Skip to main content

Morning Overview

A breach at ID-verification vendor IDScan.net may have exposed 153 million ID numbers

A dark-web marketplace called Nexus advertised digital scans of more than 153 million U.S. and Canadian driver’s licenses starting Aug. 31, 2026, and security researchers traced the trove back to IDScan.net, an identity-verification vendor used at rental counters, shipping desks and retail checkouts nationwide. IDScan.net confirmed four days later, on Sept. 4, that unauthorized parties had accessed customer data, though the company has not independently verified the marketplace’s own count. The FBI’s New Orleans field office has since opened an inquiry into the exposure.

The company processes more than 21 million identity verifications a month across more than 20,000 locations, according to reporting that traced the leak to its systems. That volume is why a single vendor breach can touch customers of businesses that never handled the scanned documents themselves.

A Nexus listing claims 153 million licenses, unverified by the company

The Nexus marketplace displayed roughly 11.5 million search-result pages, at about 15 results per page, offering the 153 million driver’s license scans alongside 10 million additional ID cards, 3 million travel documents and 579,000 medical cards. None of those secondary totals has been independently verified by IDScan.net. Security journalist Brian Krebs first connected the marketplace to IDScan.net after being alerted to it on Aug. 31, according to his own reporting at KrebsOnSecurity.

Krebs confirmed the data was genuine by finding his own Virginia driver’s license inside the database, with a timestamp matching a car rental he had made through Hertz. Other researchers who checked the listing reported the same pattern: timestamps lining up with their own rentals and, in some cases, visits to cannabis dispensaries that use IDScan.net’s age-verification kiosks. Hall Attorneys’ review of the marketplace found the Nexus listing itself claimed continuous data exfiltration stretching back more than a year before the August 2026 posting, a period IDScan.net has not confirmed or disputed publicly.

The scans reportedly included the same infrared and ultraviolet security-feature images IDScan.net’s own verification hardware generates when it checks a license for authenticity — the kind of detail that would be difficult for an unrelated party to fabricate convincingly, and part of why researchers treated the listing as credible rather than a hoax.

IDScan.net’s confirmation, without a matching number

IDScan.net’s statement, issued Sept. 4, said “certain data may have been accessed without authorization” around Sept. 1 — language that confirms an intrusion without validating the scale Nexus advertised. The company said the accessed information included full names and driver’s license or other government-issued identification numbers, and it has offered affected individuals free credit monitoring and identity-protection services.

That gap between a confirmed breach and an unconfirmed headline count is not unusual in early breach reporting, but it matters here because the 153 million figure comes entirely from the marketplace listing itself, a source with every incentive to inflate its own inventory. A driver’s license number paired with a full name is enough, in most states, to attempt account takeovers or apply for credit in someone else’s name, which is why the free monitoring IDScan.net offered targets exactly that kind of misuse rather than the breach itself.

Hertz, FedEx and Target sit in IDScan.net’s client list

Legal-tracking documents reviewed by Tech Insider describe IDScan.net’s customer base as including rental giant Hertz, logistics company FedEx and retailer Target, among others. Hall Attorneys, a law firm gathering information from potentially affected individuals, says its own review of the Nexus records turned up Hertz rental timestamps that matched what several people interviewed by Krebs had reported, along with data tied to Planet 13, a dispensary chain that uses IDScan.net’s VeriScan technology across more than 1,000 locations nationwide.

Hall Attorneys’ page is explicit that it has not yet filed a lawsuit; it describes itself as running an investigation, not litigation, while it collects accounts from people whose documents may be in the exposed set.

An FBI inquiry moves faster than a public number

The FBI’s New Orleans field office opened its inquiry shortly after Krebs published his findings, and Help Net Security reported the bureau is now working alongside IDScan.net’s own third-party investigators. By the time Cybernews and other outlets picked up the story in the following days, at least nine putative class-action complaints had already been filed in the U.S. District Court for the Eastern District of Louisiana.

Nexus itself went offline within days of the first reporting, a pattern common to dark-web marketplaces caught in a law-enforcement spotlight. Whether that shutdown reflects seized infrastructure or a seller simply pulling the listing before it could be scrutinized further is a question neither the FBI nor IDScan.net has answered publicly.

For Hertz, FedEx and Target customers, the practical exposure depends on details none of the public reporting has settled: how many of their own transactions ran through IDScan.net’s systems during the window Nexus claims to cover, and whether the 153 million figure describes distinct people or overlapping scans of the same drivers across repeat rentals and shipments. IDScan.net has not published its own count, and until it does, the marketplace’s number remains the only one on record.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview