Observed Signal · Sep 2, 2026 · Data Breach · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
Hackers suspected of breaching ID verification service IDScan
Independent security journalist Brian Krebs reported that a dark web identity search site called Nexus is advertising access to more than 150 million driver's licenses and passports from the US and Canada, apparently stolen from a major identity verification company. Krebs identified the likely source as IDScan, a Louisiana-based ID verification service used by major tech and consumer brands. The site claimed to add about 500,000 new documents daily, suggesting near real-time access to the company's systems. Krebs confirmed his own driver's license was in the database, and Defense Secretary Pete Hegseth's photo was also listed. IDScan's COO said the company is investigating, and the FBI's New Orleans field office is probing the breach. Nexus went offline after the report was published.
Major breach of an identity verification provider used by major brands; exposes 150M+ ID documents, undermining trust in identity verification and age-verification infrastructure crucial for digital advertising and privacy compliance.
Track TechCrunch Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Security journalist Brian Krebs reported a suspected breach of identity verification service IDScan, exposing over 150 million driver's licenses and passports from the US and Canada.
- Dark web identity search site Nexus advertised the stolen documents and claimed to add about 500,000 new records daily from a 'major identity verification company.'
- Krebs confirmed his own driver's license was in the database, and U.S. Secretary of Defense Pete Hegseth's photo was also listed.
- IDScan COO Jillian Kossman told Krebs the company is investigating; the FBI's New Orleans field office is probing the breach.
- The Nexus site went offline shortly after Krebs's report was published.
Connected Companies & Entities
1 Entity mapped“A spokesperson for the Department of Defense told TechCrunch that it is 'aware of these reports and is evaluating them.'...”
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
IDScan confirms data breach of 150 million driver's licenses
Identity verification service IDScan has confirmed a data breach involving the theft of over 150 million driver's license records from its cloud systems. The stolen data includes full names, driver's license numbers, and other government ID numbers such as passports. The breach, which occurred over a year-long hack, was first reported by cybersecurity journalist Brian Krebs. IDScan, based in Louisiana, serves corporate clients including entertainment venues and cannabis dispensaries. The company acknowledged the incident on September 1 after receiving information about a claim of a hack, and its investigation is ongoing. The FBI and Pentagon are reportedly investigating. The stolen database is accessible on the dark web, with searchable records including photos.
ShinyHunters leaks Florida driver data after ransom unpaid
The ShinyHunters hacking group has published hundreds of thousands of files from Florida's vehicle and driver database (DAVID), which was breached earlier in September. The group claims the leak occurred because the state agency, FLHSMV, did not pay a ransom or cooperate. The stolen data includes certificates of vehicle ownership, vehicle identification numbers, and some Social Security numbers and government-issued documents, but not driver's licenses. FLHSMV confirmed the breach, attributing it to compromised police officer credentials. The event follows a separate major breach at identity verification firm IDScan, which resulted in over 150 million driver's license images being stolen. This incident highlights ongoing vulnerabilities in government data systems and the increasing threat of cybercriminal groups targeting sensitive citizen data, with potential implications for identity fraud and advertising data security.
Duc App Exposed Hundreds of Thousands of ID Documents
A publicly accessible Amazon-hosted storage server containing unencrypted identity documents and personal data collected by the Duc App (owned by Toronto-based Duales) was exposed to the open web. Security researcher Anurag Sen of CyPeace discovered the misconfigured storage server listing over 360,000 files that included driver’s licenses, passports, selfies, and spreadsheets with names, addresses and transaction details. TechCrunch alerted Duales’ CEO Henry Martinez González, after which the files were made inaccessible; a listing of the server contents remained visible. The company said the data was on a "staging site." Canada’s privacy regulator has reached out to Duales for more information. The exposure dated back to September 2020 and the Duc Android app shows over 100,000 downloads on Google Play.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
