
Every time a privacy expert warned that storing millions of identity documents was a disaster waiting to happen, the industry shrugged. That disaster may have now arrived. According to TechCrunch, a dark web site called Nexus launched this week claiming to let anyone search a database of more than 150 million driver’s licenses and passports belonging to people in the United States and Canada. The alleged source: a major real-world identity verification company whose systems hackers appear to have accessed in near real-time, adding roughly half a million new documents every single day.
The story broke through independent security journalist Brian Krebs, who confirmed the data was real by finding his own driver’s license in the searchable database. Secretary of Defense Pete Hegseth was also identified in the records, with photos listed alongside the documents. A Department of Defense spokesperson said the agency is “aware of these reports and is evaluating them.” That is a polite non-answer for what is, by most measures, one of the largest single breaches of identity documents in recent memory.
Krebs, working alongside security researcher Zach Edwards, whose ID was also caught up in the breach, traced the likely source to IDScan, a Louisiana-based company that verifies tens of millions of identity documents each month for tech firms and consumer brands. Think bars, dispensaries, car rental counters. Any place that scans your physical ID. IDScan’s chief operating officer told Krebs the company is investigating. The FBI’s New Orleans field office confirmed it is also “looking into the incident.” IDScan’s CEO did not respond to requests for comment. Nexus went offline shortly after Krebs published his report, which is the kind of thing that happens when a criminal operation attracts too much attention too fast.
But the damage, if real, is already done. Driver’s licenses and passports contain a dense package of personal data: full legal name, date of birth, home address, photo, document number. That combination is exactly what identity thieves need to open credit accounts, commit fraud, or impersonate someone in a verification system. There is no changing a passport number the way you change a compromised password.
The timing here is hard to ignore. Governments across the US, UK, and Europe have been aggressively pushing age verification laws that require adults to upload their identity documents to access websites and apps. Privacy advocates and security researchers have spent years arguing that centralizing this data creates high-value targets for exactly this kind of attack. This breach is the clearest possible example of what that risk looks like in practice. Companies collecting and storing biometric-grade identity data at scale will always be attractive targets. And when they get hit, the people who had no real choice but to hand over their ID at a bar or a rental counter are the ones who pay the price.