Forgotten Dairies
America’s Identity Industry Has Become a Security Threat -By Fransiscus Nanga Roka
Verification contractors with businesses that use them have to specify which vendor gets an ID (if any), retains what, for how long and possibly why else. Contracts cannot outsource accountability.
In the name of deterring fraud, America built a huge identity-surveillance industry. But in a new twist, hackers have one upped the situation, and at least one compromised vendor potentially provided criminals with everything they need to impersonate an entire continent.
The crisis came to light on September 1, 2026, when cybersecurity journalist Brian Krebs discovered that an entity called “Nexus” was advertising through the Russian cybercrime forum Exploit access to upwards of more than 170 million identity documents. It purportedly contained scans of 153 million US and Canadian driver’s-licenses, 10 million ID cards, more than three million travel or international documents and 579,000 medical cards. As a teaser, the license of Krebs itself was shown. He later confirmed records for nine individuals.
This answers we the who, what and when. But it is the where, how and why that tells a bigger scandal.
New Orleans-based IDScan was implicated. net, an identity-verification company that many of the people whose documents it processed had never heard of. Companies (like car-rental counters and cannabis dispensaries) are using its technology to verify identities and ages. Victims did not requiredly opt into IDScan, they didn’t sign up for it and they surely never affirmatively consented to having their documents retained by the company.
Nexus revealed data had been taken repeatedly from a large verification provider over more than a year. According to reports, timestamps linked at least some scans with actual transactions of shops using services from IDScan. Based on what Krebs discovered, it seemed like the database was accepting new records in real time before vanishing after his investigation was published.
Edited on November 18th to add: IDScan later admitted third-party access and/or copying of customer information from its cloud-hosted accounts. Names and government-issued identification numbers were just a few of the data points that may have been compromised. The company is working with federal authorities to investigate, and is providing credit monitoring and identity-protection services. But it has, crucially, not confirmed the criminals’ figure of 153 million licenses by itself.
We can tell the difference—but that cannot be a future justification for inertia on our part. Media credit: John Moore / Getty ImagesThe FBI is investigating one of the largest potential data exposures of government issued identity documents in North America. The logs supposedly contained the driver ́s licenses of US Defense Secretary Pete Hegseth and an FBI assistant director, turning consumer negligence into a bona fide national-security emergency.
These are not disposable passwords. Criminals can defeat essential “know your customer” checks by obtaining images of front-and-back document images, photographs and signatures plus potentially ultraviolet or infrared scans as basic building blocks to manufacture synthetic identities for opening accounts, running up lines of credit or conducting highly persuasive impersonation attacks. Your password can be reset; your face, date of birth and identity history cannot.
In other words, credit monitoring is an absurdly limited fix. It has waited for some results that follow the fact to manufacture the fraud having lost control of what is required.
Congress and Canada should act now to impose log preservation, appoint an independent forensic expert, and publish a credible victim count. Regulators need to lay down data-minimization and deletion deadlines, requiring a documented legal justification (not just commercial necessity) for retaining a reusable identity scan once a verification has been performed.
Congress should require identity-verification vendors to adopt security best practices, create personal liability for reckless concealment by executives, place mandatory notification obligations on affected firms and allow statutory damages for victims-who need not prove actual financial loss. Document replacement for high-risk officials, threat assessment and monitoring of those threats.
Verification contractors with businesses that use them have to specify which vendor gets an ID (if any), retains what, for how long and possibly why else. Contracts cannot outsource accountability.
The breached company may be IDScan. The true failure is of a regulatory system which permitted private intermediaries to create irresistible vaults of permanent identity.
And it was not just that America went digital with identification. It turned vulnerability into an industry and called it verification.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and managing Partner Law Firm Victorious Indonesia
