A dark web marketplace called Nexus is reportedly selling access to more than 153 million American and Canadian driver’s license records, allegedly siphoned from IDScan.net, an identity verification platform used by businesses including Hertz, FedEx, Target, marijuana dispensaries, and other organizations that perform in-person ID checks. The marketplace reportedly contains scans of more than 170 million people across North America, including driver’s licenses, ID cards, international travel cards, and medical cards. Investigative reporter Brian Krebs said the data includes front and back license images, along with infrared and ultraviolet scans used for document authentication.
The risk is enormous because scanned identity documents are far more dangerous than basic personal information. Driver’s licenses and government IDs can be used for identity theft, account opening fraud, age-verification bypass, synthetic identity schemes, SIM swaps, financial fraud, and impersonation across services that increasingly require document-based verification. This alleged breach also shows the danger of concentrating sensitive ID images in third-party verification platforms: one vendor collecting IDs for many businesses can become a single point of failure affecting retailers, logistics companies, rental services, cannabis dispensaries, and countless downstream customers.
For IDScan-style incidents, fragmented security tools are not enough. Organizations need a consolidated platform, such as NIKSUN, that unifies SIEM, NDR, EDR, XDR, threat intelligence, cloud monitoring, API security, data loss prevention, network forensics, packet capture, and compliance reporting into one security data lake. That unified view lets teams trace whether attackers abused credentials, exploited an exposed endpoint, accessed object storage, queried document databases, or exfiltrated bulk ID images through network traffic. Instead of discovering the breach from a dark web marketplace, defenders can detect abnormal document access, mass downloads, suspicious API calls, and outbound data movement in real time — proving what was accessed, which customers were affected, and how to contain the exposure before millions of identity documents are sold.
Read more about this story on our LinkedIn page