Last updated: Sep 3, 2026
A potentially massive identity data incident is unfolding, with implications both for consumers and for the way organizations think about identity verification.
A dark-web service called Nexus appeared this week claiming to offer access to more than 153 million U.S. and Canadian driver’s license records, alongside millions of other identity documents.
The FBI has opened an investigation.
The full scope and source of the data have not yet been confirmed, so some caution around the early headlines is important. But enough of the dataset has been independently examined to make the incident worth paying close attention to.
We will update this post as new information becomes available.
What happened?
Investigative cybersecurity journalist Brian Krebs was alerted to Nexus after its operator used a copy of Krebs’ own Virginia driver’s license as a sample while advertising the service on a Russian cybercrime forum.
Krebs subsequently searched the service, with permission, for the licenses of more than a dozen friends and family members. He found nine of them.
The records were particularly sensitive. Some reportedly included multiple images of the same license, including the front and back as well as infrared and ultraviolet images.
Those additional images matter because IR and UV scans can be used by sophisticated document-authentication systems to inspect security features and determine whether an identity document is genuine.
Nexus claimed to hold more than 153 million driver’s license records, more than 10 million other identification cards, more than 3 million travel and international identity documents, and at least 579,000 medical cards.
The service has since gone offline.
Where did the data come from?
That remains under investigation.
Evidence uncovered by Krebs points toward IDScan.net, a Louisiana-based provider of identity scanning and verification technology.
Among other evidence, timestamps associated with some of the exposed scans reportedly corresponded with occasions when individuals had presented their licenses at businesses using IDScan technology.
IDScan has not confirmed that its systems were breached or confirmed the scope of any unauthorized access. The company has said it is investigating.
The FBI has also opened an inquiry.
Until those investigations produce additional information, reports that IDScan was definitively breached should be treated as an allegation rather than a confirmed fact.
If you are worried your ID is included
At the time of writing, we have not identified a legitimate public service where individuals can search the Nexus dataset.
That creates another potential risk: opportunistic phishing sites claiming to offer a “Nexus breach checker.”
Do not upload a driver’s license, enter a license number, or provide other highly sensitive identity information to an unverified website claiming it can tell you whether you were affected.
Nexus itself is now offline, so trying to find the original dark-web service is unlikely to provide an answer either.
Consumers who believe their identity information may have been compromised should follow guidance from the FTC and appropriate state authorities, monitor financial accounts and credit reports, and consider a credit freeze if warranted.
We will update this section if IDScan, law enforcement, or a reputable breach-notification provider releases a legitimate way to determine whether an individual was affected.
The connection to hiring fraud and North Korean IT workers
This incident is also relevant to another identity-security problem organizations are confronting: fraudulent remote workers operating under stolen identities.
There is no evidence at this point that the Nexus dataset has been used by North Korean IT workers or other specific threat groups.
But the underlying security problem is closely related.
The FBI and other U.S. government agencies have repeatedly documented North Korean IT worker schemes involving stolen identities, fraudulent or altered identification documents, proxy infrastructure, and third parties who help operators appear to be legitimate workers.
As we recently covered in our North Korean IT Worker media roundup, these schemes can survive surprisingly far into the employment process. A candidate may interview successfully, perform the work competently, and authenticate normally while still concealing who is actually behind the identity.
Read the roundup: https://imper.ai/north-korean-it-workers-media-roundup-august-2026/
That is why a massive repository of genuine identity documents matters beyond traditional identity theft.
If an attacker can obtain convincing or authentic identity artifacts, the question for employers cannot stop at: “Does this person have valid identity documentation?”
It also has to include: “Is the human we are interacting with throughout hiring, onboarding, and employment actually the person we intended to trust?”
The Nexus incident and the North Korean IT worker problem are different stories. But together they illustrate the same architectural limitation: identity evidence can establish important facts about an identity without necessarily establishing continuity of the human using it.
Why this incident raises a bigger question about identity verification
Beyond the immediate breach investigation, the Nexus story highlights a fundamental distinction that is increasingly important as organizations respond to AI-enabled impersonation and social engineering:
Is the identity document genuine, or is the human presenting it actually the person the organization expects?
Those are not the same question.
Document-based identity verification is designed to establish things such as whether an ID appears authentic, whether its data is valid, and in some implementations whether the person presenting it resembles the photograph on the document.
Those capabilities can be extremely useful.
But a genuine identity artifact is still an artifact.
If legitimate identity documents, high-quality document images, associated personal information, and even authentication imagery become available to attackers, organizations cannot assume that possession of convincing identity evidence is sufficient to establish trust.
This becomes particularly important in workforce environments.
Consider a remote candidate moving through several interviews. An employee calling the help desk to recover an account. A contractor joining an organization. An executive making an unusual request over video.
In each case, the organization’s real question is not simply: “Is this ID real?”
It is: “Is this the human we expect to be interacting with, in this context, right now?”
That requires a broader set of signals.
Will digital identity wallets solve this?
The long-term direction of identity verification is already shifting away from repeated uploads of static document images. Under the EU Digital Identity Regulation, every EU Member State is required to provide at least one European Digital Identity Wallet by the end of 2026. The wallets are designed to hold and present credentials such as mobile driving licences, education credentials, and other identity data. The European Commission explicitly lists applying for a job as one of the potential use cases.
The UK is moving in a similar direction with GOV.UK Wallet. Its roadmap includes a digital driving licence, with credentials secured through GOV.UK One Login and a proven identity.
This is a meaningful improvement. Verifiable digital credentials and selective disclosure can reduce reliance on screenshots and scans of physical documents, give users more control over what they share, and potentially reduce the number of businesses retaining complete copies of sensitive IDs.
But stronger digital identity does not make impersonation detection redundant. A wallet can give an organization much stronger assurance that a valid credential was issued and presented. The organization may still need to determine whether the human participating in an interview, requesting account recovery, joining a meeting, or operating an employee account is the expected person in that context.
The likely future is not identity verification or impersonation detection. It is stronger digital identity plus stronger assurance of the human using it.
IDV still has a role
The lesson from this incident should not be that identity verification no longer works.
It is that organizations should be precise about what identity verification can and cannot establish.
Document IDV can be an important identity assurance layer. But when the threat is active impersonation, organizations may also need signals related to the device, network, environment, behavior, interaction history, and context of the person communicating with them.
There is also a privacy consideration.
The more organizations rely on collecting and retaining highly sensitive identity artifacts, the more consequential a compromise of that infrastructure becomes. Driver’s licenses, photographs, dates of birth, addresses, and document security images cannot be rotated as easily as a password.
The developing Nexus story is an unusually stark reminder of that tradeoff.
What we are watching next
This remains a developing story.
The most important unanswered questions are the confirmed source of the records, the number of unique individuals affected, the time period covered by the data, which organizations and workflows generated the scans, whether the reported data collection has actually stopped, and what notification or remediation will be offered to affected individuals.
We will update this article as those answers become available.
The broader security principle is already worth considering: authenticating an identity artifact and detecting an impersonator are different security problems. Organizations increasingly need to be able to do both.
SOURCES AND URLS
Primary reporting – KrebsOnSecurity:
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses
SecurityWeek coverage:
https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web
FTC IdentityTheft.gov guidance:
https://www.identitytheft.gov/Info-Lost-or-Stolen
IDScan privacy/contact information:
https://idscan.net/website-terms-of-service
imper.ai North Korean IT Worker media roundup:
EU Digital Identity Wallet (European Commission):
https://digital-strategy.ec.europa.eu/en/factpages/european-digital-identity-wallet
EU Digital Identity Regulation / rollout timing:
https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation
GOV.UK Wallet:
GOV.UK Wallet digital identity sector guidance (updated September 1, 2026):
https://www.gov.uk/guidance/using-govuk-wallet-in-the-digital-identity-sector

