documents of approximately 153 million individuals, creating a systemic risk of identity theft across North America. The leak involves highly sensitive data, including driver's licenses and passports, which serve as the primary tools for verifying identity in financial and government sectors.

According to reports from Brian Krebs and TechCrunch, the stolen data was advertised on Nexus, a dark web site. The sellers on the platform claimed the documents originated from the United States and Canada. Investigators have identified IDScan, a Louisiana-based identity verification service, as the suspected source of the leak.

The Nature of the Leak

Identity verification services like IDScan are designed to prevent fraud by validating government-issued IDs. However, when these centralized repositories are compromised, they become goldmines for cybercriminals. Driver's license and passport data typically include full names, home addresses, and unique identification numbers. Unlike passwords or credit card numbers, these government-issued identifiers cannot be easily changed or reset, leaving victims vulnerable to long-term exploitation.

Why It Matters

This breach is particularly dangerous because it facilitates synthetic identity fraud. By combining stolen government IDs with other leaked personal information, attackers can create entirely new, fake identities to open bank accounts, apply for loans, or claim government benefits. Because the breach spans two countries and involves millions of records, the scale of potential fraud is immense, placing a heavy burden on credit monitoring services and law enforcement agencies to track the fallout.

What's Next

Industry experts are now monitoring the dark web to determine if the 153 million records are being sold in bulk or targeted for specific high-value fraud schemes. While the suspected source is IDScan, official confirmation and a full accounting of the affected individuals remain pending. Users are encouraged to monitor their credit reports for unauthorized activity and remain vigilant against phishing attempts that may use this stolen data to appear legitimate.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.