153 million
Identity verification provider IDScan.net has confirmed it was the victim of a major data breach that resulted in the theft of a database containing over 153 million U.S. and Canadian driver's licenses. The confirmation came after the massive dataset was advertised for sale on a dark web marketplace called 'Nexus.' The company stated that on September 1, 2026, it identified unauthorized access to its cloud platform where customer-provided identification data was stored. The breach exposes millions of individuals to a high risk of identity theft and fraud. The FBI is reportedly investigating the incident.
The incident appears to be a classic case of a cloud storage breach. An unauthorized third party gained access to IDScan.net's cloud environment and exfiltrated a huge trove of sensitive data. This data was subsequently put up for sale on the 'Nexus' dark web forum, a common tactic for monetizing stolen information. A journalist was able to verify the data's authenticity by finding their own driver's license among the samples offered by the threat actor.
IDScan.net provides identity verification services to a wide range of industries, including retail and car rentals, which require customers to scan their driver's licenses.
The core of the incident was the compromise of IDScan.net's cloud platform. While the specific method of unauthorized access was not disclosed, this type of breach often stems from misconfigured cloud storage (e.g., a public S3 bucket), stolen credentials, or a vulnerability in a cloud-hosted application. This is a form of T1530 - Data from Cloud Storage.
The stolen database contains highly sensitive Personally Identifiable Information (PII), including:
The dataset for sale reportedly contained:
The impact of this breach is critical and far-reaching.
NexusFor organizations managing large PII databases in the cloud, hunting should focus on detecting unauthorized access and exfiltration:
Cloud Trail / Audit LogsListBuckets, GetObject, or CreatePresignedUrl from unexpected users, roles, or IP addresses.Large data egress from storagePublic storage exposureDormant account activityTo prevent similar breaches, organizations handling sensitive PII in the cloud must implement a defense-in-depth strategy:
M1054 - Software Configuration).M1041 - Encrypt Sensitive Information).M1032 - Multi-factor Authentication).Lawsuits against IDScan.net double to 19 following data breach, alleging negligence.
Properly configuring cloud storage access controls, such as disabling public access, is fundamental to preventing this type of breach.
Mapped D3FEND Techniques:
Encrypting data at rest in cloud storage can make the data unusable to an attacker even if they manage to exfiltrate it.
Mapped D3FEND Techniques:
Enforcing MFA on all cloud administrative accounts makes it much harder for attackers to gain initial access via stolen credentials.
Mapped D3FEND Techniques:
IDScan.net becomes aware of unauthorized access to its cloud platform.
News of the breach and the data being for sale on the dark web becomes public.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.