IDScan.net has issued its first detailed public statement on the breach that triggered an FBI investigation, confirming that “on or around September 1, 2026,” the company detected unauthorized access to its data and brought in outside forensic specialists. The statement, reported by WBRZ citing Nola.com on September 8, is the most specific timeline IDScan.net has given since KrebsOnSecurity first tied the New Orleans-based identity-verification vendor to a dark-web listing selling more than 153 million driver’s license scans.
The breach itself is not new. CBS8 and other outlets reported last week that the FBI is investigating an alleged cybersecurity breach at an ID verification company, and that story has been building since early September. What changed on September 8 is that IDScan.net moved from silence and one-line comments to a formal written account of when it discovered the intrusion and what it has done since. That shift matters, because it is the first time the company has put a date on the incident rather than leaving reporters to piece together a timeline from dark-web listings and FBI statements.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
IDScan.net’s Breach Statement: What It Actually Says
According to the IDScan.net statement cited by WBRZ, the company said: “On or around September 1, 2026, IDScan.net received information indicating that certain data may have been accessed without authorization. Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident. This investigation is currently ongoing.”
That single paragraph does three things reporters had been waiting for since KrebsOnSecurity’s original story. It puts a specific date on the discovery. It confirms the company hired outside forensic help rather than investigating alone. And it frames the matter as still open, which lines up with the FBI’s own description of an active, ongoing inquiry. What it does not do is confirm the scope of the exposure, name the attack vector, or say whether the 153 million license figure circulating on the dark web matches what IDScan.net itself found in its systems.
Before this statement, IDScan.net’s only public comment came from Jillian Kossman, described by CSO Online as a marketing and operations leader at the company, who told Krebs: “I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” That line, from early September, was the extent of the company’s engagement with the press for nearly a week. The September 8 statement is a step up in transparency, even if it still withholds the technical detail that lawyers, regulators, and affected consumers actually want.
How the IDScan.net Breach Story Started
The story traces back to a dark-web marketplace called Nexus, which KrebsOnSecurity reported was selling high-resolution scans of more than 153 million U.S. and Canadian driver’s licenses. Bloomberg reported that access to the data was being advertised on Exploit, a Russian-language cybercrime forum, with the listing pointing to more than 160 million “North American” driver’s licenses. Krebs traced the operation back to IDScan.net, a Louisiana-based identity-verification vendor, as the likely upstream source of the leaked images.
Each record in the Nexus listings reportedly includes a person’s full name, address, date of birth, license number, issuing jurisdiction, and photograph, according to reporting that reviewed sample listings. A security newsletter tracking the case noted that close to 400,000 new records were added to Nexus in a single 24-hour period, which suggests the marketplace is still receiving fresh data rather than selling a static, one-time dump. Breach-tracking reports have tied the Nexus listing to a seller using the handle “databroker1.”
The FBI’s Role in the IDScan.net Investigation
The FBI’s New Orleans field office opened a formal inquiry into the source of the leaked images on or around September 1, according to KrebsOnSecurity. The bureau has kept its public comment brief. In statements given to multiple outlets, including USA Today and NBC News, the FBI said: “The FBI can confirm that it is looking into the incident. Due to the ongoing nature of the investigation, we decline to comment further.” That single sentence has been the bureau’s entire public position for more than a week, repeated nearly verbatim across USA Today, Bloomberg, and Yahoo News coverage.
Federal investigations into data brokers and dark-web marketplaces typically move slowly, and the FBI’s silence on scope, suspects, or timeline is standard practice for an active case. What is unusual here is the scale of what is allegedly exposed and the fact that a sitting cabinet official’s identification is reportedly part of the dataset, which raises the case’s profile well beyond a typical consumer data breach.
The Hegseth Detail That Escalated Coverage
NBC News reported that the FBI is investigating the alleged breach after hackers claimed to hold Defense Secretary Pete Hegseth’s driver’s license and advertised it for sale as part of the Nexus dataset. That detail turned a story about a data broker into a story with national-security overtones, and it is likely why outlets like CBS8 and Bloomberg picked up the story quickly rather than treating it as a routine breach disclosure. NBC’s reporting did not detail how the claim was verified, and neither the Pentagon nor IDScan.net has publicly confirmed the authenticity of that specific record.
Who Is IDScan.net?
IDScan.net is identified in KrebsOnSecurity’s reporting and multiple follow-up stories as a Louisiana-based identity-verification vendor headquartered in the New Orleans area. Companies in this space typically supply age-verification and identity-check technology to bars, retailers, online platforms, and other businesses that need to confirm a customer’s identity or age from a scanned government ID. That business model means a breach at a company like IDScan.net does not just expose data the company collected directly. It potentially exposes ID scans that were captured on behalf of thousands of downstream client businesses, none of which the affected individuals ever dealt with directly.
That structural detail is a big part of why this breach is drawing more scrutiny than a typical retailer hack. Consumers whose licenses ended up in an ID-verification vendor’s systems often have no idea which businesses used that vendor, making it hard for them to even know they were exposed until a story like this one breaks.
Breach Timeline: What Happened and When
| Date | Development | Source |
|---|---|---|
| Sept. 1-2, 2026 | KrebsOnSecurity traces Nexus dark-web listing to IDScan.net, FBI New Orleans opens formal inquiry | KrebsOnSecurity |
| Sept. 2, 2026 | Malwarebytes reports Nexus selling 153M+ licenses plus millions of other ID and medical records | Malwarebytes |
| Sept. 3, 2026 | Bloomberg reports FBI confirms it is investigating exposure of “North American” IDs sold on Exploit forum | Bloomberg |
| Sept. 3-4, 2026 | NBC News reports Hegseth driver’s license allegedly included in dataset advertised for sale | NBC News |
| Sept. 4, 2026 | IDScan.net’s Jillian Kossman gives brief comment to Krebs, declines further detail | CSO Online |
| Sept. 6, 2026 | USA Today reports FBI investigating dark-web sale, reiterates bureau’s “looking into it” statement | USA Today |
| Sept. 7, 2026 | Reports say at least five class-action lawsuits filed against IDScan.net | Legal-tracking coverage |
| Sept. 8, 2026 | IDScan.net issues formal statement confirming Sept. 1 discovery date and third-party forensics engagement | WBRZ / Nola.com |
What’s Actually in the Nexus Dataset
Reporting on the Nexus listings breaks the claimed dataset down into several categories of documents, not just driver’s licenses. The totals below come from Malwarebytes and legal-investigation summaries of the marketplace listing, and they have not been independently confirmed by IDScan.net.
| Document type | Claimed volume | Reported by |
|---|---|---|
| Driver’s licenses | 153 million+ | KrebsOnSecurity, Engadget, USA Today |
| Identification cards | 10 million | Malwarebytes, legal-tracking coverage |
| Travel documents / international IDs | 3 million (approx.) | Malwarebytes |
| Medical cards (incl. dispensary cards) | 579,000 (approx.) | Malwarebytes |
| Total credentials claimed by Nexus | 170 million (approx.) | SANS NewsBites |
Bloomberg’s figure of “more than 160 million” North American licenses is close to but not identical to the 153 million figure Krebs reported, a reminder that these numbers come from a criminal marketplace’s own advertising copy rather than a verified audit. Nexus, like most stolen-data marketplaces, has every incentive to inflate its inventory to attract buyers, so the real number of unique, valid records could be lower than advertised.
The Class-Action Lawsuits Piling Up
Legal-tracking coverage reported that five class-action lawsuits and a formal FBI investigation now surround IDScan.net as of early September. Plaintiffs’ firms that specialize in data-breach litigation, including at least one firm publicly investigating the Nexus/IDScan.net matter, are gathering potential class members ahead of formal certification. Class-action breach suits typically allege negligence in data security practices and seek damages tied to the cost of credit monitoring, identity-theft risk, and emotional distress, though none of these claims have been tested in court yet in this case.
The lawsuit count is likely to keep climbing. Breaches of this scale typically draw new filings for weeks after the initial disclosure, as more law firms open investigations and more affected individuals come forward. IDScan.net’s September 8 statement, by putting a specific discovery date on the record, gives plaintiffs’ attorneys a clearer timeline to build negligence claims around, particularly if it turns out the company knew about suspicious activity before September 1.
Market Impact: A Trust Problem for Identity Verification Vendors
Identity-verification companies sell trust as their core product. Retailers, bars, online age-gated platforms, and financial services firms pay vendors like IDScan.net specifically because they promise to handle sensitive ID scans securely on their clients’ behalf. A breach at that layer of the stack undermines the entire pitch, and it puts every ID-verification vendor’s enterprise sales team in the position of fielding hard questions from prospective clients about their own security posture.
Expect procurement teams at retailers and platforms that rely on ID-scanning vendors to start asking for updated SOC 2 reports, penetration-test results, and data-retention policies in the coming weeks. Vendors that can demonstrate they don’t retain full-resolution ID scans longer than necessary, or that encrypt stored images at rest with strong key management, are likely to use this incident as a selling point against competitors that can’t make the same claims. The identity-verification market has generally grown alongside stricter age-verification laws in the U.S. and abroad, and a breach this size is the kind of event that slows that growth by forcing longer security reviews into every new client contract.
Historical Context: Another Entry in a Heavy Year for Breaches
2026 has already produced several large-scale breach disclosures across different industries, from healthcare data brokers to court-records systems to dental benefits managers. The IDScan.net case stands out less for its size, since some other incidents this year have involved comparable or larger record counts, and more for the category of data involved. Driver’s license scans are harder to change than a password or even a credit card number. A driver’s license number, photograph, and address don’t get reissued the way a compromised payment card does, which is part of why security researchers treat physical-ID-document breaches as a more durable risk to victims than a typical retailer payment-card breach.
The pattern also fits a broader 2026 trend: breaches increasingly hit the vendors and data brokers sitting behind consumer-facing businesses, rather than the consumer-facing businesses themselves. That makes disclosure messier, because affected individuals often have no direct relationship with the breached company and no easy way to know they were exposed until a security researcher or journalist connects the dots, as Krebs did here.
How IDScan.net’s Response Compares to Other Breach Disclosures
| Response element | IDScan.net (as of Sept. 8) | Best-practice benchmark |
|---|---|---|
| Time to first public comment | ~3 days (brief comment via Kossman) | 24-72 hours |
| Time to formal written statement | ~7 days after story broke | Within 72 hours of confirmed scope |
| Third-party forensics disclosed | Yes, confirmed Sept. 8 | Disclosed immediately upon engagement |
| Scope of exposure confirmed | Not yet confirmed by company | Confirmed as soon as verified |
| Direct notification to affected individuals | Not yet reported | Required under most state breach-notification laws |
That comparison is not a formal scorecard, since IDScan.net has not published a full incident report. It’s a rough read of what has and hasn’t been disclosed publicly so far, based on the same sources cited throughout this article. The biggest open item is direct notification: state breach-notification laws generally require companies to tell affected residents once a breach involving personal information is confirmed, and as of September 8 there’s no public reporting that IDScan.net has begun that process.
What Happens Next: Five Predictions
- More class-action filings are likely within the next two to three weeks as additional law firms open investigations, pushing the count past the five reported as of September 7.
- State attorneys general, particularly in Louisiana and states with large numbers of affected residents, will likely open their own inquiries or demand answers on IDScan.net’s notification timeline.
- IDScan.net will probably face pressure to disclose a specific number of affected records rather than letting the 153-to-170 million range from the Nexus listing stand as the default public estimate.
- Downstream client businesses that used IDScan.net for age or identity verification may face their own disclosure obligations once it’s clear whose customer data passed through the breached systems.
- Expect renewed legislative attention to how long identity-verification vendors are allowed to retain scanned ID images, since data that isn’t stored can’t be stolen in bulk the way this dataset appears to have been.
These are analytical projections based on how similar breach cases have unfolded in the past, not confirmed plans from any of the parties involved.
What Affected Consumers Should Do Now
There’s no public tool yet where consumers can check whether their specific license was part of the Nexus listing, and IDScan.net has not published a notification process as of September 8. Security researchers covering the case have generally recommended a few standard precautions while the investigation continues: placing a credit freeze with the three major credit bureaus, watching for unexpected accounts or credit inquiries, and being cautious of phishing attempts that reference personal details like a license number or address, since scammers often use breached data to make follow-up scams look more credible. Anyone who receives a direct notification letter from IDScan.net or a business that used its verification services should keep it, since it may be needed for identity-theft claims or to join a class-action suit later.
The Open Questions IDScan.net Still Hasn’t Answered
Even with the September 8 statement, several basic questions remain unanswered in public reporting. IDScan.net has not said how the data was accessed, whether it was a direct system intrusion or a misconfigured storage system, nor has it confirmed how many records were actually taken versus the number Nexus is advertising. It also hasn’t said whether the breach affects data collected on behalf of its business clients, its own internal records, or both. Until the third-party forensic review IDScan.net says it has engaged is complete, most of the specifics driving this story will keep coming from KrebsOnSecurity’s tracing work and the Nexus listing itself rather than from the company at the center of it.
Frequently Asked Questions
Is the IDScan.net breach a new incident as of September 8, 2026?
No. It’s the same incident first reported in early September, tied to the Nexus dark-web marketplace and more than 153 million driver’s license scans. What’s new as of September 8 is IDScan.net’s formal written statement confirming a September 1 discovery date and third-party forensics engagement, as reported by WBRZ citing Nola.com.
What is IDScan.net?
IDScan.net is a Louisiana-based identity-verification vendor identified by KrebsOnSecurity as the likely upstream source of the leaked driver’s license images being sold on the Nexus marketplace.
How many records were exposed in the IDScan.net breach?
Reports cite more than 153 million driver’s license scans, plus roughly 10 million ID cards, 3 million travel documents, and 579,000 medical cards, based on the Nexus marketplace listing as reported by KrebsOnSecurity and Malwarebytes. These are figures from the marketplace’s own advertising and have not been independently verified by IDScan.net.
Is Defense Secretary Pete Hegseth’s driver’s license really part of the leak?
NBC News reported that hackers claimed to have Hegseth’s driver’s license and advertised it for sale as part of the dataset. Neither the Pentagon nor IDScan.net has publicly confirmed the authenticity of that specific record.
Is the FBI actively investigating IDScan.net?
Yes. The FBI’s New Orleans field office opened a formal inquiry around September 1, according to KrebsOnSecurity, and has told multiple outlets it “can confirm that it is looking into the incident” while declining further comment due to the ongoing nature of the case.
How many lawsuits has IDScan.net faced over the breach?
Legal-tracking coverage reported at least five class-action lawsuits against IDScan.net as of early September, with more considered likely as additional law firms open investigations.
Has IDScan.net notified affected individuals directly?
There is no public reporting as of September 8 confirming that IDScan.net has begun direct notification to affected individuals, even though most state breach-notification laws require this once a breach involving personal information is confirmed.
What should someone do if they think their ID was part of this breach?
Security researchers generally recommend placing a credit freeze with the major credit bureaus, monitoring for unexpected accounts or credit inquiries, and being cautious of phishing attempts that reference personal details, since that’s a common follow-up tactic after large ID-document breaches.


