Krebs's reporting frames the breach as the predictable outcome of a single Louisiana ID-verification vendor accumulating scans from countless downstream customers over years. The scale — 153M+ licenses siphoned from one company — only makes sense if the vendor was storing images long after any legitimate verification need had passed.
Argues this wasn't a sophisticated attack but a data-hygiene failure: the vendor treated identity scans like early-2010s startups treated analytics data — 'keep everything, forever, just in case.' The boring technical story is the whole point, since the real vulnerability was retention policy, not exploit chains.
Points out that whatever the Louisiana vendor's identity, its customer list is 'effectively the list of companies now co-owning this incident.' Outsourcing identity verification doesn't outsource the liability when the vendor's aggregated pile becomes a single point of catastrophic failure.
Submitted the Krebs story to HN, where commenters immediately began triangulating the vendor by recalling which services demanded the ID-plus-selfie ritual — rental car companies like Hertz and marijuana dispensaries emerged as top suspects, illustrating how the downstream customers effectively broadcast their own exposure.
Notes that even the US Defense Secretary and other high-ranking federal officials show up in the catalog — evidence that this verification pattern has become ubiquitous enough to ensnare everyone, including people whose ID scans should never sit in a third-party vendor's S3 bucket. The FBI opening an inquiry only after a cabinet-level official was exposed underscores how invisible this ecosystem has been.
On August 31, a new vendor calling itself Nexus showed up on the Russian cybercrime forum Exploit advertising digital scans of identity documents on more than 170 million people across North America. Brian Krebs, tipped off after the seller used his own Virginia driver's license as a free sample, confirmed the catalog is roughly what it claims: a blank search on Nexus returns about 11.5 million pages at 15 results per page. The pitch: 153 million+ US and Canadian driver's licenses, 10 million+ ID cards, 3 million+ travel documents, and roughly 579,000 medical cards.
The images appear to have been siphoned from a single widely-used identity verification company based in Louisiana, based on interviews with people whose licenses ended up in the catalog. The FBI's New Orleans field office has opened an official inquiry. One of the sample records making the rounds: US Defense Secretary Pete Hegseth's driver's license, alongside scans belonging to several other high-ranking federal officials. Krebs notes the Canadian slice alone is about 1.1 million licenses; the rest is overwhelmingly Americans who at some point did the now-familiar "hold up your ID, then tilt your head at your camera" ritual to unlock an account somewhere.
The vendor hasn't been publicly named yet. But the community on Hacker News is already narrowing it down by use case — commenters flag rental cars ("probably Hertz") and marijuana dispensaries as the categories where their licenses were most likely captured. Whatever the identity of the Louisiana KYC provider, its customer list is effectively the list of companies now co-owning this incident.
The technical story here is boring, and that's the point. This wasn't a novel zero-day or a nation-state APT chain. It was, almost certainly, a vendor that treated identity scans the way early-2010s startups treated user analytics: keep everything, forever, just in case. As one commenter put it bluntly: "surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them."
The economics of KYC-as-a-service actively push vendors toward hoarding. Retained scans make re-verification cheaper, let the vendor sell "fraud intelligence" products on top of the corpus, and — most importantly — turn every enterprise contract into a moat, because the vendor's identity graph gets more valuable every quarter. Deletion is a cost center that competes with the roadmap. Until an incident like this, nobody in the room is arguing hard for it.
The second thing worth naming: the liveness theater doesn't help you here. Commenter trollbridge points out the absurdity of the standard flow — front and back scan of the license, plus a selfie with head tilts. If the vendor's corpus leaks, the front and back scans are gone. The selfie ritual protected the *session*, not the *artifact*. A motivated attacker with a Nexus subscription can now forge a convincing verification against any downstream service that trusts static ID scans as sufficient proof. This is the same lesson the payments industry had to relearn twice: anything you store, someone else eventually reads.
And the third thing, the one that should keep product leads up tonight: your incident-response plan probably assumes *you* had the breach. If your KYC vendor is the one bleeding, you inherit the customer-notification obligations, the state AG letters, and the class action exposure — but you don't control the timeline, the disclosure language, or the forensics. The Louisiana provider hasn't even been named publicly yet, and hundreds of downstream companies are already exposed without knowing it.
If you outsource identity verification, the correct question this week is not "are we affected" — it's "do we even know which of our vendor's other customers we're pooled with in their storage tier?" Get on the phone with your KYC provider and ask three things, in writing: (1) what is the retention policy on the actual image bytes, not the derived fields; (2) is the image bucket segregated per customer, or commingled; (3) what is the deletion SLA when a user churns from your product. If the answers are vague, treat that vagueness as a P1.
Inside your own product, this is the moment to audit what you're actually asking the vendor to store. A lot of "we need ID verification" requirements resolve, on inspection, to "we need a yes/no signal and maybe a hashed identifier." You almost never need the underlying JPEG living on someone else's S3 bucket in perpetuity. Push your vendor toward verify-and-forget flows, or move to providers that support zero-knowledge attestations — where you get a cryptographic proof of "this person is over 21 and their ID passed liveness on 2026-08-14" without the image ever leaving the issuing authority. mDLs (mobile driver's licenses) under ISO 18013-5 are the standards-track version of this, and they're finally shipping in enough US states to be worth designing against.
And if you're building the KYC vendor: the ungreased0675 comment on HN — "bankrupt this company to serve as a warning" — is the sentiment your customers' lawyers are about to internalize. The competitive moat you thought you had (a huge retained image corpus) is a liability that just repriced overnight. Any vendor that can credibly say "we don't keep the images after verification" is going to eat this quarter's RFPs.
Expect two things in the next 90 days. First, at least one state AG — probably in California or New York — will use this as the pretext for a rule that puts a hard retention cap on identity images, measured in hours not years. Second, a wave of RFPs will start demanding verify-and-delete as a baseline, and the vendors that architected around retention will spend a painful year re-platforming. The uncomfortable takeaway is that "we use a reputable third-party for KYC" stopped being a defensible answer somewhere around this week. The vendor is now part of your attack surface, and the only durable fix is to store less — ideally nothing.
The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the da
One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole th
> vendors who collect this sensitive data need to be held to a higher standard.They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).One thing about the US, is that companies
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID.Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this