The Identity Checks Meant to Stop Fraud May Have Created a 153-Million-Record Fraud Kit
An identity check is supposed to prove that a person is real. If the evidence behind that check escapes, the same driver’s licence images, document numbers and security scans can help someone else impersonate them.
IDScan.net has now acknowledged a data-security incident. The Louisiana identity-verification provider says an unauthorised party may have accessed or copied customer information stored in its cloud, potentially including full names and driver’s licence or other government-issued identification numbers.
The admission followed a KrebsOnSecurity investigation into Nexus, a dark-web service that claimed to hold more than 153 million driver’s licence records. IDScan has not confirmed that figure or said that every document advertised by Nexus came from its systems. That distinction must remain attached to the story.
Nexus claimed an identity archive at national scale
Nexus advertised more than 153 million driver’s licences from the United States and Canada, over 10 million identity cards, more than three million travel or international identity documents and at least 579,000 medical cards.
KrebsOnSecurity did more than repeat the operator’s sales pitch. A blank search reportedly returned about 11.5 million pages with roughly 15 results per page. The reporter found his own licence in the service, and nine people who agreed to checks confirmed that timestamps on their records aligned with real journeys or transactions.
Some records included six images: front and back scans in ordinary, infrared and ultraviolet modes. That matters because it is not merely a list of names and document numbers. Multiple spectral images can preserve authenticity signals that verification systems use to distinguish a real document from a crude copy.
The trail led back to places where people had proved their identity
Several timestamps matched Hertz car rentals. Another matched a visit to a cannabis dispensary that had publicly announced an IDScan relationship. IDScan says it performs more than 21 million verifications each month at more than 20,000 locations.
That reach is why the incident is bigger than a conventional vendor breach. Each customer may believe it is collecting one identity document for one transaction. The verification provider can become a point where data from travel, retail, hospitality, age checks and regulated services converges.
KrebsOnSecurity reported that the FBI’s New Orleans field office opened an investigation. Nexus disappeared shortly after the report, replacing its login page with a message that the service was no longer available. Disappearance does not mean deletion, and it does not reveal how many records were sold or copied before the site went dark.
What IDScan has confirmed
IDScan now says the event was limited to VeriScan, reports no known misuse, and offers free credit monitoring and identity-protection services.
Harborside’s notice, dated 3 October, says IDScan reported unauthorised access to part of its cloud system from 4 April to 2 September 2026 and an ongoing investigation. That expanded access period does not establish when each record entered the system or say that access continued after 2 September.
In a notice dated 3 October, Harborside says its retail customers may have had front-of-ID images and scan metadata involved, including the store, approximate device location and validation result. The company says its own systems were not involved and its notice gives no indication that passports, medical cards, phone numbers, email addresses, Social Security numbers, payment information or purchase history were involved for those customers. Those limits are Harborside-specific and do not describe every VeriScan customer.
The notice does not validate the 153 million figure, the claimed year-long exfiltration period or every document category advertised by Nexus. Those remain claims supported by KrebsOnSecurity’s sampling and scale checks, not a complete forensic statement from IDScan or law enforcement.
A leaked licence is not a password you can simply rotate
A password can be changed. A face, date of birth and historical driver’s licence image are far more durable. Even when a licence number changes, old document images can support social engineering, account recovery abuse, synthetic identities and attempts to defeat remote onboarding.
The scans may also expose people whose physical safety depends on limiting where their identity appears. The problem is not limited to credit fraud. A central identity archive can connect a person to a place, date and transaction that they never expected one provider to retain at scale.
What organisations and individuals should do
- Organisations using IDScan should preserve contracts, data-flow diagrams, retention settings and subprocessor information, then ask which account data and locations fall within the investigation.
- Customers should verify whether raw document images were retained, for how long, and whether deletion settings applied to every copy, backup and derived data set.
- Security teams should monitor identity-proofing and account-recovery workflows for reuse of valid document data paired with a different device, network, face or behaviour profile.
- Potentially affected individuals should follow the company’s notification process, use the offered monitoring if appropriate and review financial accounts and credit reports for unusual activity.
- High-risk individuals should consider a credit freeze where available. Monitoring reports activity after it occurs, while a freeze can make new credit harder to open.
- Do not trust a caller or message merely because it contains accurate licence details. Breach data makes targeted fraud more convincing.
The policy question is equally important. Services should collect the minimum evidence required, retain raw document images only when a defensible purpose demands it, and make deletion verifiable. An anti-fraud control becomes a systemic risk when everyone sends the same permanent identity evidence to the same few processors.
The same retention problem appeared after the Heights Finance breach exposed data belonging to people who were not customers. Identity evidence can remain valuable to attackers long after the transaction that justified collecting it has ended.
Sources and further reading
- KrebsOnSecurity: FBI probes service selling 153 million driver’s licences, published 1 September 2026 at 18:40 ET and updated later that day.
- IDScan.net incident notice, updated 29 September 2026.
- Harborside: Notice of Data Breach, dated 3 October 2026.


