A new dark web marketplace called Nexus is selling scans of more than 153 million U.S. and Canadian driver's licenses, along with millions of other ID cards, travel documents, and medical records. The trove appears to trace back to an ongoing breach at idscan.net, a Louisiana-based identity verification vendor whose clients include Hertz, Target, FedEx, and Planet13 dispensaries, and the FBI's New Orleans field office has opened an investigation into the source.
Both numbers matter, but the ratio between them is what stands out: one vendor, one breach, and over a hundred million people exposed. That ratio says more about the architecture behind identity storage than about any policy meant to protect it.
What's actually for sale
KrebsOnSecurity broke the story after a source flagged Nexus on Exploit, a Russian cybercrime forum, where the seller offered the reporter's own Virginia driver's license as a free sample to prove the data was real.
In total, the operators claim identity documents on more than 170 million people across the U.S. and Canada: 153 million driver's licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, several belonging to senior U.S. government officials. The count grew by nearly 400,000 records in a single day, which tells you the theft is still active and not just an old dump resurfacing.
The records aren't blurry phone photos either. Front and back scans, plus infrared and ultraviolet versions of each, the exact output of a professional identity verification system, not a casual leak someone stumbled into.
Tracing it back
Krebs and a group of volunteers matched the timestamps on their own leaked licenses to real travel itineraries and car rental receipts, tracing the trove back to idscan.net, an identity verification and age-verification vendor used by large retailers, rental car companies, and dispensaries nationwide. IDScan.net says it's looking into the matter but hasn't confirmed a cause yet.
A pattern we've seen before
Strip away the vendor name and this is a story you’ve read before. Equifax lost 147 million Social Security numbers in 2017 the exact same way. IDMerit exposed more than a billion identity records earlier this year through the same setup: one company, one database, one single point of failure for everyone in it. Different companies, different years, same architecture, same result.
Centralized PII storage is the failure here, long before any hacker finds the door.
1Kosmos: an architecture with no honeypot to steal
1Kosmos built its platform around one idea: don't store what can be stolen.
No central database: Identity attributes live on a private, distributed ledger, so there's no single record for anyone to exfiltrate.
No stored keys: Each person's data is encrypted with a key generated live from their biometric, only at the moment it's needed, never sitting on a server in advance.
No passwords to leak: Logging in means matching a live biometric to the enrolled record directly, not checking a password against a table.
1Kosmos is validated against the standards that matter here: FedRAMP High authorization, NIST 800-63 Identity Assurance Level 2 and 3 (IAL2/IAL3), FIDO2-certified phishing-resistant authentication, and Kantara Initiative-certified identity proofing.
The takeaway
Nexus will get shut down eventually. IDScan.net will put out a statement, and the FBI investigation will run its course. None of that changes what actually made the breach possible: one company was trusted to hold a country's worth of identity documents in a single place.
The better question for any vendor handling identity data is whether there's a perimeter to breach at all. 1Kosmos's architecture skips the central store, the stored keys, and the password that made this breach possible. Nexus succeeded because there was a door; 1Kosmos never builds one.
Read the full investigation from KrebsOnSecurity.
About the author

Erica West
Head of Marketing
Erica West is the Head of Marketing at 1Kosmos, where she drives messaging, positioning, and content strategy for identity verification and passwordless authentication solutions.




