HomeData Breaches153 Million Driver's Licenses Offered for Sale After Suspected Breach at ID...

153 Million Driver’s Licenses Offered for Sale After Suspected Breach at ID Verification Firm IDScan.net

A dark web identity theft marketplace is selling scans of more than 153 million driver’s licenses from the United States and Canada, according to security journalist Brian Krebs, who traced the data back to IDScan.net, a Louisiana-based company that verifies identity documents for businesses across North America.

IDScan.net processes more than 21 million identity checks a month at over 20,000 locations worldwide. Its scanners read infrared and ultraviolet markings on driver’s licenses, passports and other government-issued IDs to confirm they are genuine, a service used at car rental counters, retail checkouts, casinos and cannabis dispensaries. Krebs reported that the company’s client list includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry and, previously, Caesars Entertainment.

The stolen records surfaced on a marketplace called Nexus, which appeared on the Russian-language cybercrime forum Exploit on August 31. Sellers advertised more than 153 million U.S. and Canadian driver’s licenses, over 10 million other ID cards, 3 million travel documents and 579,000 medical cards, along with cannabis dispensary membership cards. Each entry reportedly includes front and back photos of the document along with the infrared and ultraviolet scan versions IDScan’s hardware captures, complete with timestamps. Krebs noted that the number of driver’s license records for sale grew by roughly 400,000 within a single day of his report going live, suggesting the listing was still being updated.

Krebs said he confirmed the leak was real by searching for his own driver’s license on Nexus and finding six separate image files timestamped to a trip he took in June 2025, matching a Hertz rental from that period. He also found a scan of his mother’s license logged seconds apart from his own, consistent with a joint checkout at the rental counter. He asked more than a dozen colleagues and contacts to search for themselves, and nine reported finding accurate matches tied to specific travel or rental dates. Security researcher Zach Edwards told Krebs he found his own license in the database with a timestamp matching a visit to a Planet13 cannabis dispensary in Las Vegas, a chain that has used IDScan technology since 2022. “These systems are putting sensitive data into more and more third party vendors, and we don’t have nearly the oversight to ensure they are safe,” Edwards said.

Fraud investigator Larry Baldwin of Cybera offered a similar warning. “Just when it seems like we’re making some headway in improving authentication controls through driver’s license verification systems, this happens, and the very thing those improvements are dependent on are compromised,” he said.

IDScan.net has not confirmed a breach. A representative named Jillian Kossman told Krebs only that “at this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” The company did not respond to a separate request for comment from BleepingComputer. No CVE or technical root cause has been disclosed publicly as of this writing, so it remains unclear exactly how the data was obtained.

The FBI’s New Orleans field office opened a formal investigation on September 1. Krebs said he joined a call with roughly six FBI agents, including senior members of the bureau’s cyber division, who confirmed the probe was underway. The Nexus website went offline on September 2, replaced with a message reading “This service is no longer available,” though it is not clear whether that was a law enforcement action or a decision by its operators.

Caesars Entertainment, which appeared in earlier reporting as an IDScan client, issued its own statement on September 2 clarifying that it discontinued use of IDScan’s VeriScan product in February 2025 and had no active accounts with the company during the period the breach is believed to have occurred.

The scale of the exposure has already drawn legal action. Law firms including Markovits, Stock & DeMarco and Hall Attorneys have filed class action lawsuits against IDScan in Louisiana, where the company is based, arguing it failed to adequately protect data belonging to customers of its business clients, Hertz among them. Several firms have also opened investigations soliciting affected individuals.

Because the leaked files include high-resolution scans rather than just names or numbers, the practical risk for anyone caught up in the breach is elevated. A clear photo of a driver’s license, front and back, is enough on its own to pass many identity checks used to open accounts, apply for credit or verify age. Anyone who has rented a car, visited a dispensary that scans IDs, or had their license checked at a retailer in the past few years may want to watch their credit reports and consider a credit freeze as this investigation continues.

Source: Brian Krebs, “FBI Probes Service Selling 153M+ Driver’s Licenses,” KrebsOnSecurity, September 2026, with additional reporting from BleepingComputer.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular