FBI Investigated Massive Data Leak on Nexus Marketplace
The breach exposed over 160 million identity documents linked to the Louisiana-based verification firm IDScan.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you trust that companies today are doing enough to protect your sensitive personal data?
In late August 2026, the dark-web marketplace Nexus began advertising a massive cache of 153 million driver's license scans from the United States and Canada. The FBI has launched a formal investigation into the breach, which security researchers linked to the Louisiana firm idscan.net after matching leaked timestamps to real-world rental transactions.
Why it matters
The leak is significant due to the sheer volume and sensitivity of the exposed documents, which included government-issued IDs and medical records. Law enforcement action was prioritized after records allegedly belonging to the U.S. Secretary of Defense and an FBI assistant director were identified among the listings.
The dataset included 153 million driver's license scans, 10 million ID cards, 3 million travel documents, and 580,000 medical cards. Security experts verified the source by correlating timestamped data within the files against specific transactions conducted at Hertz rental locations.
The players
IDScan
A Louisiana-based company specializing in automated identity verification and credential scanning services for corporate clients.
FBI
The domestic intelligence and security service of the United States currently conducting a criminal probe into the digital data breach.
The details
The breach involved the unauthorized access and sale of digital identity scans that were collected by idscan.net for client verification. Researchers confirmed the origin of the leak by performing time-series analysis, matching the metadata within the stolen files to the exact timing of check-in events at rental car counters. The Nexus marketplace served as the platform for this exfiltrated data before it was taken offline in response to security reports.
Timeline
Late August 2026: Nexus began advertising the stolen database.
September 7, 2026: The security findings and federal investigation were reported.
The Tech Race
This incident mirrors the systemic risks highlighted by the 2017 Equifax data breach, where centralized identity verification firms become high-value targets. It marks a departure from typical localized leaks, scaling to a national level that now invites federal scrutiny and broad class-action litigation.
Users whose identity documents were processed by IDScan-affiliated businesses may face increased risks of targeted phishing or identity fraud. Businesses currently utilizing third-party verification platforms should review their data handling protocols as legal observers anticipate imminent multidistrict litigation.
The takeaway
The exposure of top-level government official records on the dark web underscores the vulnerability of third-party identity verification stacks. Readers should watch for updates from state attorneys general regarding potential regulatory fines and any specific remediation steps offered by the affected vendors.
Further reading
For broader trends in digital identity protection, see the latest reporting on Cybersecurity.
Source note: This article includes information reported by Computer Crime Research Center.
Live Poll
Do you trust that companies today are doing enough to protect your sensitive personal data?






