Cybersecurity3 mins read

Suspected ID Verification Breach Raises Alarm Over Driver’s License Data

TechCrunch reports that hackers may have breached a major ID card verification service after an identity theft site claimed access to more than 150 million driver’s license and passport records.

What TechCrunch Says Happened

TechCrunch reports that hackers appear to have breached a major ID card verification service, citing a report by independent security journalist Brian Krebs. The identity theft site Nexus claimed it could search through more than 150 million driver’s licenses and passports belonging to people in the United States and Canada. The site also claimed it added about half a million new documents daily, allegedly sourced from a “major identity verification company.”

Why the Claimed Data Is So Sensitive

The exposed records reportedly included government-issued identity documents such as driver’s licenses and passports, with customer photos displayed when available. Krebs found his own driver’s license in the database, and Secretary of Defense Pete Hegseth was also listed on the identity search site. If authentic at the scale claimed, the incident would represent a major risk because identity documents are difficult to replace and can be abused for identity theft.

IDScan Identified as the Likely Source

Working with security researcher Zach Edwards, Krebs identified the likely source as IDScan, a Louisiana-based identity verification service. TechCrunch says IDScan is used by major tech and consumer brands to verify tens of millions of IDs around the world each month. IDScan’s chief operating officer told Krebs the company was investigating, while TechCrunch reported that its chief executive did not return a request for comment.

What Officials Have Said So Far

A Department of Defense spokesperson told TechCrunch it was aware of the reports and evaluating them. The FBI confirmed it is looking into the incident but declined to comment further. Nexus went offline shortly after Krebs’ report was published, but the broader questions around how long identity verification companies retain sensitive documents remain unresolved.

The Bigger Takeaway for Age and Identity Checks

The report lands as governments increasingly roll out age-verification laws that can require adults to upload identity documents to access websites or apps. TechCrunch notes that security experts and privacy advocates have long warned that storing large volumes of identity documents creates a major target for hackers. The clearest takeaway: systems that collect IDs need strong safeguards, limited retention, and clear accountability when sensitive records are exposed.

Discover More

    U.S. Coast Guard troops scaling a ladder onto a vessel
    Hacked Tankers Boarded

    The FBI and Coast Guard investigated compromised tanker networks near the U.S. coast.

    CybersecurityShipping
    Warning message, computer notification on screen
    Claude Used in OpenAI Hack

    A bug-bounty test shows how AI tools can accelerate vulnerability discovery and raise new security questions for AI labs.

    AI SecurityOpenAI
    An AI startup found vulnerabilities in OpenAI's infrastructure.
    Hacktron’s OpenAI Bounty

    A small AI cybersecurity startup used Claude in research that exposed OpenAI account vulnerabilities.

    CybersecurityOpenAI