153 million driver's license scans went up for sale. Krebs traced them to IDScan.net.
A dark web service listed scans of 153 million US and Canadian licenses. Krebs's timestamp analysis points at IDScan.net, and the FBI opened an inquiry.
A dark web service called Nexus spent a week selling scans of 153 million driver’s licenses. The listings carried full images, front and back, plus the infrared and ultraviolet captures that ID readers use to decide whether a card is genuine. Brian Krebs found his own Virginia license there, offered as a free sample.
Almost nobody in that catalog chose to be there. They handed a card to a rental clerk or a dispensary doorman and got it back ten seconds later. Krebs’s timestamp analysis points at IDScan.net, a New Orleans identity-verification vendor whose site says its technology runs more than 21 million checks a month across 20,000-plus locations. The FBI’s New Orleans field office opened an inquiry. Four proposed class actions have since been filed in Louisiana. IDScan.net has confirmed an incident, and its notice describes something narrower than what Nexus was advertising.
What Nexus was selling
Nexus surfaced on a Russian-language cybercrime forum on Monday, August 31, claiming identity documents on more than 170 million people in North America. The headline figure was 153 million driver’s licenses from the US and Canada, alongside more than 10 million ID cards, more than three million travel documents and at least 579,000 medical cards. Krebs sanity-checked the claim by running a blank search, which returned roughly 11.5 million pages of results at about 15 records a page. Canadian licenses came to about 1.1 million, with 473,673 from Ontario alone. The count grew by nearly 400,000 licenses in 24 hours, so whatever was feeding the store was still leaking while it was open.
The record for Krebs’s own license held six image files: three front-and-back pairs, one plain scan and one each under infrared and ultraviolet light, with a date and timestamp stuck onto every filename. That’s an unusual artifact. Ordinary photocopies don’t come with IR and UV layers, and a phone camera can’t produce them.
So Krebs asked more than a dozen friends and relatives for permission to search. Nine of them turned up, and every one confirmed traveling on or near the date in their timestamp. The airport theory died fast, because the data set held no passports at all and several people said they never showed a license at security. What the nine had in common was renting cars. Krebs also found his mother’s license, timestamped seconds from his own, which lines up with the moment the two of them handed their cards to the same Hertz representative.
Zach Edwards, the researcher behind DecryptAds, had a scan dated to the middle of his DEFCON trip to Las Vegas. He told KrebsOnSecurity the only place that put his license into a machine that day was Planet 13, a dispensary chain that signed an exclusive verification agreement with IDScan.net in 2022. IDScan.net’s client page has listed Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment, though Caesars told Krebs it has not been an IDScan.net client and stopped using the company’s VeriScan product in February 2025. Records for senior US officials were in the catalog too, including one for Defense Secretary Pete Hegseth. Nexus went dark within hours of publication.
The chain of evidence has real limits. Timestamp correlation across nine people is strong circumstantial work by one reporter, not a forensic finding, and the company has not accepted the attribution. IDScan.net’s September 4 notice says an unauthorized third party “may have accessed and/or copied certain customer information”, then lists that information as “full names and driver’s license or other government-issued identification numbers”. Names and numbers. The notice doesn’t mention images anywhere. Whether the picture files in the Nexus catalog came out of the same incident is an open question, and the FBI, which told Reuters only that it was “looking into the incident”, hasn’t said.
Where the scan actually goes
Handing a license across a counter feels like showing a card. At a lot of those counters it’s a capture. The card goes into a reader that photographs it under visible light and then again under infrared and ultraviolet, decodes the PDF417 barcode on the back, and compares the result against a template library for that state’s current design. Licenses hide most of their anti-counterfeiting features outside the visible spectrum, which is why the expensive readers exist at all: a scanner that only takes a normal photo can’t separate a good fake from a real card.
IDScan.net’s own marketing spells out the shape of the business. The company advertises an “adaptive AI identity verification platform” with models “trained on hundreds of millions of identity documents”, bank onboarding that confirms identity “in under 12 seconds”, and retail deployments that keep “a full scan history on every transaction”. That last phrase is the retention policy in miniature. A dispensary keeps the log because a regulator may one day ask it to prove it checked, and the log lives in the vendor’s cloud rather than in a filing cabinet behind the counter.
Now trace the consent. The renter’s relationship is with Hertz. Hertz’s relationship is with an identity vendor the renter has never been introduced to, under a contract nobody reads aloud at pickup. Nothing in that transaction says which vendor sits behind the reader, how long the image survives, or whether it’s kept at all. IDScan.net’s notice describes the copied data as stored “within their accounts on the IDScan.net cloud”, meaning the business customer’s account. The person in the photo isn’t the customer here. That gap is what makes this different from a retailer losing card numbers, where at least the shopper knew whose store they were standing in.
Why an image beats a number
A leaked license number is a string of characters, and a credit freeze blunts most of what anyone can do with one. A leaked license image is closer to a working credential. Plenty of services now run identity checks by asking for a photo of the front and back of an ID, sometimes with a selfie on top, and a genuine high-resolution capture with the barcode data intact clears automated document checks that a photocopy fails. The IR and UV frames sharpen the problem, because those are the layers an authenticity engine is looking for. A live selfie step still gets in the way. Not every service has one.
Larry Baldwin, principal intelligence researcher at the security firm Cybera, found his own scan in the set with a timestamp matching a Hertz rental. “Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” he told KrebsOnSecurity. Baldwin also flagged the people for whom this can’t be fixed by changing anything: those fleeing domestic violence, and people relocated under witness protection, whose faces are now searchable against a stolen document set by anyone with image-matching software.
Account recovery is the other soft spot. Password resets have been hardened for years, and WhatsApp only recently traded its six-digit two-step PIN for a real password. Identity documents went the other way and quietly became the thing everything else falls back on. A support agent looking at a clean scan of a state ID is looking at the artifact most recovery scripts treat as final, which is the same weakness the Scattered Spider crew worked for years by talking help desks into resets. The pattern rhymes with session-cookie theft, where the stolen item sits downstream of the login and two-factor never fires.
Readers landed on the same gap. On r/PersonalFinanceCanada, where the story travelled because roughly 1.1 million Canadian licenses were listed, one commenter warned that “some banks allow users to reset their password by uploading an image of their ID”, calling it poor practice kept around for customers who can’t manage an authenticator app. Treat that as community sentiment rather than a documented bank policy. It still describes a real class of recovery flow, and it’s the flow a service with KYC obligations leans on hardest when a customer is locked out.
Edwards tied the incident to the push for online age checks. “This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” he told KrebsOnSecurity. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”
What this means for you
There’s no undo for a scan that already happened, so start with the part you control. Freezing your credit files at Equifax, Experian and TransUnion is free in the US and blocks the most common downstream fraud, and Ontario residents got a free lock option this year. IDScan.net is offering credit monitoring through the number on its notice. After that, the habit worth building is asking before the card leaves your hand: does this get scanned, who holds the image, how long do they keep it. Where a site offers age estimation or a plain yes-or-no age check instead of a full ID upload, take it. And treat any account whose recovery path accepts a photo of your ID as weaker than it was two weeks ago. For tens of millions of people, it is.
Share this article
Quick reference
Sources
- FBI Probes Service Selling 153M+ Drivers Licenses — KrebsOnSecurity
- Notification of Data Security Incident — IDScan.net
- FBI says it is investigating report that millions of US drivers' licenses exposed — Reuters
- FBI Probes Reported Dark Web Driver's License Breach — TIME
- FBI Investigates Dark Web Sale of 153 Million Driver's Licenses — eSecurity Planet
- IDScan Faces Four Lawsuits Over Alleged Data Breach — eSecurity Planet
- IDScan sued over alleged data breach affecting 153 million drivers — BleepingComputer
- Dark web site puts 153 million driver's licenses and millions more IDs up for sale — Malwarebytes
- More than 170M ID scans for sale on dark web in breach allegedly traced to IDScan.net — Biometric Update
- ID Fraud Prevention & ID Verification — IDScan.net
Frequently Asked
- Has IDScan.net confirmed that the license images came from its systems?
- No. Its September 4 notice says an unauthorized third party may have accessed or copied customer information, and lists that information as full names and government-issued ID numbers. The notice does not mention scanned images. The link between the Nexus listings and IDScan.net is Krebs's timestamp analysis, and the FBI's inquiry is open.
- How can I check whether my license was in the data?
- You can't, at least not today. The service went offline within hours of the KrebsOnSecurity story, so there is no lookup and no equivalent of Have I Been Pwned for this set. IDScan.net says it is reviewing records and notifying people it identifies as affected.
- Why do the infrared and ultraviolet frames matter?
- Modern licenses hide most of their anti-counterfeiting features outside the visible spectrum. An automated authenticity check looks for those layers, so a record that already contains them is far closer to a usable credential than a phone photo of a card.
- Does freezing my credit fix this?
- It blocks the most common downstream fraud, which is someone opening a new account in your name. It does nothing about identity checks that accept a photo of an ID, tax-refund fraud, or a stranger locating you by name and address.
- Which businesses use this kind of scanner?
- IDScan.net's site says its technology runs more than 21 million verifications a month at over 20,000 locations, and it has listed Hertz, Target, FedEx, Motorola Solutions and Jack Henry among its brands. It also says it serves more than 1,000 cannabis dispensaries in 19 states.