Executive Summary

In September 2026, a new identity theft service called Nexus launched on the dark web selling digital scans of over 153 million drivers licenses from the United States and Canada. The breach appears to originate from Louisiana-based identity verification company IDScan.net, which provides services to major clients including Hertz, Target, FedEx, and numerous marijuana dispensaries. The stolen data includes infrared and ultraviolet scans with timestamps indicating continuous exfiltration over more than a year, prompting an FBI investigation by the New Orleans field office. This massive identity document breach represents one of the largest exposures of state-issued identification data in U.S. history, with attackers offering licenses of high-profile government officials including Defense Secretary Pete Hegseth and FBI leadership. The incident highlights critical vulnerabilities in third-party identity verification systems that process over 21 million verifications monthly across 20,000 locations worldwide.

Why This Matters Now

Identity verification systems are proliferating rapidly across industries, creating massive centralized repositories of sensitive biometric data. This breach exposes the dangerous lack of oversight and security standards for third-party identity processors, while AI-powered facial recognition makes stolen license photos permanently compromising for victims.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exposed digital scans of over 153 million driver's licenses including infrared and ultraviolet images, plus medical cards, travel documents, and marijuana dispensary cards with timestamps indicating when each document was scanned.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained the attackers' ability to move laterally across IDScan.net's distributed verification network and maintain persistent access to identity databases. The segmented architecture would likely have reduced the blast radius and limited continuous data harvesting across multiple client integrations.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust architecture would likely have constrained the initial compromise scope by limiting attacker reachability to only specific workload segments rather than broad infrastructure access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware segmentation would likely have limited privilege escalation by constraining access to identity databases based on authenticated workload identity rather than allowing broad database access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation would likely have constrained lateral movement between client integration points, reducing the attacker's ability to access data from multiple Fortune 500 companies across geographic locations.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Continuous visibility and anomaly detection would likely have identified persistent command and control channels, constraining the attacker's ability to maintain long-term covert access across the infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have constrained the systematic exfiltration of massive identity datasets by blocking unauthorized outbound data transfers and detecting anomalous data volume patterns.

Impact (Mitigations)

Residual impact would likely have been limited to a smaller subset of identity records from specific client segments, reducing exposure of witness protection participants and domestic violence victims.

Impact at a Glance

Affected Business Functions

  • Identity Verification Services
  • Customer Data Management
  • Compliance Operations
  • Third-Party Integrations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Digital scans of over 153 million drivers licenses from US and Canada, including infrared and ultraviolet images with timestamps. Additional exposure includes 10+ million ID cards, 3+ million travel documents, 579,000+ medical cards, and marijuana dispensary records. High-profile individuals including government officials affected.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate identity verification systems and prevent lateral movement across client data boundaries
  • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound transfers of sensitive identity data
  • Enable Multicloud Visibility & Control to monitor anomalous data access patterns and bulk extraction activities across distributed verification infrastructure
  • Establish Encrypted Traffic controls for all identity data in transit between verification endpoints and central processing systems
  • Implement Threat Detection & Anomaly Response to baseline normal verification volumes and alert on suspicious bulk data access or prolonged session activities

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image