A Single ID Verification Vendor Leaked 153 Million Driver's Licenses, Defense Secretary Included
Cybersecurity

A Single ID Verification Vendor Leaked 153 Million Driver's Licenses, Defense Secretary Included

A dark web marketplace called Nexus surfaced on August 31 selling more than 153 million U.S. and Canadian driver's licenses traced to identity verification vendor IDScan.net, and the pile included the license of Defense Secretary Pete Hegseth.

PublishedSeptember 7, 2026
Read time5 min read
Share

A Marketplace Called Nexus

On August 31, 2026, a new dark web storefront calling itself Nexus went live selling scanned identity documents by the millions. The listing covered more than 153 million U.S. and Canadian driver's licenses, over 10 million identification cards, 3 million travel documents, and roughly 580,000 medical cards. That volume alone made it one of the largest identity document leaks on record, and it landed at a moment when identity verification has become the default gatekeeper for everything from age-restricted retail purchases to rental car pickups. Researchers quickly traced the data to IDScan.net, a Louisiana-based identity verification vendor whose scanners sit behind counters at Hertz, Target, FedEx, Caesars Entertainment, and more than 1,000 marijuana dispensaries across 19 states.

IDScan.net had not confirmed the breach at the time reporters reached out, and the company's silence is itself instructive. When SecurityWeek contacted IDScan for comment, it received no response, leaving the public record built entirely from what researchers could verify independently in the stolen data itself. That is the position most enterprises find themselves in when a downstream vendor is compromised: no confirmation, no scope statement, no timeline, just a pile of records for sale and a growing list of people who recognize themselves in it. The vendor's silence does not slow the exposure. It only slows the response.

How a Security Reporter Found His Own License

Brian Krebs did what any skeptical researcher would do: he searched the stolen dataset for himself. He found his own driver's license record, and his mother's, both timestamped to a Hertz rental transaction from June 2025. That single data point mattered because it tied a specific real-world transaction, at a specific company, on a specific date, directly to the leaked records months later. It ruled out coincidence and ruled out a stale or recycled dataset. It confirmed the leak was current, accurate, and tied to a live pipeline of identity documents still flowing through IDScan's systems as recently as last year.

The confirmation also exposed a retention problem that most executives never think about. Plenty of companies manage vendors that touch customer data briefly during a transaction: a payment processor, a KYC check, an age gate. Few of those contracts specify how long the vendor keeps the raw scan, in what format, or under what encryption. IDScan's business model depends on holding onto scanned IDs for fraud modeling and compliance audits. That retention is exactly what turned a routine rental car pickup into a data point sold on a dark web marketplace fourteen months later.

A Defense Secretary in the Dataset

The story escalated fast once researchers found more than an ordinary consumer's license in the pile. Defense Secretary Pete Hegseth's driver's license turned up for sale, alongside the license of an FBI assistant director. The New Orleans FBI field office opened a formal investigation on September 1, 2026, after Krebs alerted authorities, and senior FBI cyber division leaders briefed him personally on a conference call that same afternoon. Security researcher Zach Edwards, whose own information also appeared in the trove, put the underlying problem plainly: "These systems are putting sensitive data into more and more 3rd party vendors, and we don't have nearly the oversight to ensure they are safe."

The Nexus marketplace vanished from the dark web within hours of the story breaking, replaced with a message stating simply that the service was no longer available. That is a familiar pattern: criminal marketplaces go dark the moment they draw law enforcement and press attention, but the underlying dataset does not disappear with the storefront. Once 153 million documents have been packaged, copied, and distributed to buyers, taking the original listing offline does nothing to claw back what has already changed hands.

The Vendor Layer Nobody Underwrites

NCC Group's Tim Rawlins framed the right response for anyone who has outsourced identity verification: "Organizations should design identity systems on the assumption that identity evidence may eventually be compromised." That is a hard sentence for a compliance team to hear, because most identity verification contracts are written the opposite way, as if the vendor's security posture is a settled question answered once at procurement and never revisited. IDScan's client roster spans automotive, banking, gaming, and cannabis retail precisely because identity verification has become commoditized infrastructure, bought off the shelf and rarely audited again once it works.

The uncomfortable truth is that identity verification vendors sit in a blind spot most vendor risk programs were not built for. Payment processors get PCI audits. Cloud providers get SOC 2 reviews. Identity verification vendors that scan a government-issued ID and retain the image often get neither the scrutiny nor the contractual retention limits that the sensitivity of the data would justify. A driver's license scan is a durable, reusable piece of identity evidence, unlike a credit card number that can be reissued. It cannot be rotated the way a compromised password can.

What This Means for Your Vendor Risk Program

If your retail, hospitality, or gaming business runs identity or age verification through a third party, this is the week to pull the contract and ask three questions. How long does the vendor retain the raw scan after the transaction closes. Is that retention encrypted at rest with keys the vendor does not also hold. And does the contract specify a breach notification window shorter than the weeks it took IDScan.net to say nothing at all. If those answers are not on file, the exposure already exists whether or not your specific customers show up in this particular leak.

The roadmap implication goes beyond this one vendor. Identity verification is being bolted onto more checkout flows, delivery confirmations, and loyalty programs every quarter, often by teams optimizing for conversion rate rather than data minimization. The decision in front of every CTO managing that stack is whether to keep treating identity verification as a plug-in integration or to start underwriting it with the same rigor as payments infrastructure. Given what 153 million exposed licenses just proved about the current standard, the plug-in model has run out of runway.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#idscan-net#identity-verification#driver-license-breach#third-party-risk#brian-krebs