Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 4, 2026, IDScan.net published a breach notification confirming what Brian Krebs had documented three days earlier: an unauthorized party accessed customer information stored on the company's cloud platform, including driver's licenses and government documents. The notification came after Krebs, founder of KrebsOnSecurity, had already verified with his own and volunteers' samples that the records offered for sale on the dark web service "Nexus" matched real transactions — car rentals, dispensary visits — with timestamps that reconstructed the chain of custody back to IDScan.
The company states it learned of the breach "on or around September 1, 2026," the same day Krebs published his investigation. The Nexus service, meanwhile, vanished from the dark web hours after the scoop.
- IDScan.net confirmed the breach on September 4, 2026; the company reports learning of it on September 1 but has not quantified the records involved
- Nexus advertised over 153 million U.S. and Canadian driver's licenses, plus 10 million ID cards, 3 million travel documents, and 579,000 medical cards
- Brian Krebs directly verified the data's authenticity by searching for his own Virginia license and his mother's, finding matches with timestamps from Hertz rentals conducted in June 2025
- Nexus claimed to have "continued exfiltrating new data for over a year," with an increase of roughly 400,000 records in just 24 hours observed by Krebs
How Timestamps Reconstructed the Chain of Custody
The decisive proof was not strictly technical but forensic. Krebs discovered that every document image in the Nexus database carried a precise timestamp: his Virginia license dated to June 2025, identical to a Hertz rental. His mother's license bore the same timestamp, coinciding with the same rental. IDScan.net is Hertz's provider for document verification; the loop was closed.
Equally determinative was the verification involving Zach Edwards, a security researcher who had visited a Planet13 dispensary in Las Vegas in August 2025. His license in the Nexus database reflected that month. IDScan.net holds the exclusive contract with Planet13 for age verification at entry. Krebs found matches in 9 of 15 volunteers, with transactions traceable to specific dates and locations.
The images were not simple scans: they included multispectral bands — visible, infrared, ultraviolet — as documented in IDScan.net's technical specifications. This level of detail makes the documents particularly valuable for sophisticated identity fraud and the generation of document deepfakes.
"This dataset will continue to have immense value for the criminal community for many years" — Brian Krebs, to TIME
The Continuous Flow: What Nexus Says About Exfiltration
A post attributed to Nexus on the Exploit forum, reported by Krebs, states: "We have been continuously exfiltrating new data for over a year into our private database." The claim finds observational support in the increase of roughly 400,000 license records logged by Krebs over a 24-hour span during his investigation. The service offered previews with partially redacted information, but with customer photos "if available."
The claim of 153 million licenses originates from the marketplace itself, not an independent count. Nexus also stated the database covered approximately 170 million people in North America, with 1.1 million Canadian licenses alone — 473,673 from Ontario. An empty search on the service returned roughly 11.5 million results pages, with an estimated 15 results per page. These figures have not been independently verified by journalistic sources.
IDScan's Response: Late Confirmation and Notice Obfuscation
IDScan.net's official notification, published September 4, contains a cautious formulation: "an unauthorized third party may have accessed and/or copied certain customer information." The company offers free credit monitoring to potentially affected individuals. However, as noted by BleepingComputer and The Record, the notice page was tagged with a noindex directive, rendering it effectively invisible to search engines.
The timing is significant: IDScan states it learned of the breach on September 1, but KrebsOnSecurity had already contacted the company before publication, receiving confirmation from IDScan representative Jillian Kossman that the "updates provided were appreciated and helpful for the team's investigation." The official notification arrived after the journalistic scoop.
The FBI field office in New Orleans has opened an official investigation, as confirmed by TIME with an FBI source and reported by KrebsOnSecurity and BleepingComputer. At least 4-5 class actions had been filed by September 7, 2026, according to Tech-Insider and StartupFortune.
Why It Matters
The dossier does not specify the initial access vector or the technical root cause of the breach. It does not emerge whether IDScan.net stored scanned images in plaintext or encrypted, nor what access controls were in place on the cloud platform. The actual duration of the exfiltration — "over a year" according to Nexus — is not independently verified.
The source does not document specific ongoing regulatory actions by the FTC or state attorneys general. It is unknown whether the data was actually sold or paid for before Nexus disappeared from the dark web. The identity of the service's operators remains unknown.
The brief does not list technical remedial measures adopted by IDScan.net after discovery, nor data minimization retention procedures previously in effect. The exact number of unique individuals affected is undetermined: the 153 million licenses may include duplicates, image variants of the same document, or expired IDs.
What Remains: A Market for Government Documents With No Possible Revocation
The structural problem far exceeds the single incident. A compromised driver's license cannot be "revoked" like a credit card: it remains valid until its natural expiration, and the identifier persists. The multispectral images stored by IDScan.net — which the company processes for 21 million monthly verifications across 20,000 locations — constitute a treasure trove for synthetic fraud.
For downstream companies — Hertz, Target, FedEx, the more than 1,000 marijuana dispensaries in 19 states — the case raises vendor risk assessment questions the brief does not explore: who monitors how a third-party processor stores the "crown jewels" of the identity chain? The timestamp shed light in this case. But without the journalistic investigation, the breach would have remained in the darkness of the supply chain.
Sources
- https://www.helpnetsecurity.com/2026/09/11/idscan-net-data-breach-153-million-drivers-licenses/
- https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/
- https://therecord.media/idscan-data-breach-notice-drivers-licenses
- https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
- https://www.schneier.com/blog/archives/2026/09/drivers-license-data-for-sale.html
- https://time.com/article/2026/09/03/fbi-probes-reported-dark-web-drivers-license-breach/
- https://tech-insider.org/idscan-breach-kyc-vendor-risk-reckoning-2026/
- https://startupfortune.com/idscan-breach-exposes-153-million-drivers-licenses-tied-to-hertz-and-target/
- https://www.helpnetsecurity.com/2025/03/26/how-dark-web-works/
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.