Dark Web Listing Exposes 153 Million North American IDs
Bastillepost · 2 SOURCES1 day ago2 MIN

Summary
A dark web marketplace known as Nexus allegedly listed more than 153 million scans of identity documents from the United States and Canada, including driver’s licenses, passports and medical cards. Among the records cited in reports was a driver’s license belonging to US Defense Secretary Pete Hegseth, while another senior FBI official’s license information was also said to appear in the database. The FBI’s New Orleans field office has confirmed a formal investigation, and the US Department of Defense said it was aware of the reports and was assessing the situation. Brian Krebs and other researchers said the material appeared authentic in multiple checked cases, raising the possibility of the largest known leak of government-issued identity documents in North America.
Key Points
- Nexus advertised on the Russian-language cybercrime forum Exploit, offering paid searches across personal data tied to more than 170 million North American residents
- The site claimed to hold over 153 million US and Canadian driver’s license scans, 10.33 million identity cards, 3.3 million travel documents, and at least 579,000 medical cards
- Krebs said the exposure came to light after he received an alert about his own digital driver’s license, then verified authenticity with nine affected individuals
- Reports said some files included infrared and ultraviolet images of documents, potentially helping criminals bypass bank and government verification systems.
- Krebs and Infoblox researcher Zach Edwards traced the suspected source to Louisiana-based identity verification provider IDScan.net, whose clients include Hertz, Target and FedEx.
Why It Matters
For Hong Kong readers, the case shows how outsourced identity-checking systems can become a single point of failure when businesses and agencies rely on scanned documents for onboarding and verification. If high-resolution IDs and embedded security features are exposed, the risk extends beyond privacy loss to bank fraud, account opening abuse and forged travel documents, problems that can cross borders quickly. The reports also underline why users should monitor bank activity, review credit records and enable two-factor authentication after any suspected identity-data compromise