Technology
TechCrunch

It sure looks like hackers breached a major ID card verification service

Source Entity

Zack Whittaker

September 4, 2026
It sure looks like hackers breached a major ID card verification service

A massive data breach involving an ID verification service has exposed over 150 million driver's licenses and passports. The FBI is investigating the incident, which saw personal identification data sold on the dark web site 'Nexus'.

The Nexus Breach: A Crisis in Identity Verification

The recent emergence of the dark web platform 'Nexus' has exposed a systemic vulnerability in the digital infrastructure of identity verification. Reports indicate that over 150 million driver’s licenses and passports—spanning both the United States and Canada—have been exfiltrated from a central verification service. This breach is particularly alarming because it involves high-resolution scans that include not only standard visual images but also infrared and ultraviolet spectrum data, which are typically used for advanced anti-counterfeiting measures.

The Mechanics of the Theft

Security researcher Brian Krebs uncovered that the stolen data originated from a service used by various real-world businesses, including car rental agencies, cannabis dispensaries, and hospitality venues. When a consumer hands over their physical ID to be scanned, they trust that the data will be handled securely. Instead, the breach suggests that the backend databases where these third-party verification services store their information have been compromised, allowing hackers to aggregate millions of sensitive records for sale on the black market.

Broader Implications for Identity Security

This incident highlights a significant flaw in the modern 'scan-and-store' approach to identity verification. By collecting and retaining high-fidelity scans of government documents, companies create massive honeypots of personal data. When these centralized repositories are breached, the damage is irreversible; unlike a password, a driver's license number or the specific infrared signature of an ID cannot be changed or reset, leaving victims permanently vulnerable to identity theft and fraud.

The Dark Web Marketplace

Nexus functioned as a specialized search engine for stolen identities, demonstrating the growing sophistication of cybercriminal enterprises. By offering victims' data—including that of high-profile security researchers and even an FBI assistant director—the perpetrators signaled a brazen confidence in their illicit operations. While the site has since shut down, the data remains in circulation, posing a long-term threat to the millions of individuals whose biometric and identification details were leaked.

Regulatory and Future Outlook

As the FBI continues its investigation into the breach, the incident serves as a wake-up call for regulators and private enterprises alike. There is an urgent need for stricter data minimization policies, where businesses are discouraged from storing unnecessary high-resolution scans of sensitive documents. Moving forward, the industry must shift toward decentralized verification methods that verify identity without creating massive, vulnerable databases that act as attractive targets for state-sponsored and independent cybercriminals.

Multiple Citing Sources

Verification Required?

Read the full report from the primary source

Go to TechCrunch