Back to Blog
data breachesdriver's licenseidentity theftthird party riskdocument security

153 Million Driver's License Scans, Handed Over In Person, At a Counter

Nobody in this breach got phished. They rented a car, bought legal cannabis, checked into a hotel, and handed a license to a person behind a desk. A vendor they had never heard of kept six infrared and ultraviolet images of it for over a year.

By RedactID Team7 min read
Conceptual vector illustration of a driver's license fragmenting into six stacked scan layers under infrared and ultraviolet light bands, in slate blue and navy

Here is the part of this story that should bother you most: nobody did anything wrong.

Nobody clicked a phishing link. Nobody reused a password from 2014. They walked up to a rental car counter, or a dispensary register, or a hotel front desk, and handed their driver's license to a person who asked for it. Which is exactly what you are supposed to do.

On September 1, Krebs on Security reported that a dark web identity theft service called Nexus had launched offering digital scans of more than 153 million driver's licenses from people in the United States and Canada. Alongside those: more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. A threat actor advertising it on the Russian cybercrime forum Exploit claimed to hold IDs of over 170 million people in North America.

The FBI's New Orleans field office opened an official investigation into an apparent breach involving idscan.net, a Louisiana identity verification company. SecurityWeek reported two days later that the Nexus platform was shut down shortly after the story ran.

Six images, not one

The detail that gives this away is the file structure.

Each license record in Nexus did not contain a photo. It contained six image files: three pairs of front and back photos, a basic image scan, plus infrared and ultraviolet versions. idscan.net's own documentation states that its technology scans IDs with both infrared and ultraviolet light.

Nobody's phone camera produces an infrared scan of a license. That is hardware sitting on a counter.

Every image file also had a date and timestamp appended to the filename, and the timestamps appeared to be GMT. Which turned the data set into a map of where and when people had physically presented their ID.

The timestamps tell you where you were standing

Krebs asked friends and family for permission to search the service. Nine people whose licenses turned up confirmed they had been traveling on or near the timestamp dates. Multiple had rented cars from Hertz.

The cleanest single data point: Krebs and his mother had timestamps a few seconds apart, matching the moment they both handed their licenses to a Hertz rental representative at the same time.

He also ruled something out honestly, which is worth noting. He did not show his license at airport security that day, having used a passport because he had no Real ID at the time. That weakened the airport theory. There were also no passports in the data set at all.

Researcher Zach Edwards found his own license in the service, with a timestamp matching a DEFCON trip to Las Vegas. On that trip he handed his license to TSA, to a marijuana dispensary called Planet13, and to his hotel, the Aria. The dispensary was the one that definitely scanned it into a device. IDScan announced an exclusive ID verification agreement with Planet13 dispensaries in 2022.

Larry Baldwin, principal intelligence researcher at Cybera, found a front and back scan of his own license with timestamps matching a Hertz car rental. He made the point that matters most about this document class: driver's licenses are commonly used as proof of identity when opening new lines of credit.

idscan.net says it performs more than 21 million verifications monthly at more than 20,000 locations worldwide, and provides ID verification for more than 1,000 marijuana dispensaries in 19 US states. Its trust page lists customers including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment.

None of those brand names are the point. The point is that you have never heard of the vendor behind the counter, and it does not matter how careful you are, because you were never in that conversation.

This was not a snapshot, it was a subscription

Nexus records grew by nearly 400,000 driver's license records in 24 hours. The operators claimed they had "been continuously exfiltrating new data for over a year into our private database."

Read that again. Not a one-time dump. A live feed, running for over a year, filling up in near real time as people kept walking up to counters and handing over their licenses.

The license of US Defense Secretary Pete Hegseth was among those available, as was the FBI's assistant director's. Krebs did not find FBI Director Kash Patel's license, which is a useful reminder that absence from a data set proves very little.

idscan.net told Krebs it was investigating. Jillian Kossman of the company said, "At this point I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation."

We build a redaction tool and it would not have helped here

Let us be blunt, because the alternative is dishonest.

RedactID would not have prevented this. Not a single record. When a clerk runs your physical license through a scanner, you have zero technical control over what gets captured, how long it is retained, or which third party warehouses it. There is no browser, no file, no export step, no decision point you own. You can ask about retention policy and you can decline and walk out, and that is genuinely the whole toolkit.

Anyone selling you a product as the answer to this particular breach is lying to you.

The part you actually control is much bigger

Here is what is worth sitting with. The counter scan happens a handful of times a year. Renting a car, checking into a hotel, a dispensary visit.

Now count the other way. How many times in the last twelve months did you email, upload, text, or attach a photo of your ID? A rental application. A loan officer. HR onboarding. A car dealership. A wire verification. A gym membership. A P2P payment app hitting its identity threshold.

For most people that number is higher, the copies are full resolution, and they live indefinitely in inboxes, shared drives, CRMs, and property management portals that nobody is auditing.

And almost every one of those requests needed three things: a name, a photo, and an expiration date. Not the license number. Not the full address. Not the document discriminator, the height, the weight, the organ donor status, the endorsements. People send the whole card because the whole card is what the camera captured, not because the whole card was asked for.

That is the surface where reducing what you hand over actually works. Naming what the recipient is deciding, then redacting an ID down to the fields that serve that decision, is a real intervention with a real effect. Same logic applies to the ID copy a lender asks for, where the temptation to overshare is highest because you want the approval. Same for bank statements, pay stubs, and mortgage paperwork, where a single PDF can carry account numbers you never intended to circulate.

RedactID runs in your browser. The file never leaves your device, nothing is uploaded, nothing is stored on a server. Redactions are permanently flattened, which matters because drawing a black box in Preview or an image editor can often be reversed, and in a PDF the text underneath is frequently still selectable. You get free redactions daily, with credit packs and a Pro plan if you need volume.

A password is a five minute fix. A license is not.

This is the asymmetry nobody prices correctly.

When a password leaks, you rotate it over coffee and the exposure ends. When a six-image infrared and ultraviolet scan of your driver's license leaks, nothing ends. You cannot rotate your face. You cannot rotate your license number, your date of birth, or your signature. You can get a new card, and the old images still open new lines of credit.

Breach data does not expire. It just waits.

You could not have stopped the counter scan. You can stop being the person who emails a full unredacted license image to a leasing agent next Tuesday, and given how permanent this document class is, that is not a small thing.

---

Related: Redact an ID online · Redact documents online · Redact an ID for a loan application

If you want to start with the copies you do control, RedactID is free to try in your browser, and plans and pricing are there if you outgrow the daily free tier.

Everything runs in your browser. Your file is never uploaded.

Ready to Protect Your Privacy?

RedactID lets you redact sensitive information from documents without uploading them — everything is processed on your device.