A suspected massive cyberattack has compromised more than 150 million driver's licenses and passports belonging to residents of the United States and Canada, according to a report published September 2 by independent security journalist Brian Krebs. The breach appears to have targeted a major identity verification company, with hackers gaining what may be near real-time access to its systems. Krebs confirmed the authenticity of the stolen data by finding his own driver's license among the searchable records.

The stolen identity documents surfaced on Nexus, an identity theft site that appeared on the dark web this week, the report states. An advertisement posted on a known Russian cybercrime forum claimed the site was adding roughly half a million new documents each day, sourced from a "major identity verification company," suggesting the attackers maintained ongoing access to the company's databases. The listing stated that customer photographs are shown when available. Working alongside security researcher Zach Edwards, whose ID card was also among the stolen data, Krebs identified the probable source as IDScan, a Louisiana-based identity verification service used by major technology and consumer brands to verify tens of millions of people's IDs globally each month.

Secretary of Defense Pete Hegseth was among those whose photographs appeared on the identity search site, according to the report. A Department of Defense spokesperson told TechCrunch the agency is "aware of these reports and is evaluating them." IDScan chief executive Jimmy Roussel didn't respond to TechCrunch's request for comment, but the company's chief operating officer Jillian Kossman told Krebs that IDScan was investigating the incident. The FBI's field office in New Orleans is probing the breach, Krebs reported, and an FBI spokesperson confirmed to TechCrunch that the bureau is "looking into the incident" but declined further comment. The Nexus site went offline shortly after Krebs' report was published.

The breach arrives as governments increasingly implement age-verification laws that largely depend on requiring adults to upload identity documents to confirm they're old enough to access a website or app. Security experts and privacy advocates have long cautioned that companies retaining vast quantities of people's identity documents for extended periods expose that information to theft by hackers, the report notes. By all measures, this would rank as the largest known single breach of identity documents in recent years. The incident underscores the vulnerability of centralized identity verification systems that accumulate millions of sensitive government-issued documents—particularly when those services are embedded in everyday transactions like entering bars, purchasing cannabis at dispensaries, or renting vehicles. For enterprise leaders evaluating third-party verification vendors, the breach highlights the urgent need to scrutinize not just compliance frameworks but the operational security posture of any partner handling biometric or government credential data at scale.