You handed over your driver’s license to rent a car, pick up age-restricted goods, or prove you aren't a bot. Now, 153 million North American scans sit in a criminal database called Nexus.
The FBI is investigating. IDScan.net confirmed cloud exposure. And security researchers like Brian Krebs found their own travel timestamps matched the exposed files down to the exact Hertz car rental date. If you enjoyed this piece, you might want to read: this related article.
Credit monitoring won't fix this. You can't rotate your face, your date of birth, or the infrared scan of your state-issued license.
What Actually Happened at Nexus and IDScan
Forget abstract corporate boilerplate. A dark web marketplace called Nexus popped up on a Russian forum advertising 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. For another look on this event, see the latest coverage from The Next Web.
It wasn't a static SQL dump. The database grew by nearly 400,000 records daily. The actors claimed over a year of continuous exfiltration from a major verification pipeline.
IDScan.net—based in New Orleans, handling checks for dispensaries, gun shops, FedEx, and car rentals—admitted unauthorized cloud access starting around September 1, 2026. They quietly posted a notice telling search engines not to index it.
Why Infrared and Ultraviolet Scans Matter
Basic data breaches steal text strings: name, license number, address. You freeze credit, you move on.
Nexus had multi-spectral assets. Front and back images, infrared, and ultraviolet layers. Modern verification software uses these spectrum captures to prove physical card authenticity. Steal those layers, and you bypass liveness or photo-based fraud checks.
An attacker doesn't just pretend to be you on paper. They feed your exact UV-verified card profile into automated onboarding flows for fintech, crypto exchanges, or remote KYC (Know Your Customer) systems.
The Age-Verification Trap Backfired
Lawmakers and liability-averse platforms pushed hard for mandatory ID scans. Age verification laws for social media, retail, and digital services forced millions of ordinary people to snap photos of government credentials and beam them to third-party cloud buckets.
Zach Edwards, a threat researcher at Infoblox, put it bluntly: we are funneling high-entropy identity proof into vendor silos with zero structural oversight.
When Target got dragged into early screenshots of IDScan customer lists, Target rushed to clarify hardware use versus cloud transmission. Good for Target. Cold comfort for the millions whose license scans were harvested from peer vendors who scanned a badge at a counter or a dispensary intake tablet.
Can You Protect Yourself Against This?
No. That’s the honest answer.
Credit freezes stop synthetic credit lines opened with stolen SSNs and plain license numbers. They do not stop someone authenticating an automated digital onboarding portal using a stolen multi-spectral scan of your physical license face.
Stop pretending standard hygiene works here. Do this instead:
- Audit where your physical ID goes. If a local shop or minor app demands a full license scan for something stupid, walk away or show a passport/alternative if risk allows.
- Treat state IDs like compromised private keys. Expect synthetic targeted phishing. Attackers pairing your travel timestamps from a car rental with your actual license scan know where you vacationed and what agency badge you carry.
- Watch for account takeovers tied to KYC re-verifications. If an exchange, digital bank, or service forces a sudden re-scan of your ID, treat the session with extreme paranoia. Verify out-of-band.
- Push back locally. Demand sunset policies from vendors. If a third-party validator holds your raw image scan longer than the transaction window, they are accumulating a honeypot for the next Nexus.
Freeze credit anyway. Enable fraud alerts. Realize the perimeter isn't your password anymore—it's every scan sitting in a vendor cloud waiting for the next zero-day or leaked cloud token.