Finn's Take· TL;DRYou probably don't remember handing your ID to a scanner at a car rental counter, a cannabis dispensary, or a retail checkout — but that moment may now be haunting you. ID verification service IDScan has confirmed that a data breach involved the theft of driver's licenses from its systems, with hackers stealing the licenses from the company's cloud — including people's full names, driver's license numbers, and identity numbers from other government-issued documents such as passports. The scale is staggering. In what has to be one of the biggest data breaches to date, a security researcher discovered a hacker who appeared to be selling access to a database of over 153 million driver's licenses from the United States and Canada.
The disclosure, first reported by security journalist Brian Krebs of KrebsOnSecurity, points to a likely breach at IDScan.net, a Louisiana-based identity-verification company whose scanning technology sits behind ID checks at car rental counters, retailers, and dispensaries across North America. A new dark-web identity theft service, called Nexus, appears to have siphoned images from IDScan.net, a platform that serves businesses such as Hertz, FedEx, Target, and marijuana dispensaries. If you've done business with any of them in recent years, your data may be out there.
According to Krebs, Nexus claimed in its forum post that it obtained the documents through a live breach at a "major identity verification company," and that it had been "exfiltrating new data for over a year into our private database." That's not a smash-and-grab — that's a sustained, methodical operation. A post on the Exploit forum promoting Nexus claimed that new records were being added at a rate of roughly half a million per day, which would imply the attacker still had a live feed into the company's systems as of early September.
Krebs reported that he was alerted to a website on the dark web that allowed anyone to search the driver's license information of over 150 million people living in the United States and Canada, including accessing their photos — and he verified the authenticity of the data by examining his own record. The database also contained high-profile individuals, including U.S. Secretary of Defense Pete Hegseth. The Pentagon confirmed it was aware of the suspected breach, and a spokesperson for the FBI said it was also investigating the incident. The Nexus service was shut down shortly after the Krebs report was published.
Government-issued ID scans are not like a compromised email password or a leaked credit card number you can cancel and replace. A driver's license number paired with your full name can fuel account fraud, synthetic identity creation, and impersonation across verification systems that treat these credentials as definitive proof of identity. The danger doesn't stop at finances, either. Beyond financial fraud, this breach raises unusual safety concerns — security researchers noted that clear license photos could help someone locate individuals who do not want to be found, including domestic violence survivors and people in witness protection programs, meaning the risk extends past typical financial harm into personal safety.
If the service's reported claims are true, the breach could be one of the most extensive single leaks of driver's license data, according to James E. Lee, President of the Identity Theft Resource Center, which has tracked breaches since 2005. Compromised data reportedly includes photos of the front and back of licenses, as well as infrared and ultraviolet versions of the same images. That level of detail makes the stolen records especially valuable — and dangerous.
IDScan.net says it will offer free credit monitoring and identity protection services to those whose information is determined to have been involved, encouraging potentially impacted individuals to enroll and to monitor their account statements for suspicious activity. If you have rented a car, visited a dispensary, or completed age verification at a business in recent years, your license could be part of this breach, as businesses tied to IDScan.net include major national brands — meaning even routine transactions could have put your ID scan at risk.
Experts recommend placing a freeze on your credit, which helps stop lenders from opening new accounts in your name — and you can lift it temporarily whenever you apply for credit yourself. As Krebs himself noted, "There is no way to 'protect' yourself from someone else using a digital scan of your license if the company collecting the scans is relieved of them by hackers, apart from choosing not to have your ID scanned by anything or anyone." That's a sobering reality check — and a warning about how much trust we place in the quiet, forgettable moment of handing over an ID. As investigations by the FBI and IDScan continue, the deeper question this breach forces is whether businesses should be storing your biometric document data at all.