HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Breach

Dark Web Platform Sells 153 M+ Driver’s Licenses After IDScan.net Breach

A new dark‑web marketplace is offering over 153 million driver’s‑license scans and millions of other identity documents stolen from IDScan.net. The breach underscores the need for continuous third‑party risk monitoring and defensible audit evidence of vendor controls.

Verisq™ Intelligence · 📅 September 03, 2026 · 📰 malwarebytes.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Dark Web Platform Sells 153 M+ Driver’s Licenses After IDScan.net Breach

What Happened — A newly discovered dark‑web marketplace, Nexus, is offering more than 153 million driver’s‑license scans, 10 million ID cards, 3 million travel documents, and hundreds of thousands of medical cards. The data appears to have been exfiltrated from identity‑verification provider IDScan.net, which confirmed it is investigating the incident.

Why It Matters for Trust & Control Assurance

  • Highlights the risk of relying on a single third‑party for high‑value identity data; continuous vendor‑risk monitoring is essential to detect and remediate such gaps.
  • Demonstrates the need for documented controls around data‑handling contracts, encryption, and breach‑response procedures that can be presented as audit evidence.
  • Aligns with Verisq’s Vendor Risk Management capability, which supplies real‑time assurance artifacts for third‑party oversight.

Who Is Affected – SaaS identity‑verification services, their downstream clients (e‑commerce, travel, cannabis dispensaries), and any organization that collects government‑issued IDs from customers.

Recommended Actions

  1. Review and tighten contracts with ID‑verification vendors: require recent SOC 2/ISO 27001 reports, breach‑notification clauses, and data‑encryption commitments.
  2. Deploy continuous third‑party risk monitoring to collect evidence of vendor controls and detect deviations promptly.
  3. Implement tokenization or on‑premise encryption for stored ID images to limit exposure if a provider is compromised.

Technical Notes – The breach was uncovered by KrebsOnSecurity, which captured front‑and‑back, infrared, and ultraviolet scans of driver’s licenses. The FBI’s New Orleans field office has opened an investigation. No specific vulnerability (CVE) was disclosed; the incident appears to stem from a supply‑chain compromise of IDScan.net’s data‑collection pipeline. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/09/dark-web-site-puts-153-million-drivers-licenses-and-millions-more-ids-up-for-sale

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →