Back to news
Cybersecurity Alert
September 7, 2026 by EmailMeNow IT Consulting

153 Million Driver’s License Scans Were for Sale — FBI Is Looking at IDScan.net

Krebs found Nexus listing 153M+ U.S. and Canadian license scans. FBI New Orleans is investigating. IDScan says a third party may have copied cloud records. Audits (ideal 100%): fbi.gov 64%, hertz.com 53%, veriscancloud.com 44%, idscan.net 42%.

Source: KrebsOnSecurity · Reuters · IDScan.net · Fox 8

NewsData BreachIdentity TheftPhishingMFAYubiKeyAuthenticator AppsCybersecurity
Car-rental counter at dusk with a clerk scanning a face-down ID card beside a darkened monitor

Brian Krebs reported on September 1, 2026 that a new identity-theft storefront called Nexus was selling searchable digital scans of more than 153 million U.S. and Canadian driver’s licenses. The listing also claimed more than 10 million other ID cards, more than 3 million travel or international IDs, and at least 579,000 medical cards. Krebs said his own Virginia license was used as a free sample on the Russian-language Exploit forum.

This is not a state DMV hack in the public record. Krebs matched timestamps on consented samples to places those people had just handed over a license — several Hertz rentals, and at least one Planet 13 dispensary visit. Those businesses use, or have used, New Orleans identity-verification vendor IDScan.net. The FBI’s New Orleans field office opened an inquiry the same day. Reuters independently confirmed the bureau is “looking into the incident.”

This is not a duplicate of the Nutex Health 8-K, the ATF / Qilin claim, or FBI NCII lookalike phishing. Those are different victims and different data.

Car-rental counter at dusk with a clerk scanning a face-down ID card beside a darkened monitor

Snapshot

FieldDetail
VendorIDScan.net (New Orleans / Metairie, Louisiana)
StorefrontNexus — advertised Aug 31; offline after Krebs published
Federal inquiryFBI New Orleans — Sept 1, confirmed to Reuters Sept 2
Company lineUnauthorized party may have copied cloud records

IDScan has not publicly adopted the 153 million figure as its own count. Treat Nexus inventory as Krebs’s measurement of the storefront, not a confirmed victim total.

What Krebs documented

A blank Nexus search returned about 11.5 million pages at roughly 15 records per page. During his reporting the advertised driver’s-license count rose by nearly 400,000 in 24 hours. The operators claimed they had been exfiltrating “for over a year.” That claim is unverified.

Consented samples included front, back, infrared, and ultraviolet images — the same extra spectra ID-authentication hardware uses to check holograms and security inks. Krebs found licenses belonging to senior U.S. officials, including the Defense Secretary and an FBI assistant director. We are not reproducing those images or filenames.

Several timestamps lined up with Hertz counters. Researcher Zach Edwards told Krebs the only device scan he was sure of that day was Planet 13 in Las Vegas. IDScan announced an exclusive Planet 13 agreement in 2022 and says it processes ID checks for more than 1,000 cannabis shops in 19 states. IDScan’s own marketing says it runs more than 21 million verifications a month at more than 20,000 locations.

Ars Technica later described a Hertz rental whose license appeared in Nexus within hours. That is corroboration of the timestamp pattern, not proof Hertz’s own network was breached.

Sealed sample envelope beside a laptop showing only a blurred grid of empty document thumbnails

What IDScan and the FBI have said

Krebs quoted IDScan marketing and operations lead Jillian Kossman on September 1: the company was investigating and could not share more. Shortly after publication, Nexus replaced its login with “This service is no longer available.” Taking the storefront down does not delete copies already sold.

Fox 8 (WVUE) reported a Friday, September 4 company statement: IDScan took immediate steps to secure systems, hired outside specialists, and is cooperating with federal law enforcement. The company wrote that an unauthorized third party may have accessed and/or copied certain customer information stored in accounts on the IDScan.net cloud. Affected data may include full names and driver’s license or other government ID numbers. IDScan said full access on the storefront required payment, and it is notifying people and offering free credit monitoring.

Fox 8 listed the company’s help line as 1-833-516-2980 and a Metairie mail address. Type idscan.net yourself before calling a number from email or text.

A Caesars Entertainment spokesperson told Krebs the casino group has not been an IDScan client and has not used VeriScan since February 2025, despite appearing on IDScan’s trust page. Caesars said IDScan told them the incident should have no impact on Caesars.

CourtListener — Eastern District of Louisiana

Nine putative class actions against IDscan.net, Inc. landed in the Eastern District of Louisiana between September 2 and 4, 2026. CourtListener RECAP has the dockets. These are allegations, not findings.

CaseDocketFiled
Bunch v. IDscan.net2:26-cv-01929Sep 2
Greenbaum v. IDscan.net2:26-cv-01930Sep 2
Sealy v. IDscan.net2:26-cv-01931Sep 2
Rioux v. IDscan.net2:26-cv-01932Sep 2

Also filed: Layman (2:26-cv-01937, Sep 3); Wagner (2:26-cv-01946); Katz (2:26-cv-01949); Buckles (2:26-cv-01954); Sullivan (2:26-cv-01956) on Sep 4. BleepingComputer reported additional firm investigations.

What to do if you handed over a license

You cannot reset a face, date of birth, or license history the way you reset a password.

  1. Type idscan.net if you need the company’s notice or help line. Ignore “your scan is for sale — pay to suppress” mail.
  2. Type hertz.com yourself for Gold+ account changes. Do not use a lookalike “rental refund / ID restored” link.
  3. Place a credit freeze at Equifax, Experian, and TransUnion if you recently rented a car, checked into a hotel, or showed ID at a dispensary, gun counter, or freight dock that uses a third-party scanner.
  4. Watch new-account and tax-refund mail. A high-resolution license scan is enough to open credit or clone a card that can pass some UV/IR checks.
  5. Report misuse to IdentityTheft.gov and IC3.
  6. If you run a shop that scans IDs: ask the vendor whether images are retained, for how long, and who can pull them. If you do not need the image after the check, do not keep it.

MFA: YubiKey and Google Authenticator

A hardware key does not un-copy a license image that already left a scanner cloud. It does cut a lot of the follow-on “verify your Hertz / IDScan notice / credit-freeze PIN” phishing. Grades match our MFA directory.

GradeMeaning
FailDocumented second factor is SMS, voice, or email OTP — or no public path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
Hertz Gold+FailNoNo
IDScan VeriScan CloudPassNoYes
Login.govStrongYesYes

Hertz’s public Gold+ help does not name a YubiKey or Google Authenticator enrollment path. Treat consumer login as Fail. IDScan’s VeriScan Cloud MFA article documents phone SMS, email, or an authenticator app, and admins can require MFA. That is Pass on open TOTP — not Strong. SMS and email OTP remain weaker options; we found no public YubiKey path. Login.gov remains Strong for eligible federal sign-in. It does not protect a license you handed to a rental clerk.

Directory: MFA support directory · Category → Travel and Email & Identity.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a blank car-rental folder

Independent cybersecurity audits

We audited the official IDScan, VeriScan Cloud, Hertz, and FBI hosts on September 7, 2026. 100% is the idealnone reach it. These scores are public email / transport / website posture. They do not say how Nexus obtained the scans.

OrganizationDomainOverallvs 100%
FBIfbi.gov64%−36
Hertzhertz.com53%−47
VeriScan Cloudveriscancloud.com44%−56
IDScan.netidscan.net42%−58
DomainIdentityTransportWebsite
fbi.gov75%45%40%
hertz.com50%45%37%
veriscancloud.com0%15%90%
idscan.net25%15%37%

Audit links: fbi.gov · hertz.com · veriscancloud.com · idscan.net

idscan.net Identity 25% and Transport 15% mean spoofed “license restored / enroll monitoring” mail is easier to deliver than the 42% overall suggests. veriscancloud.com Identity 0% is a no-MX portal-host pattern — not a reason to follow a lookalike. fbi.gov is the investigating agency, not the vendor.

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on September 7, 2026:

DomainStack signal
idscan.netStack undetected; Let’s Encrypt TLS expires 2026-11-26; HTTP→HTTPS redirect not confirmed
veriscancloud.comStack undetected; GlobalSign TLS expires 2026-11-26
hertz.comStack undetected; GlobalSign TLS expires 2027-02-06
fbi.govStack undetected; Amazon Trust TLS expires 2027-02-08

Point-in-time only. A live marketing homepage is not a forensic finding on the cloud accounts IDScan described.

Blacklist and lookalike domains

Email blacklist checks (public DoH, September 7, 2026): idscan.net, veriscancloud.com, hertz.com, and fbi.gov were clear on mail/domain lists we can query.

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
idscan.net2401
hertz.com7531
fbi.gov1100
veriscancloud.com000

High-interest registered names (investigate; not proof this incident used them):

LookalikeTechniqueNote
ldscan.nethomoglyphBEC staging (NS + MX)
idscan.comtld-swapLive NS + A + MX — not the .net vendor
hertz.nettld-swapBEC staging (NS + MX)
heertz.cominsertionLive NS + A + MX
fbi.comtld-swapNot the .gov bureau

Type idscan.net and hertz.com, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing response aimed at the 100% ideal.


Sources: KrebsOnSecurity, Sept 1, 2026 · Reuters, Sept 2 · Fox 8 / WVUE, Sept 6 · Ars Technica · BleepingComputer · IDScan · VeriScan Cloud MFA · CourtListener RECAP (E.D. La., Sept 2–4). Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 7, 2026. Domain scores: audit.emailmenow.com only.