// 1 CRITICAL · 2 ZERO-DAY · 6 CVE · 5 EXPLOIT · 2 ADVISORY IN THE LAST 24H
A dark web service claims 153 million driver's license scans traced to IDScan.net. The FBI is investigating and at least four class-action lawsuits have been filed.

On September 1, 2026, as IDScan.net began notifying some business customers, the dark web service "Nexus" had already been selling over 153 million scans of U.S. and Canadian driver's licenses for some time. Brian Krebs directly verified the presence of his own license in the database, with timestamps matching a Hertz rental. The FBI's New Orleans field office confirmed it is investigating the incident. At least four class-action lawsuits have been filed in the U.S. District Court for the Eastern District of Louisiana.

Key Takeaways
  • Nexus advertised over 153 million driver's license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, according to KrebsOnSecurity research and BleepingComputer confirmation.
  • Brian Krebs traced the data source to IDScan.net, a New Orleans-based identity verification technology provider, through car rental timestamps and exclusive contracts with cannabis dispensaries.
  • The FBI confirmed to BleepingComputer and TIME it is "looking into the incident," declining further comment due to the ongoing investigation.
  • Nine of thirteen people contacted by Krebs confirmed the dates associated with their licenses matched real trips or rentals, with timestamps apparently in GMT.

The Trail That Pins the Provider

The verification was not theoretical. Krebs searched for his own license in the Nexus database and found it, with a timestamp matching exactly a Hertz vehicle rental. Hertz is listed among IDScan.net's clients, alongside Target, FedEx, Motorola Solutions, Jack Henry, Caesars Entertainment, and Planet13. The latter, a Nevada cannabis dispensary chain, has an exclusive contract with IDScan.net for customer age verification; a sample verified by Krebs originated from that chain.

The files are not simple photographs. They are IR/UV scans—infrared and ultraviolet—of the type documented in IDScan.net's commercial materials. This level of detail makes the documents significantly more dangerous than a textual license number: it exposes document security features, alteration traces, and scan metadata that can facilitate forgery or use in structured identity fraud.

Zach Edwards, a security researcher whose own sample was found in the database, helped strengthen the chain of provenance. His role in this specific incident is limited to verifying his own document; he is not the primary source of the breach report, but an independent checkpoint in Krebs's reconstruction.

Black Market Numbers and Real-Time Growth

Nexus claimed to have been exfiltrating data "for over a year" into a private database, according to the introductory post on the Exploit forum cited by KrebsOnSecurity. At the time of the investigation's publication, the service counted over 153 million driver's licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. BleepingComputer reports the same figure for licenses; Malwarebytes confirms the aggregate categories.

A particularly disturbing data point: in the 24 hours following the news publication, the license count increased by approximately 400,000 records. This surge suggests an active feed or a gradual release by the seller, though the dossier does not establish with certainty whether this represents real-time exfiltration or a merchandising strategy for the stolen data.

IDScan.net, according to its own commercial materials cited by Krebs, processes approximately 21 million identity verifications per month across more than 20,000 locations worldwide. The collection surface is massive: over 1,000 cannabis dispensaries in 19 U.S. states, plus car rental, logistics, and hospitality networks. None of these numbers have been contested by available sources.

"We have been continuously exfiltrating new data for over a year into our private database" — Nexus, post on Exploit forum

FBI Investigation and Class Actions

The FBI's New Orleans field office confirmed to BleepingComputer and TIME that it is investigating the incident. "The agency has also confirmed for BleepingComputer that it is looking into the incident. However, the FBI declined any further comment due to the ongoing nature of the investigation," the specialist outlet reports verbatim. TIME adds that Brian Krebs commented: "This data set will continue to have massive value to the cybercriminal community for many years, and we are likely to see this service or one very similar appear again on the darknet."

In parallel, at least four class-action lawsuits have been filed in the U.S. District Court for the Eastern District of Louisiana. The plaintiffs' firms include Markovits, Stock & DeMarco and Hall Attorneys, according to BleepingComputer and shattered.io. The site shattered.io, which aggregates information with references to ClassAction.org, reports that the legal actions involve consumers who never interacted directly with IDScan.net, but presented their licenses to an entity using its technology.

This is the central legal knot: liability in the personal data supply chain. Consumers did not choose IDScan.net, did not sign a contract with the company, and are often unaware of its existence. Yet their government documents, with timestamps of real activities, resided in a database that at least one criminal group exploited for over twelve months.

Why It Matters

The IDScan.net case exemplifies a systemic, little-visible risk architecture: centralized identity verification vendors operating as hidden critical infrastructure. A consumer renting a car or entering a cannabis dispensary does not perceive they are handing their document to a chain of third parties with centralized storage and potential dark web exposure.

The dossier does not specify the technical intrusion vector into IDScan.net's systems, nor the exact nature of the unauthorized access: backend, data pipeline, or both. IDScan.net has not publicly confirmed the breach; the only documented official response is from Jillian Kossman, who told KrebsOnSecurity: "At this point I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation."

It is unclear whether the timestamps are actually in GMT as hypothesized by Krebs, nor whether the growth of 400,000 records indicated a live feed or a strategic release. The exact number of individuals actually impacted remains undetermined: possible duplicates, expired documents, and test data confound any precise count. The Nexus service is no longer online, but BleepingComputer reports that criminals would still have access to the database.

IR/UV scans, with timestamps and implicit location metadata, constitute a richer and more dangerous identity profile than traditional breaches would expose. The combination of government document, time-verified activity, and advanced scanning technology creates an identity kit that far exceeds simple numerical cloning.

The regulatory escalation—FBI investigation, four federal lawsuits, outside experts like the Identity Theft Resource Center cited by TIME—signals that the identity verification sector may face a redefinition of regulations on data retention and minimization. For now, the dossier documents no specific remedial measures by IDScan.net nor guidelines for end users.

Information has been verified against cited sources and updated as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. krebsonsecurity.com
  3. malwarebytes.com
  4. we-fix-pc.com
  5. hendryadrian.com
  6. time.com
  7. shattered.io