Blog
Security8 Sep 2026

The ID scans nobody deleted.

A dark web service advertised document images for more than 170 million people in the US and Canada, and said it had been pulling fresh data from an identity verification company for over a year. The FBI is investigating.

On 31 August a service calling itself Nexus appeared on the Russian-language cybercrime forum Exploit, advertising identity documents belonging to more than 170 million people across the United States and Canada. Its listed inventory ran to over 153 million driver's licenses, more than 10 million other identification cards, over 3 million travel and international identity documents, and at least 579,000 medical cards. Brian Krebs reported the service on 3 September, and the FBI told TIME it was "looking into the incident".

What was actually on offer

The listing was not a table of names and license numbers. It offered the document images themselves: front and back, together with infrared and ultraviolet captures. Verification platforms take those extra layers to check the security features built into a modern license, which is why their presence in the data points at a verification provider rather than a shop or a licensing authority. Krebs verified licenses belonging to nine individuals and found timestamps that lined up with documented car rental and travel dates. While he was looking, the number of driver's licenses in the database grew by roughly 400,000 in 24 hours.

A breach measured in months

Nexus described its source as a live breach at a major identity verification company, and claimed it had been exfiltrating new data for over a year. The FBI's New Orleans field office opened an investigation, and reporting has pointed at IDScan.net, a New Orleans identity verification provider whose customers include cannabis dispensaries alongside retail, transport and finance businesses. The company has said it is investigating. Nothing is confirmed, and that attribution should be read as an allegation until the investigation settles it. The growth rate does not depend on attribution: whatever the source was, it was still feeding the database while the listing sat in public view. Nexus went offline within hours of the Krebs report.

The copy you cannot take back

Scanning an ID is a moment. You hand a license across a counter or upload it to a form, the answer comes back yes or no, and the transaction closes. The image does not close with it. It goes to a vendor, is retained for audit or fraud investigation, and sits in a system the person in the photograph has no relationship with and no way to query. Years later that document is still valid, still matches a face, and still opens accounts. A password can be rotated the morning after a breach. A date of birth, a license number and an ultraviolet scan of a physical card cannot.

The shape this failure keeps taking

Set the specific vendor aside. The pattern repeats across the incidents of the past year, including the voice phishing intrusion we wrote about last week: a system that has to read sensitive files in order to do its job keeps them readable afterwards, in whichever store was operationally convenient. Encryption at rest is usually present and usually beside the point, because the attacker arrives holding a working credential and the data decrypts for them exactly as designed. What actually reduces the damage is having fewer readable copies sitting in fewer systems.

A stolen password is revoked in a minute. A stolen passport scan stays valid for a decade.

Sending a document without leaving another copy

Identity verification is not something a storage product replaces; a dispensary checking an age has to look at the card. But plenty of the sensitive documents people move around are not verification at all: the ID scan a landlord asks for, the passport page an accountant needs, the medical letter a lawyer requests. That transfer step is usually a mail attachment or a shared drive link, and each one deposits another readable copy in another company's system.

SpaceBox Lite is built so the transfer step does not add one. Files are encrypted on the sender's device with AES-256-GCM, and the key is wrapped using post-quantum ML-KEM-768 (NIST FIPS 203). Private keys stay on the device, our servers hold ciphertext only, and a sender needs no account and gives us no personal data. Post-quantum key exchange is not unique to SpaceBox. The property that matters for this story is simpler: a breach of our storage returns bytes nobody can read. The free tier covers 1 MB, one sender and three files, and a free voucher at beta.i46.space adds 100 MB and 100 files (email required). SpaceBox Lite is not available to EU and EEA residents during the beta. Why SpaceBox sets out the rest of the design.

The Nexus site disappeared from the dark web in an evening. The images it was selling did not disappear with it, and neither did the practice of keeping them.

Send documents nobody else can readEnd-to-end encrypted, post-quantum, ciphertext only. Start free.

Keep reading

All articles โ†’