IDScan.net Breach: 153 Million Driver's Licence Scans and the Default Setting That Kept Them
By pico picu · 12 Sept 2026 · 16 min read
Threat Actor: Unknown — operator of the "Nexus" identity-theft service on the Exploit forum; unattributed · Target: IDScan.net (New Orleans) and the customers of its VeriScan Cloud platform — car rental, retail, hospitality and cannabis dispensary locations across the US and Canada; ~153 million individuals
Source: idscan.net
Executive Summary
On 31 August 2026 a new account on the Russian-language Exploit forum advertised a service called Nexus: a searchable database of scanned identity documents covering, by its own count, more than 153 million driver's licences from the United States and Canada, 10 million identification cards, 3 million travel documents and 579,000 medical cards, with new records arriving continuously. Brian Krebs, whose own Virginia licence was offered as the free sample, spent a day tracing the source through the timestamps attached to the images. Nine of the people he asked confirmed the timestamps matched a day they had handed a licence to a Hertz rental counter or a Planet13 cannabis dispensary, both customers of IDScan.net, a New Orleans identity-verification vendor whose scanners capture documents under visible, infrared and ultraviolet light. The FBI's New Orleans field office opened an investigation on 1 September. Nexus went offline the same evening. IDScan.net posted a notice on 4 September confirming that "an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud."
The question the coverage has not answered is why a vendor that verifies an ID at a counter was holding the scan a year later. IDScan.net's own support documentation answers it. VeriScan Cloud's data-collection setting defaults to "Collect all," which includes "high-resolution scans of the front and back of the ID" and webcam photographs, and its retention setting defaults to "Do not delete, retain records in secure cloud." Customers on the Basic plan cannot change either. That page has read the same way in every archived copy since at least January 2025 and was unchanged on 2 September 2026, after the breach. Caesars Entertainment, listed on IDScan.net's website as a client, told Krebs it had not used the product since February 2025 and "did not authorize IDScan.net to retain data from its accounts," which is the default seen from the customer's side.
What IDScan.net has confirmed is narrower than what was for sale. Its notice names "full names and driver's license or other government-issued identification numbers." It does not mention images. Nexus's records carried six image files per licence: front and back under visible, infrared and ultraviolet light, each with a GMT timestamp of the scan. The notice also does not give a number, an intrusion date, or a mechanism; it says the company "received information" on or around 1 September, which is the day Krebs called. The claim that the data was exfiltrated "for over a year" is Nexus's, and Krebs's June 2025 timestamp is consistent with it, but IDScan.net has not said when access began.
Fourteen class actions were filed in the Eastern District of Louisiana between 2 and 10 September, all resting on Krebs's reporting, and one against Hertz in the Western District of Texas. No state attorney general has announced an inquiry and no regulator has spoken. The loss is unusual in kind as well as size: a licence number can be reissued, but a high-resolution multi-spectrum scan of a physical document, plus the holder's photograph, is the exact artefact that document-authentication systems are built to trust.
Verification of Claims
-
Claim: More than 153 million driver's licences were exposed. → Partially verified → The figure is Nexus's own count. Krebs tested it: a blank search returned about 11.5 million pages of roughly 15 results each, which is consistent with the claim, and the licence count rose by nearly 400,000 in 24 hours. IDScan.net has not confirmed or disputed any number.
-
Claim: IDScan.net was the source. → Verified → Krebs's timestamp method linked nine records to Hertz counters and one to a Planet13 dispensary, both IDScan.net clients, and the six-image format matches IDScan.net's visible/infrared/ultraviolet capture. IDScan.net's 4 September notice confirms unauthorised access to customer data on its cloud. Reuters had earlier reported it could not independently confirm the source.
-
Claim: IDScan.net confirmed the theft of 153 million licence scans. → False as phrased → The notice confirms that "certain customer information" including names and ID numbers "may have" been accessed. It gives no count and does not mention images. Headlines that say IDScan.net "confirmed 153 million" combine Nexus's number with IDScan.net's admission.
-
Claim: The data was being exfiltrated continuously for over a year. → Unverified → Nexus's claim on Exploit. Supporting evidence: Krebs's own scan is stamped June 2025; the record count grew during the day of reporting. IDScan.net has stated no intrusion date.
-
Claim: VeriScan Cloud retains all scans indefinitely by default. → Verified → IDScan.net support documentation, "How can I control what visitor data is collected and retained?": "By default, new accounts are set to 'Collect all'" and "The default setting for new customers is to retain all records in our secure cloud." Basic plan: "cannot be changed." Confirmed in Internet Archive snapshots of 20 January 2025, 9 March 2026 and 2 September 2026.
-
Claim: Hertz, Target, FedEx and Caesars customers' data was stolen. → Partially verified → Those companies are listed on IDScan.net's trust page. Hertz is supported by Krebs's timestamp evidence. Caesars disputes being a client at all since February 2025. Target and FedEx have not commented, and no record has been publicly tied to either.
-
Claim: The Nexus records included Common Access Cards. → Weak evidence → Some records carry a source tag "CAC," which Krebs notes "may refer to" Common Access Cards. No CAC image has been published and no agency has commented.
-
Claim: The FBI is investigating. → Verified → Krebs was told directly by FBI cyber division leadership on 1 September that the New Orleans field office had opened an investigation that day; IDScan.net's notice states it is "cooperating with federal law enforcement."
-
Claim: 170 million identity documents were exposed. → Verified as a different count → Nexus's introductory post claimed documents on "more than 170 million people in North America." The 153 million figure is driver's licences alone; adding the 10 million ID cards, 3 million travel documents and 579,000 medical cards gives roughly 167 million records. The two figures describe the same inventory at different granularity.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 2022 | IDScan.net; Planet13 | Press release announcing an exclusive identity-verification agreement covering Planet13 dispensaries nationally. | Krebs |
| 20 January 2025 | IDScan.net | Support documentation already states the "Collect all" and "Do not delete" defaults, locked on the Basic plan. | Internet Archive |
| February 2025 | Caesars Entertainment | Stops using VeriScan; later says it never authorised IDScan.net to retain its data. | Krebs, update 2 Sept |
| June 2025 | Hertz counter | Krebs and his mother hand licences to a Hertz representative; the Nexus timestamps on both records are seconds apart. | Krebs |
| ~August 2025 (claimed) | Nexus operator | Start of continuous exfiltration, "for over a year" per the seller. | Nexus post via Krebs |
| August 2026 | Planet13, Las Vegas | Zach Edwards's licence scanned at a dispensary during DEF CON; timestamp matches. | Krebs |
| 16 August 2026 | IDScan.net | Homepage states its models are "trained on hundreds of millions of identity documents." | Internet Archive |
| 31 August 2026 | Nexus operator | Service advertised on Exploit with Krebs's licence as a free sample. | Krebs |
| 1 September 2026 | Krebs; FBI; IDScan.net | Krebs contacts IDScan.net; FBI New Orleans opens an investigation; article published 18:40 ET; Nexus goes offline by 20:56 ET. | Krebs |
| 2 September 2026 | Plaintiffs; Caesars | Four class actions filed in E.D. La. (Bunch, Greenbaum, Sealy, Rioux). Caesars says it is not a client. | CourtListener; Krebs |
| 3–4 September 2026 | Plaintiffs; IDScan.net | Five more suits. IDScan.net posts its Notification of Data Security Incident, dated 4 September. | CourtListener; IDScan.net |
| 7 September 2026 | Plaintiff | Hasenzahl v. The Hertz Corporation, W.D. Tex. 5:26-cv-05735. | CourtListener |
| 8–10 September 2026 | Plaintiffs | Four further suits in E.D. La.; fourteen against IDScan.net in total. | CourtListener |
Incident Anatomy
There is no intrusion chain to reconstruct, because IDScan.net has not described one. What can be reconstructed is how 153 million document scans came to be in one place, which is the part that determined the size of the loss.
How a scan becomes a record
Loading diagram...
IDScan.net's VeriScan product runs on desktop scanners and mobile devices at the point of contact: a rental counter, a dispensary door, a hotel desk. The scanner images the document under visible, infrared and ultraviolet light, which is how the software checks security features. The result is parsed into fields and uploaded to the customer's account on VeriScan Cloud, administered at veriscancloud.com. Two settings govern what happens next.
Data Collection. Four options: do not collect, anonymised only, collect all, custom. "Images refers to cropped ID photo and live photos taken by webcam at time of scan. Attachments refers to high-resolution scans of the front and back of the ID." The default is "Collect all." On the Basic plan it "cannot be changed."
Data Retention. Three options: do not delete; retain anonymised or custom data after a set period; delete all after a set period, from 8 hours to 1 year. The default is "Do not delete, retain records in secure cloud." On the Basic plan it "cannot be changed."
The effect is that every scan at every default-configured location, at more than 20,000 locations processing more than 21 million verifications a month by IDScan.net's own figures, was retained as a full multi-spectrum image set indefinitely, unless the customer's administrator went into Settings > Local Settings > Data and changed both. IDScan.net's homepage describes its models as "trained on hundreds of millions of identity documents." That sentence and the 153 million figure describe the same corpus.
What Nexus held
Each record Krebs examined carried up to six files: front and back under visible light, infrared and ultraviolet, with a GMT timestamp on each filename that matched the moment of the scan. Records were tagged with a source field, including "CDL" and "CAC." The search interface returned results with sensitive fields redacted and photographs displayed; full records were paid. The seller said records were "available to preview before purchase," and the inventory grew by nearly 400,000 licences during the 24 hours Krebs watched it, which implies the seller still had access at the time of publication.
What IDScan.net has said
The notice of 4 September says unauthorised access to "customer information stored within their accounts on the IDScan.net cloud." "Customer" in IDScan.net's vocabulary is the business account, not the individual scanned. The phrasing points at account-level access to VeriScan Cloud rather than at a database or storage compromise beneath it, but the company has not said whether credentials, an API, a vulnerability or an insider was involved, when access began, or how many accounts were affected. The sentence "Though full access to the information required payment" is offered as mitigation; it describes Nexus's pricing, not the exposure.
The Caesars detail
Caesars told Krebs it stopped using VeriScan in February 2025, had no active accounts at the time of the incident, and "did not authorize IDScan.net to retain data from its accounts." IDScan.net's site still listed Caesars as a client. Whether Caesars data was in Nexus is not established; what the statement shows is a former customer discovering that "do not delete" survived the end of the contract.
Threat Actor Profile
- Name / Alias: Operator of "Nexus," a new account on the Exploit forum. No prior handle or reputation reported.
- Attribution: None. The FBI has not named a suspect. No group has claimed the breach; the seller described the source only as "a major identity verification company" with Fortune 500 clients.
- Motivation: Sale of identity documents. Pricing was per-record with paid full access.
- Tradecraft observed: Continuous exfiltration rather than a one-time dump; a searchable web front end with redaction and preview; withdrawal from the market within two hours of public reporting.
- Opsec: Offering the reporter's own licence as the free sample brought the FBI in on day one.
- MITRE ATT&CK techniques (verified on attack.mitre.org, 12 September 2026; limited, because the intrusion is undescribed):
- T1078 Valid Accounts (assessed from "accounts on the IDScan.net cloud"; unconfirmed)
- T1530 Data from Cloud Storage
- T1119 Automated Collection
- T1657 Financial Theft
Technical Indicators
# IDScan.net has published no indicators. The following are descriptive.
marketplace:
name: Nexus
advertised_on: Exploit forum, 2026-08-31
status: offline since 2026-09-01 ~20:56 ET ("This service is no longer available")
record_format:
images_per_licence: up to 6 # front/back x visible, infrared, ultraviolet
filename_timestamp: GMT, matches moment of scan
source_tags_seen: [CDL, CAC]
claimed_inventory_2026-08-31:
drivers_licences: ">153,000,000 (US + Canada)"
id_cards: ">10,000,000"
travel_documents: ">3,000,000"
medical_cards: "579,000"
canadian_licences: "~1,100,000 (Ontario ~473,673)"
platform:
product: VeriScan Cloud (veriscancloud[.]com)
defaults: "Collect all"; "Do not delete, retain records in secure cloud"
basic_plan: both defaults locked
ip_addresses: []
domains: []
file_hashes: []Legal and Regulatory Response
Federal. The FBI New Orleans field office opened an investigation on 1 September 2026. No charges. No FTC statement, though the complaints plead FTC Act duties.
State. No attorney general has announced an inquiry as of 12 September. State breach-notification statutes will require individual notices; IDScan.net's notice is a substitute notice with a call centre (1-833-516-2980) and credit monitoring, and says the company is "notifying potentially impacted individuals." With no confirmed count, the scope of that notification is unknown.
Canada. About 1.1 million Canadian licences were in the inventory, with the largest share from Ontario. No statement from the Office of the Privacy Commissioner or the Ontario IPC has been reported.
Litigation. Fourteen putative class actions against IDScan.net, Inc. in the Eastern District of Louisiana between 2 and 10 September 2026: Bunch (2:26-cv-01929), Greenbaum (01930), Sealy (01931), Rioux (01932), Layman (01937), Wagner (01946), Katz (01949), Buckles (01954), Sullivan (01956), Laporte (01974), Fisher (01978), Carter (01983), Rodriguez (02025) and one further. The complaints rest on Krebs's article and plead negligence, breach of implied contract and unjust enrichment; Sealy estimates the class in "hundreds of thousands" against "the reportedly 153 million" records, which understates its own case. Hasenzahl v. The Hertz Corporation (W.D. Tex. 5:26-cv-05735, 7 September) is the first suit against a customer rather than the vendor. Consolidation in E.D. La. is the likely next step.
Vendor. IDScan.net has engaged "third-party specialists," reviewed "policies and procedures related to data security," and says the investigation is ongoing. Its retention documentation and homepage claims were unchanged as of the most recent archive snapshots.
Impact Assessment
- Source confirmed — Confirmed. IDScan.net notice, 4 September.
- Individuals affected — Reported. ~153 million licences plus ~14 million other documents (Nexus); IDScan.net gives no figure.
- Data types — Confirmed (partial). Names and ID numbers (IDScan.net). Reported: full multi-spectrum scans, photographs, dispensary and medical cards (Nexus, Krebs).
- Duration of access — Reported. "Over a year" (Nexus); June 2025 scan present (Krebs). Not stated by IDScan.net.
- Access still live at disclosure — Reported. Inventory grew ~400,000 in 24 hours before the story ran.
- Mechanism — Unknown.
- Affected customers — Reported. Hertz (timestamp evidence), Planet13 (timestamp evidence); Target, FedEx, Motorola Solutions, Jack Henry listed as clients, none confirmed. Caesars disputes.
- Government-issued cards — Reported. "CAC" source tags; a Cabinet member's and an FBI assistant director's licences found by Krebs.
- Availability of the stolen data — Unknown. Nexus withdrew; no evidence the data was destroyed.
- Cost to IDScan.net — Unknown. Fourteen suits; cyber insurer notified per Sealy.
Lessons and Defensive Recommendations
For any business that scans IDs
- Find the retention setting. On VeriScan Cloud it is Settings > Local Settings > Data, and the default keeps every image forever. If your plan does not let you change it, that is a reason to change plan or vendor, not to accept the default.
- Verification needs the document for seconds. Retaining the scan is a separate decision with a separate risk; make it deliberately, in writing, with a purpose and a period.
- Ask your vendor what was retained for your account and for how long. Caesars found out after the fact that "do not delete" outlived the contract.
For identity-verification vendors
- "Collect all" and "do not delete" as the default, locked on the entry tier, is a design choice that converts every customer's throughput into your breach surface. The 153 million number is the direct output of that choice.
- A notice that names ID numbers but not images, when images are what was sold, will be read as an omission. Say what was in the accounts.
For security teams
- Multi-spectrum scans defeat the liveness and authenticity checks that ID-verification products themselves perform. Treat any account-opening flow that accepts a licence image as compromised for this population, and weight secondary signals accordingly.
- Timestamps tied to physical presence let an attacker reconstruct travel. For protected populations, that is the more dangerous field.
For individuals
- A freeze at all three bureaus is the only control that survives a stolen licence image. The number can be reissued at a DMV; the scan cannot.
Sources
- IDScan.net. "Notification of Data Security Incident". 4 September 2026.
- Brian Krebs, KrebsOnSecurity. "FBI Probes Service Selling 153M+ Drivers Licenses". 1 September 2026, updated 2 and 8 September.
- IDScan.net Support. "How can I control what visitor data is collected and retained?". Archived 20 January 2025, 9 March 2026, 2 September 2026.
- IDScan.net homepage, archived 16 August 2026 and 11 September 2026.
- CourtListener. Sealy v. IDscan.net, Inc., E.D. La. 2:26-cv-01931, complaint. 2 September 2026.
- CourtListener. Hasenzahl v. The Hertz Corporation, W.D. Tex. 5:26-cv-05735. 7 September 2026.
- Help Net Security. "IDScan confirms breach after 153 million driver's licenses leak on dark web". 11 September 2026.
- Biometric Update. "IDScan confirms breach after 170M identity documents put up for sale". September 2026.
- TIME. "FBI Probes Report of Breach Exposing 153 Million Driver's License Scans". 3 September 2026.
- eSecurity Planet. "IDScan Faces Four Lawsuits Over Alleged Data Breach". September 2026.
- MITRE ATT&CK. T1530; T1119; T1078. Accessed 12 September 2026.
Related Research
An intruder spent four months inside a Thomson Reuters cloud environment holding case-management data for appellate courts in 13 US states, the Virgin Islands and Ontario. The exposed files included sealed records, and several courts say they didn't know the copies existed.
For 17 days in August 2026 an attacker registered Lenovo IDs on other people's email addresses and signed straight into their Dropbox accounts. Lenovo's verification was the flaw; Dropbox's willingness to trust it without a password was the breach.
A Russian web developer extradited from Georgia faces trial over a 2023–25 operation that bought search ads impersonating banks, harvested 5,000+ logins and 2FA codes on cloned pages, and tried to wire $5.58 million from one Atlanta company in a day. The mule LLC was registered in Georgia two months