The exposed information includes infrared and ultraviolet scans of IDs belonging to the general public and high-ranking government officials, such as U.S.
Defense Secretary Pete Hegseth.
The incident is significant because it highlights the vulnerability of the identity verification infrastructure used by Fortune 500 companies and government agencies.
Security researchers traced the source of the leaked images to idscan.net, a Louisiana-based provider that facilitates ID checks for car rentals, marijuana dispensaries, and retail stores.
Because these high-resolution scans are frequently used as the "gold standard" for opening credit lines or verifying identity for secure services, their availability to cybercriminals could lead to widespread, sophisticated identity theft.
The breach specifically impacts individuals who recently used services that require ID scanning, such as renting cars through Hertz or visiting specific dispensaries.
While the Nexus website went offline shortly after the investigation became public, the leaked data includes timestamps that match specific travel and transaction dates for those affected.
Security experts warn that this compromise undermines the very authentication controls designed to prevent fraud, potentially exposing sensitive groups like protected witnesses or victims of domestic violence.