Executive Summary
In September 2026, a new identity theft service called Nexus launched on the dark web selling digital scans of over 153 million drivers licenses from the United States and Canada. The breach appears to originate from Louisiana-based identity verification company IDScan.net, which provides services to major clients including Hertz, Target, FedEx, and numerous marijuana dispensaries. The stolen data includes infrared and ultraviolet scans with timestamps indicating continuous exfiltration over more than a year, prompting an FBI investigation by the New Orleans field office. This massive identity document breach represents one of the largest exposures of state-issued identification data in U.S. history, with attackers offering licenses of high-profile government officials including Defense Secretary Pete Hegseth and FBI leadership. The incident highlights critical vulnerabilities in third-party identity verification systems that process over 21 million verifications monthly across 20,000 locations worldwide.
Why This Matters Now
Identity verification systems are proliferating rapidly across industries, creating massive centralized repositories of sensitive biometric data. This breach exposes the dangerous lack of oversight and security standards for third-party identity processors, while AI-powered facial recognition makes stolen license photos permanently compromising for victims.
Attack Path Analysis
Attackers gained initial access to IDScan.net's identity verification infrastructure through unknown means, then maintained persistent access for over a year to continuously exfiltrate 153+ million driver's license records. The breach involved systematic collection of multi-spectrum ID scans from major clients including Hertz, Planet13, and other Fortune 500 companies. Attackers established command and control channels to maintain long-term access, continuously harvesting fresh identity data and uploading it to a dark web marketplace called Nexus for monetization.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Unknown initial access vector to IDScan.net identity verification platform serving 20,000+ locations processing 21 million monthly verifications
MITRE ATT&CK® Techniques
Data from Cloud Storage Object
Exfiltration Over C2 Channel
Automated Exfiltration
Exfiltration Over Web Service
Gather Victim Identity Information: Credentials
Data from Information Repositories
Acquire Infrastructure: Web Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Account Data Storage Limitation
Control ID: 3.2.1
NYDFS 23 NYCRR 500 – Data Retention and Disposal
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Data Categorization and Protection
Control ID: Data Security
NIS2 Directive – Incident Reporting
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Transportation
Massive exposure through rental car identity verification systems compromises customer data, enabling identity theft and fraudulent access to transportation services nationwide.
Leisure/Travel
Hotel check-ins and travel-related ID verification create vulnerability points where 153M+ license scans enable targeted attacks against hospitality customer databases.
Government Administration
High-profile government officials' licenses exposed including Defense Secretary, creating national security risks and potential compromise of federal employee identification systems.
Financial Services
Driver's licenses as primary identity verification for credit applications face massive compromise, enabling widespread financial fraud and unauthorized account creation attempts.
Sources
- FBI Probes Service Selling 153M+ Drivers Licenseshttps://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/Verified
- IDScan.net Identity Verification Serviceshttps://idscan.netVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the attackers' ability to move laterally across IDScan.net's distributed verification network and maintain persistent access to identity databases. The segmented architecture would likely have reduced the blast radius and limited continuous data harvesting across multiple client integrations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust architecture would likely have constrained the initial compromise scope by limiting attacker reachability to only specific workload segments rather than broad infrastructure access.
Control: Zero Trust Segmentation
Mitigation: Identity-aware segmentation would likely have limited privilege escalation by constraining access to identity databases based on authenticated workload identity rather than allowing broad database access.
Control: East-West Traffic Security
Mitigation: Microsegmentation would likely have constrained lateral movement between client integration points, reducing the attacker's ability to access data from multiple Fortune 500 companies across geographic locations.
Control: Multicloud Visibility & Control
Mitigation: Continuous visibility and anomaly detection would likely have identified persistent command and control channels, constraining the attacker's ability to maintain long-term covert access across the infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained the systematic exfiltration of massive identity datasets by blocking unauthorized outbound data transfers and detecting anomalous data volume patterns.
Residual impact would likely have been limited to a smaller subset of identity records from specific client segments, reducing exposure of witness protection participants and domestic violence victims.
Impact at a Glance
Affected Business Functions
- Identity Verification Services
- Customer Data Management
- Compliance Operations
- Third-Party Integrations
Estimated downtime: N/A
Estimated loss: N/A
Digital scans of over 153 million drivers licenses from US and Canada, including infrared and ultraviolet images with timestamps. Additional exposure includes 10+ million ID cards, 3+ million travel documents, 579,000+ medical cards, and marijuana dispensary records. High-profile individuals including government officials affected.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate identity verification systems and prevent lateral movement across client data boundaries
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound transfers of sensitive identity data
- • Enable Multicloud Visibility & Control to monitor anomalous data access patterns and bulk extraction activities across distributed verification infrastructure
- • Establish Encrypted Traffic controls for all identity data in transit between verification endpoints and central processing systems
- • Implement Threat Detection & Anomaly Response to baseline normal verification volumes and alert on suspicious bulk data access or prolonged session activities



