Brian Krebs reported on September 1, 2026 that a new identity-theft storefront called Nexus was selling searchable digital scans of more than 153 million U.S. and Canadian driver’s licenses. The listing also claimed more than 10 million other ID cards, more than 3 million travel or international IDs, and at least 579,000 medical cards. Krebs said his own Virginia license was used as a free sample on the Russian-language Exploit forum.
This is not a state DMV hack in the public record. Krebs matched timestamps on consented samples to places those people had just handed over a license — several Hertz rentals, and at least one Planet 13 dispensary visit. Those businesses use, or have used, New Orleans identity-verification vendor IDScan.net. The FBI’s New Orleans field office opened an inquiry the same day. Reuters independently confirmed the bureau is “looking into the incident.”
This is not a duplicate of the Nutex Health 8-K, the ATF / Qilin claim, or FBI NCII lookalike phishing. Those are different victims and different data.

Snapshot
| Field | Detail |
|---|---|
| Vendor | IDScan.net (New Orleans / Metairie, Louisiana) |
| Storefront | Nexus — advertised Aug 31; offline after Krebs published |
| Federal inquiry | FBI New Orleans — Sept 1, confirmed to Reuters Sept 2 |
| Company line | Unauthorized party may have copied cloud records |
IDScan has not publicly adopted the 153 million figure as its own count. Treat Nexus inventory as Krebs’s measurement of the storefront, not a confirmed victim total.
What Krebs documented
A blank Nexus search returned about 11.5 million pages at roughly 15 records per page. During his reporting the advertised driver’s-license count rose by nearly 400,000 in 24 hours. The operators claimed they had been exfiltrating “for over a year.” That claim is unverified.
Consented samples included front, back, infrared, and ultraviolet images — the same extra spectra ID-authentication hardware uses to check holograms and security inks. Krebs found licenses belonging to senior U.S. officials, including the Defense Secretary and an FBI assistant director. We are not reproducing those images or filenames.
Several timestamps lined up with Hertz counters. Researcher Zach Edwards told Krebs the only device scan he was sure of that day was Planet 13 in Las Vegas. IDScan announced an exclusive Planet 13 agreement in 2022 and says it processes ID checks for more than 1,000 cannabis shops in 19 states. IDScan’s own marketing says it runs more than 21 million verifications a month at more than 20,000 locations.
Ars Technica later described a Hertz rental whose license appeared in Nexus within hours. That is corroboration of the timestamp pattern, not proof Hertz’s own network was breached.

What IDScan and the FBI have said
Krebs quoted IDScan marketing and operations lead Jillian Kossman on September 1: the company was investigating and could not share more. Shortly after publication, Nexus replaced its login with “This service is no longer available.” Taking the storefront down does not delete copies already sold.
Fox 8 (WVUE) reported a Friday, September 4 company statement: IDScan took immediate steps to secure systems, hired outside specialists, and is cooperating with federal law enforcement. The company wrote that an unauthorized third party may have accessed and/or copied certain customer information stored in accounts on the IDScan.net cloud. Affected data may include full names and driver’s license or other government ID numbers. IDScan said full access on the storefront required payment, and it is notifying people and offering free credit monitoring.
Fox 8 listed the company’s help line as 1-833-516-2980 and a Metairie mail address. Type idscan.net yourself before calling a number from email or text.
A Caesars Entertainment spokesperson told Krebs the casino group has not been an IDScan client and has not used VeriScan since February 2025, despite appearing on IDScan’s trust page. Caesars said IDScan told them the incident should have no impact on Caesars.
CourtListener — Eastern District of Louisiana
Nine putative class actions against IDscan.net, Inc. landed in the Eastern District of Louisiana between September 2 and 4, 2026. CourtListener RECAP has the dockets. These are allegations, not findings.
| Case | Docket | Filed |
|---|---|---|
| Bunch v. IDscan.net | 2:26-cv-01929 | Sep 2 |
| Greenbaum v. IDscan.net | 2:26-cv-01930 | Sep 2 |
| Sealy v. IDscan.net | 2:26-cv-01931 | Sep 2 |
| Rioux v. IDscan.net | 2:26-cv-01932 | Sep 2 |
Also filed: Layman (2:26-cv-01937, Sep 3); Wagner (2:26-cv-01946); Katz (2:26-cv-01949); Buckles (2:26-cv-01954); Sullivan (2:26-cv-01956) on Sep 4. BleepingComputer reported additional firm investigations.
What to do if you handed over a license
You cannot reset a face, date of birth, or license history the way you reset a password.
- Type idscan.net if you need the company’s notice or help line. Ignore “your scan is for sale — pay to suppress” mail.
- Type hertz.com yourself for Gold+ account changes. Do not use a lookalike “rental refund / ID restored” link.
- Place a credit freeze at Equifax, Experian, and TransUnion if you recently rented a car, checked into a hotel, or showed ID at a dispensary, gun counter, or freight dock that uses a third-party scanner.
- Watch new-account and tax-refund mail. A high-resolution license scan is enough to open credit or clone a card that can pass some UV/IR checks.
- Report misuse to IdentityTheft.gov and IC3.
- If you run a shop that scans IDs: ask the vendor whether images are retained, for how long, and who can pull them. If you do not need the image after the check, do not keep it.
MFA: YubiKey and Google Authenticator
A hardware key does not un-copy a license image that already left a scanner cloud. It does cut a lot of the follow-on “verify your Hertz / IDScan notice / credit-freeze PIN” phishing. Grades match our MFA directory.
| Grade | Meaning |
|---|---|
| Fail | Documented second factor is SMS, voice, or email OTP — or no public path |
| Pass | Self-serve Google Authenticator-style open TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| Hertz Gold+ | Fail | No | No |
| IDScan VeriScan Cloud | Pass | No | Yes |
| Login.gov | Strong | Yes | Yes |
Hertz’s public Gold+ help does not name a YubiKey or Google Authenticator enrollment path. Treat consumer login as Fail. IDScan’s VeriScan Cloud MFA article documents phone SMS, email, or an authenticator app, and admins can require MFA. That is Pass on open TOTP — not Strong. SMS and email OTP remain weaker options; we found no public YubiKey path. Login.gov remains Strong for eligible federal sign-in. It does not protect a license you handed to a rental clerk.
Directory: MFA support directory · Category → Travel and Email & Identity.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited the official IDScan, VeriScan Cloud, Hertz, and FBI hosts on September 7, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not say how Nexus obtained the scans.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| FBI | fbi.gov | 64% | −36 |
| Hertz | hertz.com | 53% | −47 |
| VeriScan Cloud | veriscancloud.com | 44% | −56 |
| IDScan.net | idscan.net | 42% | −58 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| fbi.gov | 75% | 45% | 40% |
| hertz.com | 50% | 45% | 37% |
| veriscancloud.com | 0% | 15% | 90% |
| idscan.net | 25% | 15% | 37% |
Audit links: fbi.gov · hertz.com · veriscancloud.com · idscan.net
idscan.net Identity 25% and Transport 15% mean spoofed “license restored / enroll monitoring” mail is easier to deliver than the 42% overall suggests. veriscancloud.com Identity 0% is a no-MX portal-host pattern — not a reason to follow a lookalike. fbi.gov is the investigating agency, not the vendor.

Website stack note
Passive website-tech probes on September 7, 2026:
| Domain | Stack signal |
|---|---|
| idscan.net | Stack undetected; Let’s Encrypt TLS expires 2026-11-26; HTTP→HTTPS redirect not confirmed |
| veriscancloud.com | Stack undetected; GlobalSign TLS expires 2026-11-26 |
| hertz.com | Stack undetected; GlobalSign TLS expires 2027-02-06 |
| fbi.gov | Stack undetected; Amazon Trust TLS expires 2027-02-08 |
Point-in-time only. A live marketing homepage is not a forensic finding on the cloud accounts IDScan described.
Blacklist and lookalike domains
Email blacklist checks (public DoH, September 7, 2026): idscan.net, veriscancloud.com, hertz.com, and fbi.gov were clear on mail/domain lists we can query.
DNS lookalike scans (BEC profile, registered signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| idscan.net | 24 | 0 | 1 |
| hertz.com | 75 | 3 | 1 |
| fbi.gov | 11 | 0 | 0 |
| veriscancloud.com | 0 | 0 | 0 |
High-interest registered names (investigate; not proof this incident used them):
| Lookalike | Technique | Note |
|---|---|---|
| ldscan.net | homoglyph | BEC staging (NS + MX) |
| idscan.com | tld-swap | Live NS + A + MX — not the .net vendor |
| hertz.net | tld-swap | BEC staging (NS + MX) |
| heertz.com | insertion | Live NS + A + MX |
| fbi.com | tld-swap | Not the .gov bureau |
Type idscan.net and hertz.com, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- Nutex Health data breach (same-week scan pile; different victim)
- FBI NCII lookalike support phishing
- Heights Finance third-party cloud breach
- ChatGPT share-link malware
- MFA support directory
Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing response aimed at the 100% ideal.
Sources: KrebsOnSecurity, Sept 1, 2026 · Reuters, Sept 2 · Fox 8 / WVUE, Sept 6 · Ars Technica · BleepingComputer · IDScan · VeriScan Cloud MFA · CourtListener RECAP (E.D. La., Sept 2–4). Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 7, 2026. Domain scores: audit.emailmenow.com only.