IDScan.net Breach Exposes 153 Million North American Identity Documents
A dark web service is selling millions of government IDs following a cloud security failure at New Orleans-based IDScan.net.
A catastrophic security failure has exposed the personal identity documents of approximately 153 million people across the United States and Canada. The breach, which surfaced in early September 2026, represents one of the largest thefts of government-issued identification in history.
The data is being marketed on a dark web service known as "Nexus," which began selling digital scans of driver's licenses and other identity documents around September 1, 2026. The leak has been traced back to IDScan.net, a New Orleans-based identity verification provider. The company confirmed that an unauthorized third party gained access to customer information stored within its cloud systems on or around that date.
The Mechanics of the Leak
IDScan.net operates as a digital identity verification and fraud prevention platform, providing tools for organizations to scan and authenticate government IDs. Security analysts describe the incident as a "live" leak, noting that the Nexus database appeared to be updating in real-time. This pattern suggests that attackers may have established a continuous siphon of data from the cloud provider rather than executing a single, one-time download.
Industry Implications
The scale of the exposure is unprecedented for this specific type of data. Because driver's licenses serve as primary forms of identity verification for banking, travel, and government services, the breach creates systemic risks for identity theft and financial fraud.
High-resolution scans allow bad actors to create convincing forged documents, potentially bypassing traditional KYC (Know Your Customer) protocols used by financial institutions. The availability of such a massive dataset of verified IDs significantly lowers the barrier for large-scale synthetic identity fraud.
Ongoing Investigations
Law enforcement agencies on both sides of the border have launched responses to the crisis. The FBI's New Orleans field office has opened an official inquiry to determine the exact source of the images and the identity of the perpetrators.
In Canada, the Royal Canadian Mounted Police (RCMP) confirmed they are monitoring the situation. In an official statement, the RCMP noted they remain "engaged with domestic and international law enforcement and cybersecurity partners as appropriate" to mitigate the impact of the exposure. Investigators are currently working to determine the full scope of the compromised data and whether other verification providers were affected by the same vulnerability.