The reported Nexus document market is not another password breach. It is about the evidence people are asked to show after password breaches: driver’s licenses, identity cards, travel documents, medical cards, faces, barcodes and document security features. KrebsOnSecurity reported that a new identity-theft service was offering scans of more than 153 million driver’s licenses from the United States and Canada, plus millions of other identity documents. The FBI’s New Orleans field office reportedly opened an inquiry, and the Nexus site disappeared soon after the report.

Anonymized ID cards protected by a shield with data deletion and lock icons

The right response is not panic. The right response is to understand what is known, what is still alleged, and why document scans create a different kind of risk from exposed email addresses or reused passwords. You can reset a password. You cannot easily reset your face, date of birth, old address history, signature, document photo and the fact that a scan exists in someone else’s files.

The reporting points toward the identity-verification supply chain, with IDScan.net named by Krebs as the likely source under investigation. IDScan.net had not confirmed the nature or scope of any unauthorized access at the time covered by the reporting, and Cybernews also noted that the company had not confirmed the alleged breach scale. That uncertainty matters. Criminal-market listings, screenshots and researcher observations are not the same as a finished forensic report. But the risk model is real even before every fact is settled: businesses have built a large hidden layer of document-copying services, and those services are attractive targets.

What is known so far

KrebsOnSecurity reported that Nexus advertised more than 153 million driver’s licenses, more than 10 million identification cards, more than 3 million travel or international IDs, and at least 579,000 medical cards. Krebs also wrote that a blank search returned about 11.5 million pages with roughly 15 results per page, and that the number of driver-license records appeared to grow by almost 400,000 in 24 hours. Those numbers should be treated as reported observations and claimed counts, not final breach-notification totals.

Krebs found his own driver’s license in the service and described multiple image files: front and back scans, including ordinary, infrared and ultraviolet versions. He also wrote that documents for friends and family members could be matched to travel or rental timelines. That is why the story is not merely theoretical. It appears to involve images that people may have handed over during ordinary real-world checks.

The same reporting says the FBI opened an inquiry into the source of the images. It also says IDScan.net was investigating. Krebs later updated the article with customer-context corrections, including a note that Caesars Entertainment said it was not an IDScan.net client and had not used VeriScan since February 2025. That update is important because marketing customer lists can be stale and because readers should not assume that every named brand’s customers are affected.

What is not yet proven

The exact source is not publicly proven in a complete forensic sense. The total number of unique people affected is not proven. Document categories may overlap. Some records may be old, duplicated, partial or from multiple sources. Nexus disappearing after publication does not prove the data is gone; it may mean the operator closed, moved or changed access.

It is also not proven that every organization using ID scanning, or every customer logo ever displayed by a vendor, is part of this incident. That distinction matters for calm risk coverage. The useful conclusion is not “every scanned ID is already public.” The useful conclusion is “full document retention by intermediaries creates a high-impact failure mode, and people often do not know which intermediary holds their scan.”

Why ID scans are different from passwords

A password is supposed to be secret and replaceable. A scanned identity document is not. It contains semi-public facts, official identifiers, visual proof, machine-readable data and human trust signals in one package. A criminal who has a clear front-and-back scan may be able to use it in social engineering, account recovery attempts, fraudulent signups, targeted harassment, doxxing or attempts to pass weak identity checks.

Driver’s licenses can sometimes be reissued, but replacement is not a clean reset. The old scan may still contain name, date of birth, address at the time, face, signature and barcode information. A new number may help in some cases, but it does not make the old image harmless.

Medical cards and travel documents add other risks. A medical card can expose insurance or care relationships. A travel document may expose nationality, travel habits or identity data that is harder to change. For people at elevated risk — domestic-violence survivors, witnesses, activists, law-enforcement personnel, public figures, high-net-worth individuals — document exposure can have physical safety implications, not just credit risk.

How these scans are created

Most people do not think of an ID scan as data outsourcing. They think of renting a car, checking into a hotel, entering a restricted building, buying age-restricted products, opening an account, visiting a dispensary or proving age online. The person at the counter scans a card, the app says approved, and the process continues.

Behind that moment can be several different actions: visually checking an ID, scanning barcode data, photographing the front and back, capturing infrared or ultraviolet images, matching a face, querying a database, storing a verification result, storing the full image, or sending data to an API provider. Those are not the same from a privacy standpoint.

The safest design usually proves the minimum necessary fact: this person is over a required age, this document appears valid, this visitor was checked today. The riskier design keeps the full document image longer than needed, especially if the business only needed a yes/no decision.

Why verification vendors become systemic risk

Identity-verification vendors sell fraud prevention, age assurance, access management and compliance. That can be useful. Fake IDs exist. Regulated businesses may have legal obligations. Financial, hospitality, logistics, cannabis, gaming and access-control workflows often need some form of identity check.

The systemic risk comes from concentration. A single vendor or API can touch many industries. If it retains full images, security features, face data and metadata from many customers, it becomes a valuable target. The end user usually does not choose the vendor, does not negotiate retention terms, and may never see the vendor name.

This is the uncomfortable lesson: a service that reduces fraud for each customer can increase aggregate risk if it becomes a central store of documents. Better scanning does not solve that by itself. Data minimization, retention limits, encryption, access logs, deletion controls and privacy-preserving credentials matter at least as much as detection accuracy.

What people should do now

Do not try to find yourself through criminal markets or “breach lookup” sites that ask for more personal data. That creates new risk. Watch for official notices from businesses where your ID was scanned. Treat unexpected calls, emails or messages about document replacement, refunds, hotel bookings, rental cars, cannabis purchases or age-verification accounts as phishing candidates until independently verified.

In the United States, consider freezing credit at Experian, Equifax and TransUnion. A credit freeze does not stop every type of identity misuse, but it makes new-account fraud harder. If you expect legitimate credit applications soon, learn how to temporarily lift the freeze. A fraud alert can also be useful. IdentityTheft.gov is the central FTC recovery resource if you see actual misuse.

Also harden account recovery. Your email account, mobile phone account and financial accounts are often the path criminals use after collecting identity data. Use unique passwords, phishing-resistant multi-factor authentication where possible, carrier account PINs, bank alerts and careful recovery questions. If you are in the United States and worried about tax fraud, an IRS Identity Protection PIN may be worth considering. Canadians should monitor guidance from the Canadian Anti-Fraud Centre and relevant provincial or federal authorities.

Replacing a driver’s license may be useful in some jurisdictions after confirmed misuse, but do not assume it erases the risk. Ask the issuing agency what changes, what remains the same, and whether the old number or barcode can still be abused.

What businesses should do now

Every organization that scans IDs should run an inventory. Where are IDs scanned? Which systems receive the image? Is the full front and back stored? Are infrared or ultraviolet images stored? How long? Who can access them? Are scans used to train models? Which vendors and subprocessors receive the data? Can old scans be deleted? Is deletion actually logged and verified?

Separate verification from retention. If the business only needs to know that a person is over 21, storing a full document image for years is hard to justify. If retention is legally required, store the minimum required fields for the minimum required time. If full images are not required, disable image retention or shorten it sharply.

Procurement and legal teams should ask vendors for a data-flow diagram, retention schedule, breach-notification timing, audit reports, security certifications, storage regions, customer-managed key options, access-log exports, deletion APIs, training-data rules and subprocessor lists. They should also test contract language with a tabletop exercise: if the vendor’s document store is exposed on Friday night, who tells whom by Monday morning?

What product teams should change

“Upload your ID” is often the fastest trust-and-safety feature to add, but it should not be the default answer. Ask whether the product needs a document image, a parsed field, a risk score, an age assertion, a one-time verification result or a reusable credential. Those are different data burdens.

Mobile driver’s licenses and verifiable credentials may help when they prove limited attributes without spreading copies of the full card. They are not magic; they introduce governance, device, issuer and surveillance questions. But they point in the right direction: prove less, retain less, expose less.

If a product still needs document verification, build deletion into the workflow. Give users a clear explanation of what is stored, by whom, for how long and how to request deletion. Do not hide the verification vendor in a privacy-policy maze.

What not to do

Do not assume a credit freeze solves stalking or account-recovery risk. Do not upload your ID to random “check if you are affected” pages. Do not call phone numbers from urgent emails about this story. Do not publish screenshots of your own document while asking for help. Do not assume that because Nexus disappeared the data is gone.

Also avoid the opposite mistake: fatalism. Most exposed data is not used immediately, and not every record becomes fraud. Practical defenses reduce risk. Calm, boring actions are more useful than doom scrolling.

The bigger lesson

The identity-verification industry often frames the problem as fake IDs versus better scanning. That is only half the issue. The other half is retention. A system can be excellent at detecting fake documents and still be dangerous if it keeps too much real-document data in one place.

The safer future is not simply “scan better.” It is “prove less.” Prove age without handing over a full birthdate and address. Prove eligibility without storing front-and-back images. Prove that a visitor was checked without keeping enough material to impersonate them later.

The Nexus story is still developing, and the exact source and scope need official confirmation. But the defensive lesson is already clear: identity verification must stop treating full document copies as harmless operational exhaust. They are high-value security assets, and they deserve the same minimization, governance and breach planning as payment data or credentials.