Home
Blog
Breach on an epic scale – Who’s got your identity now?

Breach on an epic scale – Who’s got your identity now?

Paul Ducklin
09/04/2026
Share this article:

Up to 170 million victims

Sadly, data breach news stories appear all the time, because our collective resilience to cyber intrusions is worse than it should be.

And most, if not all, cyber-breach stories remind us of the critical truth that every breach matters.

More cynically put, this means that we cannot reliably trust organizations that collect our data for their own commercial or operational benefit to look after it with the zeal and focus we would expect.

Here’s a striking recent example, thanks to investigative journalist Brian Krebs’s informative research into a dark web “data for sale” service calling itself Nexus.

Nexus’s database was epic in its scale, apparently including more than 170 million scans of ID documents, mostly driving licenses, mostly from the US and Canada, where each state or province independently issues its own licenses, but also including other widely-accepted forms of ID issued in other countries.

You might assume that this magnitude of breach would require the attackers to break into dozens, if not hundreds, of different networks, given that the US and Canada alone have about 70 separate jurisdictions that issue licenses – and that’s before we consider other sorts of ID and other countries.

But it seems to be down to a single commercial entity that collects this sort of data with the co-operation (or at least the unavoidable consent) of the ID holders, for a range of reasons including helping businesses comply with government-proclaimed rules that require them to “know their customers”

Outsourced collection at scale

If you’re a car rental company, and you’re about to hand over the keys to a nearly-new car to someone you’ve never met before, you’ll understandably be keen to get the best possible idea of whether that person is legally allowed to drive a car at all, and to have some idea where to find them if they trash the car and abscond.

Similarly, if you’re a shop that sells age-regulated products such as alcohol, legal drugs, and so on, you’ll want to comply with the letter and the spirit of the rules that require you to verify, and perhaps to retain copies of, recognized IDs at the point of sale.

In some countries, even hobby sites and local sports clubs with discussion forums are now expected to have a formal age verification process, to reduce the risk that children might end up in contact with creepy adults hiding behind a pseudo-anonymous facade.

Automated, real-time verification and storage of government issued IDs is therefore a growing and profitable online service these days.

Ironically, in some countries, the data that these companies are processing in bulk can’t openly be shared between government departments, even within the same country, as a precaution against privacy abuses.

More importantly, these services aren’t just collecting the data from IDs – name, license number, address, date of birth, and the like – but also multiple high-resolution scans of the physical ID itself.

And they’re keeping this data not only in case their customers need it for a court case, but also for the eternal cycle of training and retraining their statistical models – their AIs – as the IDs themselves change and evolve to improve their fraud resistance.

The database in Krebs’s investigation included detailed scans (under visible, ultra-violet, and infra-red light) of critical identifying documents – scans that may make it possible to create bogus IDs that are good enough to fool other online verification tools, or even to generate look-alike ID cards that pass muster face-to-face.

Krebs’s report shows the sort of data that Nexus was selling, and the way in which prospective “customers” could search for IDs to buy.

He found that a search for everything returned over 11 million pages with 15 items per page, suggesting that there really were 170 million documents in total.

Searching for himself (and, with their permission, for other friends and family members) showed that at least some of the scans up for sale were genuine, and recent.

Connecting the dots

His report is well worth reading, because he explains how he connected the dots from the scans stolen from his friends and family to their likely sources.

At first, he assumed that air travel was the trouble, given that he and many Americans use licenses for identification when checking in for domestic flights.

Then, however, he remembered that on the date the criminals claimed his scan was stolen, he’d checked in for a flight with his passport, not his license.

On that day, however, both he and his mother, who were attending a family funeral together, had handed over their licenses to the same car rental company at their destination, and both their licenses showed up on the Nexus site, with timestamps just a few seconds apart.

Krebs also checked with contacts whose licenses were on sale and who are federal employees.

Two of those contacts, he says, recalled that they used their government IDs to take flights on the given date, but that both of them rented cars at their destinations – from the same company that Krebs and his mother had used.

Another contact whose data was stolen confirmed that his “breached data date” coincided with a trip to Las Vegas for DEF CON, where he didn’t rent a car, but did present his license at the airport, at his hotel, and at a cannabis shop in the city.

This contact’s recollection was that although his license was checked at all three places, only the cannabis shop visibly put it into a scanning device.

Combining this with information that the FBI field office is looking into the source of the breached data via its field office in New Orleans, plus a 2022 press release from a New Orleans-based ID scanning service about an exclusive deal with the same chain of cannabis shops, plus a marketing page on the same company’s website listing the common car rental company․․․

․․․seems to identify the identity-processing company connected to the breach.

As Krebs points out, this business advertises that its “systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world,” making it a clear target for cybercriminals seeking a treasure trove of high-resolution ID scans.

What to do?

There are definitely places and activities where we should feel safer because we’re required to identify ourselves – if only to make it harder for other people to pretend to be us.

But there are places and activities where we don’t really have a choice, whether we’re cashing in a medical prescription, renting a car, or just signing up for a web service.

Even for services where the law doesn’t explicitly require ID scans, if sufficiently many competitors in one industry sector start doing so, ID scans become a “price of entry” without which we can’t take advantage of new services and technologies in that sector.

Yet the number and scale of data breaches in recent years suggest that we should be pushing back against the poor protection our data gets after we’ve shared it, especially when the law gives us no choice but to do so.

We should also be doing our best to ensure we treat personal data that we collect with the respect it deserves:

  • Collect only what you truly need.
  • Securely delete data as soon as you no longer need it. (Focus on whether you truly need it, not merely whether having it “might be useful later.”)
  • Remember that you don’t have to do it all yourself.

At SolCyber, we help organizations build real resilience with our 24/7 detection and response services and Foundational Coverage.

Through our human-led outsourced security programs, we provide coordinated protection across people, systems, and operations, giving you visibility into your environments and working to keep not only your business but also your customers’ data safe from threats.

Reach out to the experts today to learn how SolCyber can help you become cyber resilient.


Ask how SolCyber can help you do cybersecurity in the most human-friendly way. Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit you or your business!

Breach on an epic scale - Who's got your identity now? - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Featured image of face on passport from sample data provided by the Council of the European Union as part of PRADO, the Public Register of Authentic identity and travel Documents Online.

Paul Ducklin
Paul Ducklin
09/04/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

14823