Brian Krebs, one of the most respected cybersecurity journalists in the world and the founder of KrebsOnSecurity, was alerted on August 31, 2026 to a new identity theft service that had just launched on a Russian cybercrime forum called Exploit. The service, calling itself Nexus, was advertising access to digital scans of identity documents on more than 170 million people across North America.
The reason Krebs’s source flagged it to him specifically: the Nexus operator had used Krebs’s own Virginia driver’s license as a free sample to advertise the service.
What Krebs found when he started digging is one of the most significant data breaches in American history, and it affects an identity verification company that most Americans have never heard of, even though tens of millions of them have handed their driver’s license directly to its scanning machines.
What Is IDScan.net and Why Does It Have Your License?
IDScan.net is a New Orleans-based company that provides identity verification technology to more than 20,000 locations worldwide, processing more than 21 million identity verifications every month. Its clients include some of the largest and most recognizable brands in America, including Hertz rental car, Target, FedEx, Motorola Solutions, and the financial services company Jack Henry. The company also serves more than 1,000 marijuana dispensaries across 19 states, including Planet13, a major multi-state dispensary chain.
When you hand your driver’s license to a rental car agent, a dispensary clerk, or a hotel front desk worker, and they slide it into a small scanner or hold it up to a reader, there is a reasonable chance that machine is running IDScan.net’s VeriScan software. In seconds, the software reads the barcode on the back of your license, captures an image of both the front and back using standard, infrared, and ultraviolet light, and verifies that the document is authentic.
What most people do not know is that IDScan.net appears to have been retaining those scanned images in a cloud-based database long after the verification was complete, without most customers knowing their license image was being stored at all.
On September 4, 2026, IDScan.net posted a brief notice on its website confirming that an unauthorized third party may have accessed and copied certain customer information stored within their accounts on the IDScan.net cloud, including full names and driver’s license or other government-issued identification numbers. The company said it is cooperating with federal law enforcement and offering free credit monitoring to affected individuals.
The Scale of What Was Stolen
The numbers involved in this breach are staggering. According to reporting by Brian Krebs at KrebsOnSecurity, which was first to break this story, the Nexus identity theft service claimed to have more than 153 million driver’s licenses for people in the United States and Canada, more than 10 million identification cards, more than three million travel documents, and at least 579,000 medical cards.
To verify the scale, Krebs asked more than a dozen friends and family members to let him search for their licenses in the Nexus database. Nine of them were found. Every single one confirmed they had interacted with a business using IDScan.net’s technology on or very close to the date stamped on their image file.
The records on sale in Nexus included not just a standard image of each license but six separate image files: a standard scan, an infrared scan, and an ultraviolet scan of both the front and the back of each license. Those infrared and ultraviolet images are the same forensic-quality scans that security experts use to detect fake IDs, meaning that whoever purchased this data had, in the hands of one commenter on Krebs’s story, “the exact proof that a document is real,” which also becomes the exact proof needed to impersonate someone with high confidence.
The Nexus service vanished from the dark web shortly after Krebs published his story, replaced by a message stating the service was no longer available. The FBI’s New Orleans field office opened a formal investigation the same day the story was published.
Significantly, the records in Nexus continued growing even after the breach became public. The number of driver’s license records listed increased by nearly 400,000 in the span of just 24 hours after the service launched, suggesting that data was actively being harvested and uploaded on a rolling basis. The operators claimed they had been continuously exfiltrating new data for over a year into their private database.
Undoubtably, the licenses available on Nexus will soon be available for sale Darkweb forums. A quick search on TOR found numerous sites selling driver licenses, and the licenses available on Nexus will be used to create fake driver licenses and sold.

Did You Know Your License Was Being Stored?
This is the question at the center of the controversy, and the answer for most people is almost certainly no.
When you hand your license to a rental car agent, you expect it to be checked and handed back. You do not expect a detailed forensic scan of it, captured in three different light spectrums, to be retained indefinitely in a cloud database operated by a company you have never heard of, in a file that could potentially be accessed by criminals for years afterward.
IDScan.net’s own website advertises its cloud-based storage of scanned ID data as a feature, useful for record-keeping, compliance, and analytics. But the company’s published privacy disclosures at the time of the breach were not prominently disclosed to the consumers whose licenses were being scanned at car rental counters and dispensary entrances across the country.
Security researcher Zach Edwards, whose own license appeared in the Nexus database with a timestamp corresponding to a visit to a Las Vegas dispensary, told Krebs that systems putting sensitive data into more and more third-party vendors create risks without nearly the oversight needed to ensure those systems are safe. A commenter on Krebs’s story made the same point more bluntly: to verify age by driver’s license, the data could and very much should have been thrown away after processing. Keeping it in a database was an unnecessary risk.
What ISO 27001 Says About This
IDScan.net displays an ISO 27001 certification badge prominently on its website, alongside its SOC 2 compliance badge. ISO 27001 is the internationally recognized standard for information security management, and its presence on a company’s website is meant to signal that independent auditors have verified the company meets a rigorous set of security controls.
So what exactly does ISO 27001 say about encrypting stored data like the driver’s license images that were apparently sitting in IDScan.net’s cloud?
Under ISO 27001:2022 Control 8.24, organizations are required to establish a formal policy governing the use of cryptography, including defining which data must be encrypted based on risk assessment, and applying encryption consistently to data at rest, meaning data stored in databases, servers, cloud storage, and backups. Industry experts note that approximately 95% of lead auditors conducting ISO 27001 reviews expect active cryptographic safeguards on sensitive personally identifiable information. For data at rest, the standard calls for AES-256 bit encryption on all servers, cloud storage volumes, and databases.
The standard does not prescribe specific algorithms by name, but it requires that encryption decisions be risk-based and documented. For a database holding forensic-quality scans of 153 million government-issued identity documents, any reasonable ISO 27001 risk assessment should have concluded that the data warranted the strongest available encryption controls at rest.
What remains unknown is whether IDScan.net’s stored license images were encrypted at rest, and if so, whether those encryption controls were properly implemented and maintained. The company has not disclosed technical details of the breach. Those answers will likely emerge through the FBI investigation, state attorney general actions, and the class action litigation that legal observers say is virtually certain to follow.
What Recourse Do Victims Have
This is a legitimate and understandably urgent question for anyone who rented a car, visited a marijuana dispensary, stayed at a hotel, or conducted business with any other IDScan.net client in the past several years.
Your license image was likely scanned and stored without your explicit knowledge or consent. It may now be in criminal hands. What can you actually do about it?
On the legal side, class action lawsuits are already being discussed by attorneys following the breach. Data breach class actions have become increasingly common following large incidents, and a breach of this scale affecting government-issued identity documents is exactly the kind of case that typically attracts significant plaintiff-side legal interest. Several states, including California under the California Consumer Privacy Act, Illinois under the Biometric Information Privacy Act, and Virginia under the Consumer Data Protection Act, have laws that give residents specific rights regarding how their personal data and biometric information is collected, retained, and protected. Whether and how those laws apply to IDScan.net’s retention of license scans is a question that lawyers are actively examining.
On the regulatory side, state attorneys general in states with strong data protection laws have the authority to investigate companies that retain consumer data without adequate disclosure or security controls. Given the number of states affected and the scale of the breach, multi-state regulatory action is a realistic possibility.
On the practical side, IDScan.net is offering free credit monitoring and identity protection services to affected individuals. The company’s notification page lists a dedicated phone line at 1-833-516-2980, available Monday through Friday between 8 AM and 8 PM Eastern. You can also contact the company in writing at 8814 Veterans Memorial Blvd, Suite 3-124, Metairie, Louisiana 70003.
Freeze Your Credit. Now.
This is the single most important action step following any breach involving government-issued identity documents, and it is especially critical here given the forensic quality of the license images now in criminal circulation.
A credit freeze, also called a security freeze, prevents new credit accounts from being opened in your name. It does not affect your existing accounts or your credit score. It is free. And unlike credit monitoring, which tells you after the fact that someone opened an account in your name, a freeze prevents it from happening in the first place.
To freeze your credit, you must contact all three major credit bureaus separately. Equifax can be reached at 1-888-298-0045 or equifax.com. Experian can be reached at 1-888-397-3742 or experian.com. TransUnion can be reached at 1-800-680-7289 or transunion.com. Each bureau will issue you a PIN or online account that allows you to temporarily lift the freeze if you need to apply for new credit, then refreeze it immediately afterward.
If you have children, consider freezing their credit as well. Children’s credit files are a particularly appealing target for identity thieves because the fraud often goes undetected for years until the child applies for their first credit card or student loan.
More information on placing a credit freeze is available in this previous article
The IDScan.net breach is a watershed moment in the debate over how much data identity verification companies should be allowed to collect and retain from ordinary Americans who have no meaningful choice about whether their licenses are scanned. The next time you hand your license across a counter, it is worth knowing that the transaction may be creating a permanent digital record of one of your most sensitive personal documents, stored by a company you never chose to do business with, protected by security controls you have no way to audit.
Stay safe out there, and I will see you next week!
Feeling lost in the digital world? Dr. Tom is here to help!
References
- Krebs, Brian. “FBI Probes Service Selling 153M+ Drivers Licenses.” KrebsOnSecurity. September 1, 2026. https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
- IDScan.net. “Notification of Data Security Incident.” September 4, 2026. https://idscan.net/notification-data-security-incident/
- TechCrunch. “ID Verification Giant IDScan Confirms Data Breach with More Than 150 Million Driver’s Licenses Stolen.” September 10, 2026. https://techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/
- Yahoo Finance. “US Pentagon Triggers Alarm Over 150M Driver’s License Breach.” September 2026. https://finance.yahoo.com/technology/articles/us-pentagon-triggers-alarm-150m-133500969.html
- Konfirmity. “ISO 27001 Encryption Requirements: Best Practices for 2026.” March 4, 2026. https://www.konfirmity.com/blog/iso-27001-encryption-requirements
- High Table. “What Is ISO 27001 Encryption?” June 3, 2026. https://hightable.io/iso-27001-glossary-of-terms/encryption/
- Advisera. “How to Use Cryptographic Controls According to ISO 27001 A.8.24.” July 14, 2025. https://advisera.com/27001academy/how-to-use-the-cryptography-according-to-iso-27001/
Sign up for our Sunday Spectator. Delivered to your inbox every Sunday, with all the news from the week.

Thomas Hyslip lives in Tega Cay with his wife and daughter. After 27 years in the U.S. Army and Federal Law Enforcement, he retired to pursue his passion for teaching. Tom is now an Assistant Professor of Instruction at the University of South Florida. In 2 short years he has won 10 awards from the South Carolina Press Association, including first place in column writing, education beat reporting and best podcast.


