zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Threat Actor Claims Access to Identity Data

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Threat Actor Claims Access to Identity Data

Product Serial: F-2026-09-03a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on a threat actor claiming access to hundreds of millions of American and Canadian identity documents, which were being made available via a portal called NEXUS.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On August 31, 2026, untested threat actor "databroker1" advertised a custom portal named "NEXUS" on the dark web forum Exploit, claiming the portal hosts a database of over 160 million breached identity documents.
  • The actor claims to have maintained persistent access to an unnamed major identity verification provider and its enterprise clients (including several Fortune 500 companies) and conducted ongoing exfiltration for over a year, with approximately 500,000 new documents added daily.
  • ZeroFox assesses that IDScan[.]net is very likely the vendor targeted by the threat actor; the company offers an identity verification platform in both digital and physical spaces. While IDScan[.]net has not made a public statement, several social media posts by customers claim that the company sent out an email about investigating a “potential security incident.”
  • Although the NEXUS portal is no longer active, there is a roughly even chance the threat actor will reactivate access after a cooling-off period to let the public scrutiny die down. Additionally, the threat actor’s claim of persistence—as well as the extensive coverage of IDScan[.]net data potentially available—very likely makes this breach an ongoing threat to personal identity data.

Tags: dark web data breach threat actor