Investigation · Government ID Data

Nexus / IDScan.net Data Breach Investigation

Hall Attorneys is investigating reports that a dark-web identity service called Nexus offered a massive collection of driver's-license and other identity-document records allegedly connected to IDScan.net. IDScan.net has not confirmed the reported source or scope, and the marketplace's figures are not a verified count of affected people.

Driver's-license records
153M+ claimed

marketplace claim; not a verified unique-person count

Reported publicly
Sept. 1, 2026

date of the KrebsOnSecurity report

Confirmed scope
Not established

IDScan.net's investigation was preliminary

Could this be me?

Could IDScan.net have processed my identification?

Possibly, even if you do not recognize the company name. IDScan.net provides behind-the-scenes identity-verification tools to businesses. These clues can help identify a possible connection, but none proves that your information appears in the reported Nexus data.

  1. A business scanned or photographed your government ID

    IDScan.net products can scan, authenticate, and parse driver's licenses, state IDs, passports, and other identity documents. Look for a scanner, tablet, kiosk, or online flow that captured the front and back of your ID.

    • Your ID was placed in or passed through a scanning device
    • A worker photographed both sides of the ID
    • You uploaded an ID during an online identity check
  2. You rented a vehicle and your license was scanned

    Several people interviewed by KrebsOnSecurity matched timestamps on reported Nexus records to car rentals, including Hertz rentals. That reporting is a lead—not proof that every rental company, location, or customer was affected.

  3. A cannabis dispensary scanned your ID

    IDScan.net says its technology serves more than 1,000 dispensaries, and it has publicly described a Planet 13 deployment. A dispensary scan may establish a possible IDScan.net connection, but not inclusion in the reported data.

  4. You completed an ID check in another IDScan.net industry

    IDScan.net markets identity tools for banking and fintech, automotive, hospitality, gaming, retail, equipment rental, freight and transportation, nightlife, security, education, and visitor access. The industry alone is not enough; identify the specific business and date.

  5. You used remote ID verification or a face-match flow

    An online check may have asked for front-and-back ID images and a selfie or live face capture. Save the consent screen, confirmation email, privacy notice, or support exchange that identifies the verification provider.

  6. Your records name IDScan.net, VeriScan, or DIVE

    Check receipts, rental records, account privacy notices, consent screens, emails, and saved screenshots. You can also ask the business that scanned your ID which identity-verification vendor and product it used on that date.

Check your records

Ask the business that scanned your ID

IDScan.net's privacy policy says it often processes identity information for business clients and directs people to contact the client about that client data. Ask for a written response without sending another copy of your ID through ordinary email.

IDScan.netVeriScanDIVEID verification
  • Identify the business, location, approximate date, and reason your ID was scanned or uploaded.
  • Ask whether the business used IDScan.net, VeriScan, DIVE, or another ID-verification provider for that transaction.
  • Ask whether front-and-back images, infrared or ultraviolet captures, a selfie, or parsed ID fields were retained and whether your record is within any incident review.
  • Keep the request and response. Do not send an unredacted ID image, Social Security number, or account password in an initial inquiry.
  • Treat unsolicited breach-check links as suspicious; no confirmed public Nexus or IDScan.net lookup tool has been announced.

Answer at a glance

What is known about the Nexus / IDScan.net report?

KrebsOnSecurity reported on September 1, 2026 that a newly advertised illicit service called Nexus was selling access to a large collection of identity-document images. Nexus claimed more than 153 million driver's-license records for people in the United States and Canada, more than 10 million identification-card records, more than 3 million travel-document or international-ID records, and at least 579,000 medical-card records.

The reporter examined records, interviewed people whose licenses appeared in the service, and connected scan timestamps to transactions where their IDs were presented. The report pointed to IDScan.net based on those matches, the types of infrared and ultraviolet images available, and publicly described customer relationships. Those findings are investigative reporting; they are not a completed forensic determination by IDScan.net, the FBI, or a court.

IDScan.net told KrebsOnSecurity that it was investigating but did not provide a substantive conclusion about whether unauthorized access occurred, which systems or customers were involved, or how many people were affected. The report also said the FBI's New Orleans field office opened an inquiry. No separate public FBI announcement was identified for this page.

Nexus disappeared from the dark web shortly after the report was published. That does not establish that copies of the data were deleted, and it does not resolve the source, accuracy, completeness, or possible further distribution of the records.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Nexus alleges continuing exfiltration

    The operators reportedly claimed they had been continuously obtaining new data for more than a year. IDScan.net has not confirmed that claim or a date range for unauthorized access.

  2. Nexus is advertised and records are examined

    A source alerted KrebsOnSecurity to a new service advertising access to identity-document images, and the reporter began checking records and their apparent origins.

  3. Apparent IDScan.net incident is reported

    KrebsOnSecurity published its findings, reported that IDScan.net was investigating, and said the FBI's New Orleans field office had opened an inquiry.

  4. Nexus service goes offline

    An update to the report said the Nexus site disappeared and displayed a message that the service was no longer available.

Reported data categories

What information was involved?

The categories below come primarily from Nexus's claims and records reviewed by KrebsOnSecurity. IDScan.net has not confirmed a complete field list or that these records came from its systems.

Important distinction

A scan can reveal substantially more than a license number. But the reporting reviewed for this page does not establish that Social Security numbers, passwords, or payment-card numbers were part of this event, and it does not prove that every listed record is current, unique, or authentic.

Government ID images
Front-and-back images of driver's licenses and other identity documents, potentially showing name, photograph, address, date of birth, ID number, expiration date, physical descriptors, and barcode data
Authentication images and metadata
Some reported records included standard, infrared, and ultraviolet image variants with scan timestamps
Other identity documents
Nexus claimed identification cards, travel documents or international IDs, dispensary cards, and possible government access cards
Medical cards
Nexus claimed at least 579,000 medical-card records; the issuer, fields, and unique-person count were not confirmed
Associated photographs
The service reportedly displayed customer photos where available, but the origin and scope of those images remain unclear
Transaction context
Timestamps and source labels may reveal when or in what setting an identity document was scanned

Who may want to contact us

People whose IDs may have been processed through IDScan.net

No affected-person list has been confirmed. The investigation is focused on people who can document that a business used IDScan.net to scan or verify their identity, people who receive a direct notice, and people who experience misuse consistent with the reported records.

People whose driver's license, state ID, passport, medical card, or other identity document was scanned through an IDScan.net or VeriScan product

People who uploaded an ID or completed a selfie-based identity check through an IDScan.net-powered workflow

Rental-car, dispensary, hospitality, gaming, retail, financial-services, transportation, or visitor-access customers who confirm that the specific business used IDScan.net

People who receive an incident notice from IDScan.net or a business that used its identity-verification services

People who experience new-account fraud, impersonation, targeted phishing, or other misuse involving information visible on their identity document

What to preserve

Keep proof of the scan, the provider, and any misuse

Preserve records that can connect a particular ID scan to IDScan.net without sending Hall Attorneys an unredacted copy of the identity document in an initial message.

Incident notices and updates

Keep the complete notice, envelope, email headers, monitoring offer, deadline, and later updates from IDScan.net or the business that collected your ID.

Transaction and visit records

Preserve rental agreements, receipts, reservations, account histories, access logs, and other dated records showing where and when your ID was scanned.

Vendor and consent records

Save privacy notices, consent screens, emails, support exchanges, or written answers naming IDScan.net, VeriScan, DIVE, or another verification provider.

What the process captured

Write down whether the business scanned the front and back, used a specialized reader, took a selfie, or asked you to upload images. Do not create or send a new unredacted copy solely for this investigation.

Fraud and suspicious communications

Keep credit alerts, unfamiliar-account records, phishing messages, impersonation attempts, DMV correspondence, and identity-theft reports.

Time, costs, and other harm

Maintain a dated log of time spent, freezes or replacements requested, professional fees, lost funds, denied credit, and other concrete effects.

Investigation focus

Issues under review

Hall Attorneys is investigating the source and scope of the reported records, the organizations and people involved, and whether affected individuals experienced legally cognizable harm.

  1. Whether IDScan.net systems or data were accessed without authorization and, if so, the access method and dates
  2. Which IDScan.net products, business clients, locations, tenants, repositories, or subprocessors were involved
  3. Whether the Nexus figures reflect unique people, duplicate scans, image variants, expired documents, or records from other sources
  4. What identity images, parsed fields, photographs, metadata, or transaction information were obtained
  5. How retention settings and customer-specific storage practices affected the available data
  6. When IDScan.net and its clients learned of the apparent incident and what notices will be provided
  7. Whether the information has been copied, resold, republished, or used for fraud, impersonation, account opening, or evasion of identity checks
  8. What protective steps, replacement guidance, monitoring, reimbursement, or other relief may be offered

Public records reviewed

Sources for the Nexus / IDScan.net incident

The public record is preliminary. The main incident account is investigative reporting; IDScan.net's own materials explain its services, client-data role, and the types of identity information its products can process.

KrebsOnSecurity ·

FBI Probes Service Selling 153M+ Drivers Licenses

Reports the Nexus marketplace, claimed record counts, sampled ID images, apparent links to IDScan.net, the company's preliminary response, and the reported FBI inquiry.

Read source: FBI Probes Service Selling 153M+ Drivers Licenses

IDScan.net ·

IDScan.net Privacy Policy

Explains that IDScan.net processes client data on behalf of businesses, including government-issued ID and biometric data, and directs people to the relevant client for requests concerning client data.

Read source: IDScan.net Privacy Policy

IDScan.net ·

ID Fraud Prevention at Scale

Describes IDScan.net's scanning, authentication, remote-verification, face-match, and industry use cases and identifies publicly displayed customers and integrations.

Read source: ID Fraud Prevention at Scale

Contact the firm

Was your ID scanned through IDScan.net or VeriScan?

Contact Hall Attorneys with the business and location, approximate scan date, the product or vendor name you found, any incident notice, and any resulting misuse or expense. Do not send an unredacted identity document, Social Security number, account password, or full financial record through an initial website message.

Contact Hall Attorneys

Frequently asked questions

Nexus / IDScan.net breach FAQ

Is Nexus the same company as IDScan.net?

No. In the September 1 reporting, Nexus is the name of an illicit identity-record marketplace. KrebsOnSecurity reported apparent links between sampled Nexus records and IDScan.net, an identity-verification provider. IDScan.net had not confirmed the reported source or scope.

Did IDScan.net confirm a data breach?

Not in the public sources reviewed for this page. IDScan.net told KrebsOnSecurity it was investigating but did not provide a substantive conclusion about unauthorized access, affected systems, data categories, customers, or people.

Were 153 million people affected?

That has not been established. Nexus claimed more than 153 million driver's-license records. Records may include duplicates, multiple scans or image variants, outdated documents, or material from more than one source, and IDScan.net has not confirmed the number.

How can I find out whether IDScan.net processed my ID?

Check receipts, rental records, consent screens, emails, privacy notices, and account records for IDScan.net, VeriScan, or DIVE. Ask the business that scanned or received your ID which verification provider it used on the relevant date and request a written response. There is no confirmed public breach lookup tool.

What information may be involved?

The reporting describes front-and-back government-ID images, some infrared and ultraviolet image variants, scan timestamps, and other identity-document categories. An ID image can display a photograph, name, address, birth date, document number, expiration date, physical descriptors, and barcode data. IDScan.net has not confirmed a final field list.

What should I do if my identity information may be involved?

Preserve proof of the scan and any notice, monitor financial and identity accounts, consider a free credit freeze, and be cautious of unsolicited breach-check links. If misuse occurs, report it at IdentityTheft.gov and follow the recovery plan. Ask your state motor-vehicle agency whether replacement or another license-specific step is appropriate before paying for a replacement.

Has Hall Attorneys filed a Nexus or IDScan.net lawsuit?

No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning Nexus or IDScan.net.

Attorney Advertising

Hall Attorneys is not affiliated with IDScan.net, Inc. or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.