ZeroFox Intelligence Flash Report - Threat Actor Claims Access to Identity Data
|by Alpha Team

ZeroFox Intelligence Flash Report - Threat Actor Claims Access to Identity Data
Product Serial: F-2026-09-03a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on a threat actor claiming access to hundreds of millions of American and Canadian identity documents, which were being made available via a portal called NEXUS.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On August 31, 2026, untested threat actor "databroker1" advertised a custom portal named "NEXUS" on the dark web forum Exploit, claiming the portal hosts a database of over 160 million breached identity documents.
- The actor claims to have maintained persistent access to an unnamed major identity verification provider and its enterprise clients (including several Fortune 500 companies) and conducted ongoing exfiltration for over a year, with approximately 500,000 new documents added daily.
- ZeroFox assesses that IDScan[.]net is very likely the vendor targeted by the threat actor; the company offers an identity verification platform in both digital and physical spaces. While IDScan[.]net has not made a public statement, several social media posts by customers claim that the company sent out an email about investigating a “potential security incident.”
- Although the NEXUS portal is no longer active, there is a roughly even chance the threat actor will reactivate access after a cooling-off period to let the public scrutiny die down. Additionally, the threat actor’s claim of persistence—as well as the extensive coverage of IDScan[.]net data potentially available—very likely makes this breach an ongoing threat to personal identity data.
Tags: dark web, data breach, threat actor