This week produced one of the most consequential identity-document exposures on record, alongside a steady drumbeat of extortion-driven breaches hitting retail, telecom infrastructure, and the justice system on both sides of the U.S.-Canada border. The common thread is not a single vulnerability but a pattern: threat actors are increasingly targeting the vendors and platforms that sit behind everyday consumer interactions — the ID scanner at a rental car counter, the loyalty database behind an online store, the case management software running a courthouse. For individuals, this week's events are a reminder that identity exposure now extends well past passwords into physical identity documents themselves.

153 Million Driver's Licenses: The Nexus Data Leak

The most severe incident of the week involves a marketplace called Nexus, which surfaced on a Russian cybercrime forum on August 31. The service, known as Nexus, surfaced on a Russian cybercrime forum on August 31, offering more than 10 million identification cards, upward of three million travel documents and international IDs, and at least 579,000 medical cards in addition to its headline figure. Nexus claimed in its forum post that it obtained the documents through a live breach at a "major identity verification company," and that it had been "exfiltrating new data for over a year into our private database." Reporting has since tied the exposure to a Louisiana-based identity verification vendor called IDScan.net, a company whose idscan.net — which reportedly processes 21 million+ verifications monthly at 20,000+ locations for clients including Hertz, Target, FedEx, and Caesars Entertainment — underscores how a single vendor breach can ripple across unrelated retail, hospitality, and transportation brands.

What makes this leak different from a typical credential dump is the nature of the data. Each record can include up to six image files showing the front and back of a license in standard, infrared, and ultraviolet scans, with file timestamps corresponding to specific travel dates. Unlike a breached password, you can't rotate a face — front-and-back ID scans are the keys to opening new lines of credit, and AI image-matching makes a leaked photo far more dangerous than a leaked password, according to one researcher who reviewed the data. Only around 1.1 million driver's licenses were from Canada, with the remainder belonging to U.S. residents. The FBI's New Orleans field office has opened a formal investigation, and shortly after the story was published, Nexus disappeared from the dark web with the message "This service is no longer available" — though the removal of the storefront does not mean the underlying data has been deleted or stopped circulating.

ShinyHunters Keeps Hitting Consumer Brands and Infrastructure

The extortion group ShinyHunters remained active against consumer-facing companies this week. Apparel retailer Carhartt's breach, first disclosed in mid-August, was confirmed at scale this week: in August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign, and the group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The breach followed a familiar extortion pattern: ShinyHunters claimed the attack on August 13 and said they allegedly stole more than 50GB of documents containing a wide range of customer, employee, and corporate data, after Carhartt declined to meet a multimillion-dollar ransom demand.

Separately, the group's earlier claimed breach of telecom infrastructure giant American Tower Corporation continues to draw scrutiny, with tracking services confirming ShinyHunters hacking group claims to have breached American Tower Corporation, exfiltrating over 5.2 million records covering customer and landowner data. These incidents fit a broader trend documented by identity-fraud researchers: the Identity Theft Resource Center counted 1,803 reported data compromises from January through June 2026, up from 1,732 in the same months of 2025, with breach notification letters tied to those incidents passing 471 million, already beating the 297.5 million letters logged for all of 2025.

Cross-Border Court Records Exposed in Thomson Reuters Breach

A separate incident affecting the justice systems of both countries surfaced this week. Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada, after discovering unauthorized activity involving certain C-Track information on June 30, 2026. In Canada, a subsequent investigation discovered that an unauthorized party obtained certain C-Track Canada files associated with three Ontario courts - the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice. The data at risk is sensitive: the affected records may have contained individuals' names along with one or more of the following: Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. Notably, some court officials were notified weeks after Thomson Reuters discovered the breach, with the company telling Montana's court administrator and Ontario's Ministry of the Attorney General on July 23 that court data had been accessed — a lag that left affected individuals unaware of the exposure for over a month.

What Individuals Should Do This Week

  • Check whether your driver's license or ID may be part of the Nexus exposure by monitoring for unexpected account openings or credit inquiries — a scanned photo ID cannot be reset like a password.
  • If you have shopped at Carhartt, rented from Hertz, verified age at a cannabis dispensary, or checked in at select hotels, casinos, or big-box retailers recently, treat any unsolicited email or text referencing those transactions with suspicion.
  • Place a credit freeze with all three major bureaus if you have any reason to believe your government ID was exposed — this is the single most effective step against new-account fraud.
  • Watch for notification letters from Thomson Reuters if you have been party to, or named in, court proceedings in Ontario or the affected U.S. states, and enroll in the free credit monitoring being offered.

What Businesses Should Do This Week

  • Audit any vendor relationships involving identity verification, document scanning, or age-verification services — a single upstream vendor breach can expose your customers even when your own systems were never touched.
  • Review negotiation protocols for extortion attempts; ShinyHunters has shown it will publish data in full when ransom talks stall or are handled poorly.
  • Confirm that cloud analytics platforms (such as Databricks or Salesforce instances) tied to customer data have least-privilege access controls and are not exposed through forgotten API tokens or guest permissions.
  • Build a breach-notification runbook now — delays of weeks or months between detection and disclosure, as seen in the Thomson Reuters incident, compound reputational and legal risk.