KYC Vendor Data Breach: 153M+ License Scans Leaked — What to Audit Now

Updated September 2, 2026My Business AI Audit · Tag: AI vendor security, third-party data risk

On September 1, 2026, security journalist Brian Krebs reported that a dark-web service called Nexus was advertising digital scans of more than 153 million driver's licenses from people in the United States and Canada — along with roughly 10 million ID cards, more than three million travel documents and international IDs, and at least 579,000 medical and dispensary cards (KrebsOnSecurity, Sep 1, 2026). The suspected source, based on circumstantial evidence Krebs documented, is IDScan.net, a New Orleans-based identity verification vendor — an allegation the company has not confirmed and says it is still investigating.

If your business uses a KYC or ID-verification vendor — for customer onboarding, age checks, rental counters, dispensaries, or AI-agent identity workflows — this is the third-party risk scenario your audit needs to handle. Here is what happened, why IDV vendors belong at the top of your high-risk vendor list, and what an AI-aware audit should cover when a KYC vendor data breach breaks.

Update — September 2, 2026

Nexus Went Offline the Same Evening the Story Broke

Nexus's login page was replaced with a plain-text message: “This service is no longer available.” Krebs reported the shutdown at roughly 8:56 p.m. ET on September 2, and Engadget confirmed the marketplace was no longer reachable. The FBI's New Orleans field office opened an official inquiry on September 1, but there are no arrests, charges, or confirmation that IDScan.net was the source. All figures above and below are Nexus's own claimed inventory, not an independently audited count. This is a fast-moving story; treat any “confirmed” headline with suspicion until the vendor or the FBI says more.

What Happened: A Dark-Web Service Called Nexus Listed 153M+ License Scans

On August 31, a source tipped Krebs to a thread on the Russian cybercrime forum Exploit. The service's proprietor had offered Krebs's own Virginia driver's license as a free sample. The service, dubbed Nexus, claimed more than 153 million U.S. and Canadian driver's licenses, more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards — including marijuana dispensary cards.

Krebs tested the headline number with a blank search: Nexus returned roughly 11.5 million result pages at about 15 results per page, which he said made the 153-million figure “likely not exaggerating.” He also documented that the record count grew by nearly 400,000 driver's licenses in 24 hours, and Nexus claimed it had been “continuously exfiltrating new data for over a year.” The records are not just numbers: they are full front-and-back image scans showing photo, name, address, date of birth, signature, and license number — and, on many records, infrared and ultraviolet versions of the same scans.

The connection to IDScan.net is circumstantial and unconfirmed. Krebs verified records for more than a dozen friends and family members; nine were found, and their image timestamps lined up with car rentals — several from Hertz. Security researcher Zach Edwards's license matched a scan taken during a Las Vegas trip at Planet13, a dispensary chain that signed an exclusive identity-verification agreement with IDScan.net in 2022. IDScan.net's own documentation describes scanning IDs with infrared and ultraviolet light — the same format Nexus offered — and the company is headquartered in Louisiana. IDScan.net told Krebs it was investigating the matter and had not reached conclusions about the nature or scope of any incident (Tom's Hardware, Sep 2, 2026). Cybernews titled its coverage “alleged massive IDScan.net data breach” and noted it “can't verify the claims” (Cybernews, Sep 2, 2026).

Coverage quickly spread: 9to5Mac (Sep 2) reported the FBI was “reportedly” investigating; Engadget (Sep 2) added the shutdown confirmation; and entrepreneur Pieter Levels (levelsio on X, Sep 2, 2:17 p.m. EDT) amplified the story with his own framing that 153 million records would be roughly 63% of all American driver's licenses — his math, not an official statistic, and the dataset also includes Canadian records. Reports also noted that U.S. Defense Secretary Pete Hegseth's license was listed for $100, and that records tagged “CDL” and “CAC” appeared in the service (those labels are Krebs's best-guess readings, not confirmed categories).

Why KYC and ID Verification Vendors Are High-Risk Third Parties

KYC (know-your-customer) and IDV (identity-verification) vendors are a different risk class from an ordinary SaaS tool:

What an AI-Aware Audit Should Cover After a KYC Vendor Data Breach

This is the concrete example most AI audit third-party data risk conversations have been missing: an IDV vendor holding records on tens of millions of people, with downstream businesses learning about it from the news rather than from the vendor. When your AI agents route identity data — onboarding, verification, fraud checks — through third-party KYC vendors, the audit must treat the vendor as an extension of your own environment. Walk these seven areas:

1. Vendor due diligence, before you sign — and again on renewal

Ask for security certifications (SOC 2, ISO 27001), breach history, encryption and retention practices, and proof that full ID scans — especially UV/IR images — are not stored longer than needed. The same discipline applies to any AI vendor in your stack: add model capability classification, data isolation, and disclosure obligations to your AI vendor risk assessment questions. If a vendor cannot or will not answer, that is the answer.

2. Data inventory: what did you send, and where does it sit?

Map every workflow that sends PII or license scans to a KYC/IDV vendor — not just the ones IT knows about. Rental counters, dispensary age checks, retail returns, HR onboarding, and agent-driven verification flows all count. Record what was transmitted, whether copies were retained by the vendor, how long they are kept, and what happens after a successful verification. If you cannot answer “what did we send and where does it live,” the audit starts there.

3. Subprocessor risk

Your vendor's vendors are your risk too. A KYC stack commonly passes data to identity databases, watchlist checks, and cloud storage providers. Require a current subprocessor list, the right to be notified of changes, and flow-down security commitments. For agent workflows, apply the same logic as our 10-point AI agent supply chain audit: know every hop between your data and its destination.

4. Breach liability and notification clauses

The contract should say who notifies whom, and how fast. Look for defined notification windows, indemnification for third-party claims, liability caps that are not unreasonably low, a duty to cooperate with your investigation, and evidence preservation. In the IDScan.net situation, downstream businesses learned of the suspected breach from news reports — the exact failure a strong notification clause prevents.

5. Fraud-prevention workflows

After an IDV breach, assume fraudsters hold high-quality copies of documents your customers already presented. Add step-up verification for high-risk events — new accounts, address changes, password resets, large withdrawals — and watch for synthetic-identity fraud, account takeover, and new-account fraud spikes. If your fraud team uses AI monitoring, tune it for document-reuse patterns, not just credential stuffing.

6. Dark-web monitoring

Subscribe to monitoring that covers your domain, your executives' and customers' identifiers, and batches of records that look like your onboarding data. In this incident, the marketplace was public and searchable — a monitoring service could have flagged your organization's data appearing for sale, which is faster signal than waiting for the vendor or the news.

7. Incident runbooks

Write the runbook before you need it: who declares an incident, who communicates with the vendor, customers, regulators, and insurers, what state notification laws apply, and how you capture evidence. A KYC vendor breach is a third-party incident with first-party consequences — your customers will hold you responsible even though the data sat with a vendor.

Driver's License Scan Leaked — What to Do: A Checklist

If a vendor you use is implicated in a breach like this — or if you simply handed your license to a business that uses an IDV vendor — work this checklist. It is ordered by urgency and covers both the business and the individual side of a leaked scan.

  1. Confirm the relationship. Check contracts, vendor lists, and finance records: does your business (or a vendor you use) rely on the implicated IDV provider? Do not rely on the news to tell you — ask the vendor directly for written confirmation of whether your account and data were involved.
  2. Identify affected records. Pull your data inventory: which customers, employees, or transactions had documents scanned through the vendor, when, and in what format (front/back, UV/IR).
  3. Review your breach-notification obligations. Check your state's breach-notification statute and your contracts. If the vendor processed data on your behalf, your notification duties to customers and regulators may still be yours to meet — do not wait for the vendor's timeline.
  4. Put the vendor on notice and preserve evidence. Send the contract-required notice, ask for their incident report, and preserve logs and records that show what you transmitted.
  5. Notify your cyber insurer now. Most cyber policies require prompt notice of a suspected incident — even a third-party one that touches your data — and delay can jeopardize coverage. See below for when to escalate.
  6. Step up fraud controls. Add verification friction to high-risk actions, watch for new-account fraud and account takeover, and brief your fraud and support teams on what to look for.
  7. Set up dark-web and account monitoring. Monitor for your corporate identifiers and any customer data appearing in breach dumps. Encourage affected customers to place a credit freeze or fraud alert.
  8. If you are an individual whose license was scanned: freeze your credit at the three major bureaus (or place a fraud alert), request a reissued license with a new number if your state allows it, monitor bank and credit card statements, and be alert to phishing that references your license or a “verification” of it.
  9. Document everything. Record dates, communications, vendor responses, and decisions — this becomes your evidence file for insurers, regulators, and any customer inquiries.

When to Escalate to Legal or Cyber Insurance

Not every third-party breach requires a lawyer. Escalate when any of these are true: the vendor confirms your data was involved; your notification obligations to customers or regulators are triggered; a customer, employee, or partner has been harmed and may claim against you; your contract contains an indemnification or liability dispute; or your cyber insurer asks for a formal incident assessment. Your broker or policy's incident-response provider can also help determine whether your cyber insurance coverage responds to vendor-caused exposure — many policies cover third-party data breaches but with exclusions and notice deadlines you do not want to discover after the fact.

Get legal advice early if your business handles regulated data (financial, healthcare, or government-adjacent identity records) or if you operate in a state with strict breach-notification timelines. The cost of one early consultation is trivial next to the cost of a missed notice deadline.

Frequently Asked Questions

Was my driver's license part of the 153M scan leak?

There is no public lookup tool, and Nexus went offline on September 2. If you rented a car from a company that uses the suspected vendor, or handed your license to a dispensary, retailer, or other business that scans IDs with the same kind of device, assume your scan may be affected. Freeze your credit, place a fraud alert, and monitor your accounts — the same steps you would take after any ID document exposure.

Was IDScan hacked?

Not confirmed. IDScan.net is the suspected source based on circumstantial evidence — rental-car timestamps, a dispensary scan, infrared/ultraviolet image formats, and its Louisiana headquarters. The company says it is investigating and has not confirmed a breach; the FBI's New Orleans field office opened an official inquiry on September 1. Treat any claim that IDScan was hacked as alleged until the company or investigators confirm it.

Was an identity verification provider hacked in 2026?

As of September 2, 2026, the Nexus marketplace claims more than 153 million U.S. and Canadian driver's license scans plus millions of other ID documents, and the suspected source is identity verification provider IDScan.net. The company has not confirmed the breach and the FBI inquiry is ongoing. This follows a pattern of KYC vendor breaches — third parties that hold large volumes of identity documents are a growing target.

What is a KYC vendor?

A KYC (know-your-customer) or IDV (identity verification) vendor is a company that scans, verifies, and stores identity documents — driver's licenses, passports, ID cards — for businesses that must confirm who their customers are. They are used at rental counters, dispensaries, banks, fintech apps, retailers, and increasingly in AI-agent onboarding flows, which is why a breach at one vendor can ripple across hundreds of businesses.

Driver's license scan leaked — what to do?

Freeze your credit (or place a fraud alert), request a reissued license with a new number if your state allows it, monitor financial accounts and credit reports, and stay alert for phishing that references your license. If a business you dealt with used the suspected vendor, the business should notify you — ask them what data they hold and what they are doing about it.

What should a business do after a KYC vendor data breach?

Confirm whether your business used the vendor and what data was involved, identify affected records from your data inventory, review your breach-notification obligations under state law and your contracts, notify your cyber insurer, put the vendor on notice, step up fraud controls, and update your incident runbook. Work the checklist above in order.

Not sure which vendors in your stack hold sensitive data? Run a quick third-party risk audit.

Run the free AI audit tool →

AI vendor risk assessment · AI agent supply chain audit

Sources

Accuracy note: Facts verified September 2, 2026 against KrebsOnSecurity (primary source, published Sep 1, updated Sep 2), 9to5Mac, Engadget, Cybernews, and Tom's Hardware coverage of the same events, and levelsio's X post via syndication API (timestamp 14:17:15 EDT). The 153M+ / 10M / 3M / 579K figures are Nexus's self-reported inventory, spot-checked by Krebs (blank-search estimate) but not independently audited. IDScan.net attribution is alleged — the company says it is investigating and has not confirmed a breach; the FBI's New Orleans field office opened an official inquiry on Sep 1 with no arrests or charges. Nexus went offline ~8:56 p.m. ET Sep 2. The “63%” figure is levelsio's own framing. Caesars Entertainment disputed its listing on IDScan.net's trust page. Do not treat any of this as legal advice.