Two developments outside the protocol layer frame this week's wider security picture: the breach of an identity-verification vendor that sits inside crypto onboarding stacks, and a police warning on a cheap, effective account-takeover chain targeting exchange users.

IDScan.net Confirms Breach Behind the 'Nexus' Identity Trove

IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars and Fortune 500 clients, has confirmed a data breach after a criminal marketplace began advertising identity documents on more than 170 million people in the US and Canada.

The breach surfaced through investigative reporting by security journalist Brian Krebs, who was alerted on August 31 to a new identity-theft service called "Nexus" advertised on the Russian-language Exploit forum — with more than 153 million driver's licenses, over 10 million ID cards, more than 3 million travel documents and at least 579,000 medical cards claimed. The seller offered Krebs a sample of his own driver's license to prove the data's authenticity. The trove includes commercial driver's licenses, Common Access Cards used for government facility entry, and dispensary IDs — a broader span of regulated credentials than a typical retail breach.

IDScan.net said it detected unauthorized access on or around September 1 and engaged third-party forensic specialists. The FBI's New Orleans field office has opened a formal inquiry, and the company says it is cooperating.

The most consequential detail is activity, not scale: the operators claim to have been "continuously exfiltrating new data for over a year," and Krebs observed the advertised license count climb by nearly 400,000 records in a single 24-hour window — evidence the intrusion may still be active rather than a static historical dump.

Why it matters for crypto: identity-verification vendors sit directly inside exchange and platform KYC pipelines. A searchable trove of government ID images — with front, back, infrared and UV scans available for preview — is precisely the material needed to defeat document checks, impersonate users in recovery flows, and fuel synthetic-identity fraud against exchanges and banks alike. For platforms, the incident is an argument for liveness checks and behavioral verification over static document matching; for users, it means the assumption that your license image exists only in one vendor's vault is no longer safe anywhere.

Singapore Police Warn on Crypto Account Takeovers via Compromised Email

The Singapore Police Force said on September 12 that it has observed an increase since mid-August in unauthorized access to cryptocurrency accounts through compromised email accounts.

The attack chain is credential reuse, not malware: investigations found several affected email accounts had appeared in earlier third-party data breaches, and perpetrators appear to have used reused passwords to get into victims' email. From there, attackers search the inbox to identify which crypto platforms the victim uses, create inbox rules to auto-archive or delete exchange emails to avoid detection, then trigger password resets and intercept the reset links, one-time passwords and verification emails.

Police urged unique passwords per service, MFA enabled everywhere — preferably authenticator-app based rather than SMS, which is more susceptible to interception — and regular review of email security settings for unauthorized forwarding rules and login activity. Users with crypto accounts should also enable account activity notifications and review transaction history regularly; anyone who suspects compromise should contact their email provider and exchange immediately to secure or freeze affected accounts.

The advisory is a useful summary of the cheapest attack path in the current environment: no drainer kit, no signed malicious transaction — just breached credentials from one service replayed against another, with inbox rules buying silence.

TrustGrade covers the security and trust ecosystem around digital assets. For verified trust data on the platforms and firms shaping it, see trustgrade.ai.