Добре дошли на нашите читатели от България и welkom aan onze lezers uit Nederland — we’re glad you’re here.
A dark web marketplace called Nexus surfaced on the Russian-language cybercrime forum Exploit on August 31, 2026, advertising searchable high-resolution scans of more than 153 million North American driver's licenses. The FBI's New Orleans field office opened a formal investigation within 24 hours. The story broke when investigative journalist Brian Krebs found his own license in the free samples — along with those of Defense Secretary Pete Hegseth and an FBI assistant director.
The breach is still developing. IDScan.net, the Louisiana-based identity verification company believed to be the source, has confirmed it is investigating but has not issued a public statement confirming scope or timeline. The 153 million figure is the marketplace's claim, not a verified count. What is confirmed: the images are real, the infrared and ultraviolet data is authentic, and the FBI has opened a case.
For healthcare security teams, this isn't background noise. The dataset includes 579,000 medical cards. One of IDScan.net's named clients is Jack Henry — a core healthcare financial services provider. And any healthcare organization that outsources patient identity verification to a third-party vendor just inherited that vendor's blast radius.
What Nexus Was Selling
The Nexus listing, which surfaced on the Russian-language cybercrime forum Exploit, included over 153 million driver's licenses, over 10 million identification cards, more than 3 million travel documents and international IDs, and at least 579,000 medical cards. The operators claimed coverage of more than 170 million people total — treat each figure as a separate claim made by the service's operators rather than a single deduplicated victim count.
What separates this from a typical credential dump is the nature of the images themselves. Nexus was selling high-resolution document scans with infrared and ultraviolet imaging — the same multi-spectral captures IDScan.net used to authenticate documents. This is the detail that makes the breach structurally different from a database of names, addresses, and license numbers.
Standard document fraud uses photographic copies of IDs. Banks, car rental companies, and government agencies counter this with UV and IR verification — light spectra that reveal security features invisible to a standard camera. The infrared and ultraviolet images stolen in this breach may give criminals access to data that is normally used to authenticate a physical document — meaning stolen documents from this dataset can potentially pass the authentication checks designed to catch stolen documents. The security layer built to stop this class of fraud is now weaponized against the people it was meant to protect.
Krebs confirmed the authenticity of leaked images with at least nine affected individuals, including licenses tied to Defense Secretary Pete Hegseth and an FBI assistant director. The presence of senior government officials in the free sample set is not coincidental — it's a demonstration of the dataset's reach and a signal about the breadth of IDScan.net's client base.
The IDScan.net Connection
The trail points to IDScan.net, a New Orleans identity-verification firm that performs about 21 million verifications a month for clients including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, Caesars Entertainment, and the dispensary chain Planet13. Timestamps on the stolen images matched the dates people had handed IDs to IDScan.net customers, and the leaked files carried the infrared and ultraviolet scans specific to IDScan.net's pipeline.The timestamp match is the forensic anchor. When the date a person handed their ID to an IDScan.net client corresponds to the date on the stolen image, it establishes the data provenance with high confidence — independent of anything IDScan.net says or doesn't say publicly.
The operator claimed the trove covered more than 170 million people and had been adding new records for more than a year. If accurate, the exfiltration began in mid-2025 or earlier — well before the marketplace surfaced publicly. IDScan.net has not confirmed or denied the claimed timeline.
IDScan.net's technology is installed at more than 20,000 locations worldwide. That's the scope of the potential exposure: every business at every one of those locations that scanned a customer's ID during the claimed exfiltration window may have contributed records to the Nexus dataset — without knowing it, and without their customers knowing it.
The FBI's New Orleans field office opened a formal investigation on September 1, and the marketplace called Nexus went offline within hours of the story breaking. Going dark is not the same as the data disappearing. The operators have the dataset regardless of whether the storefront is live.
The Healthcare Angles
579,000 Medical Cards
The medical card figure in the Nexus dataset is the line that healthcare security teams need to stop at. The 579,000 medical cards include cannabis dispensary cards. Cannabis dispensaries use ID scanning for age and identity verification at point of sale — IDScan.net is a common vendor in that space, as the Planet13 client relationship confirms.
The category "medical cards" is broader than dispensary cards, however. Medical identification cards — insurance cards, Medicaid cards, Medicare cards, state medical program cards — are used for identity verification at healthcare registration desks, pharmacies, and clinical intake points. Whether non-dispensary medical cards are included in the 579,000 figure has not been confirmed, but the category label doesn't exclude them.
The HIPAA implications depend on what's in those 579,000 records. A driver's license scan combined with a medical card scan, timestamped and linked to a specific dispensary or healthcare facility visit, could constitute protected health information — specifically, information that could identify an individual in connection with healthcare services received. That's a PHI determination that requires legal analysis, but healthcare security and compliance teams should be asking the question now rather than waiting for regulators to ask it for them.
Jack Henry and Healthcare Financial Services
Jack Henry & Associates is one of IDScan.net's named clients. Jack Henry provides core banking and financial technology infrastructure to more than 8,000 financial institutions — including community banks and credit unions that serve as the financial backbone of regional healthcare systems, rural hospitals, and healthcare-adjacent businesses.
The inclusion of Jack Henry in IDScan.net's client list means that individuals who have verified their identity at a Jack Henry-connected financial institution during the claimed exfiltration window may have records in the Nexus dataset. For healthcare organizations that bank with Jack Henry-connected institutions — or whose patients do — this is a downstream vendor risk exposure that extends beyond the initial breach perimeter.
Patient Identity Verification at the Registration Desk
Healthcare patient registration is an ID verification workflow. Hospitals, urgent care centers, pharmacies, and specialty clinics scan or photograph patient IDs at intake — for insurance verification, identity confirmation, and fraud prevention. Many use third-party ID verification platforms to do this.
Any healthcare organization that used IDScan.net for patient ID verification during the claimed exfiltration window has potentially contributed patient records to the Nexus dataset. Those patients have not been notified. The healthcare organization may not yet know it was a client of IDScan.net — many ID verification tools are embedded in registration software or revenue cycle platforms without the end organization being aware of the underlying vendor.
This is the vendor risk management problem made concrete: your patient's identity data traveled through IDScan.net's infrastructure as part of your registration workflow, and you may not have known IDScan.net was in your supply chain. That's the same supply chain visibility gap the CISA Vulnerability Review identified last week and the same one the OWASP AST10 framework flags for agentic AI environments. The mechanism is different; the governance failure is the same.
Synthetic Identity Fraud and Healthcare Insurance
The UV and IR imaging capability is what elevates this breach into a different fraud risk category. Standard identity theft uses stolen data to open accounts, file fraudulent claims, or impersonate individuals in low-verification contexts. The multi-spectral images stolen from IDScan.net enable something more sophisticated: synthetic identity documents that pass the authentication checks designed to catch synthetic identities.
In healthcare, the downstream fraud risk is healthcare insurance fraud and patient identity theft — using stolen identity documents to receive medical services, file insurance claims, or obtain prescription medications under someone else's identity. These fraud categories are already endemic in healthcare; a dataset of 153 million UV/IR-authenticated identity images at the disposal of organized fraud operations is a meaningful supply-side expansion of that risk.
What Healthcare Security Teams Should Do Now
The situation is still developing and IDScan.net has not confirmed scope. That uncertainty is not a reason to wait. The actions that make sense now will still make sense when the full picture is confirmed.
Determine whether your organization uses or has used IDScan.net. This requires looking beyond obvious vendor relationships — IDScan.net's technology is embedded in registration platforms, revenue cycle software, dispensary point-of-sale systems, and retail ID verification tools. Your procurement and IT teams may not know the name even if the technology is in use. Ask the vendors whose products touch your patient registration or identity verification workflows.
If you determine IDScan.net is in your supply chain, preserve records of the relationship scope and timeline. The exfiltration period claimed by Nexus covers at least a year prior to August 2026. Any patient ID verification performed through IDScan.net during that window is potentially in scope.
Assess the 579,000 medical card figure for HIPAA applicability. If your organization scanned medical cards through IDScan.net and those records are in the Nexus dataset, you may have breach notification obligations. Get legal counsel involved before making that determination publicly.
Review your vendor risk management program for third-party ID verification vendors. IDScan.net processes 21 million verifications per month at 20,000+ locations. A vendor operating at that scale with that level of access to sensitive identity data should carry commensurate security scrutiny in any vendor risk framework. If it didn't, that's the process gap this incident reveals.
Advise staff to treat any patient presenting with identity documents as potentially using compromised credentials for the foreseeable future, particularly in high-fraud-risk contexts like pharmacy, registration, and insurance verification. This is not a reason to refuse service — it's a reason to apply appropriate secondary verification where policy permits.
The Vendor Risk Lesson That Keeps Repeating
Any company that outsources ID verification to a third-party vendor now inherits the vendor's blast radius, and CISOs at Hertz, Target, FedEx and the rest just found out how big theirs is.Healthcare is not different from any of those organizations in this respect. The IDScan.net breach is a third-party vendor risk incident — the same category as the Change Healthcare ransomware event, the same category as every supply chain compromise in the CISA Vulnerability Review dataset. The organization whose data is in the Nexus marketplace may never have had a direct relationship with IDScan.net. Their vendor did.
The Nexus breach is still developing. Check KrebsOnSecurity and the FBI's public statements for updates as the investigation progresses. But the vendor risk management and HIPAA applicability questions don't require waiting for the final breach count to be confirmed.
Key Links
- KrebsOnSecurity: FBI Probes Service Selling 153M+ Driver's Licenses (Primary Source)
- CyberInsider: 153 Million Driver's Licenses Exposed in Suspected IDScan Breach
- TechTimes: IDScan.net Breach Exposes 153 Million Licenses With Infrared Scans That Pass Bank Checks
- AI Weekly: FBI Probes Nexus Sale of 153M Driver's Licenses Tied to IDScan
- IDScan.net — Official Site
- HHS: HIPAA Breach Notification Rule
- HHS: HIPAA Minimum Necessary Standard
- Related: CISA Vulnerability Review — AI Is About to Make Your Known Weaknesses Everyone's Problem