If you have rented a car, bought cannabis, or walked into a club in the last few years, there is a decent chance a small device photographed your driver’s license on the way in. Some of those photos are now in criminals’ hands. In early September, the identity verification company IDScan.net confirmed that an unauthorized third party may have accessed and copied customer information stored on its cloud platform, The Record reported, after a dark-web service began offering searchable scans of more than 153 million driver’s licenses.
The scale is alarming. The more important detail is what was being stored in the first place.
What leaked, and from whom
Security journalist Brian Krebs traced the service, called Nexus, back to IDScan’s infrastructure. According to his reporting, the cache included more than 153 million U.S. and Canadian driver’s licenses, more than 10 million other ID cards, more than 3 million travel documents, and over 579,000 medical cards. The scans carried timestamps that matched when victims had visited rental counters and dispensaries, and they included infrared and ultraviolet images of the kind IDScan’s readers capture. The FBI opened an investigation, and Nexus went offline within days of launching.
The operators claimed they had been quietly pulling new records for more than a year. That claim has not been independently confirmed, but Krebs reported that the cache grew by roughly 400,000 licenses within a single day after the service went live.
IDScan’s customers, according to Krebs, include Hertz, Target, FedEx and Caesars Entertainment, along with more than 1,000 cannabis dispensaries. In Canada, the federal privacy commissioner has opened an investigation into the company’s security and how it notified people.
Security researcher Rachel Tobac warned about what comes next:
This type of breach, affecting 153 million individual's licenses, is going to have massive impacts on identity theft, specifically identity verification platform fraud (using front and back scans from this breach to "verify" as another person for financial services and more). https://t.co/1Jc3iJKcQ5 pic.twitter.com/yEQsRkOcRb
— Rachel Tobac (@RachelTobac) September 2, 2026
The real problem is the photo
Think about what an age check actually needs to know. A bouncer or a dispensary clerk needs one answer: is this person old enough, and is this ID real? That is a yes or a no. Krebs found that IDScan instead kept complete images of each license, front and back, with the infrared and ultraviolet versions and a timestamp of the scan. That is not a record of an age check. It is a copy of the ID.
That choice is what turned a breach into a disaster. A leaked list of names and birth dates is bad. A leaked set of high-resolution, front-and-back license images is a toolkit for fraud. As Tobac notes, criminals can use front and back scans to verify themselves as someone else with financial services. The same scans that proved you were 21 at a nightclub can now be used to pass as you somewhere else.
There is a broader lesson here as more of daily life requires showing ID, from age checks on websites to purchases of age-restricted products. Every system built to check an ID faces the same choice IDScan made: verify and discard, or verify and keep. Keeping is useful to the company, for audits and disputes. But a database of ID scans is valuable to criminals in proportion to how complete it is. Collect enough of them and you have built something worth stealing.
The case for keeping records
To be fair to the businesses involved, there are real reasons to retain proof of an ID check. A bar accused of serving a minor, or a dispensary audited by state regulators, may need to show that it checked a customer’s ID. A car rental company has legitimate reasons to know who drove off in its vehicle.
But proving an ID was checked does not require a full color copy of it. A record that a specific license number passed verification at a specific time would satisfy most of those needs, at a fraction of the risk. The gap between what businesses needed and what IDScan stored is the gap the breach fell through.
What you can do, and what should change
IDScan has offered free credit monitoring and identity protection to affected people. If you think your license may be in the cache, watch for accounts opened in your name and consider a credit freeze, which is free and makes it harder for anyone to open new credit in your name. You can’t easily change your license number the way you can change a password, which is exactly why this kind of data should be collected sparingly.
The more lasting fix is for the businesses that scan IDs to ask their vendors a simple question: what do you keep, and for how long? If the answer is a picture of every license, forever, that is a breach waiting for a date.
Related reading: A Gang Hacked the FBI Over a Four-Month-Old Warning. · Passkeys Won. The Password Still Isn’t Dead.
