You cannot rotate a driver's licence
A dark web service listed 153 million US and Canadian licence scans, including the infrared and ultraviolet captures used to prove they are genuine.
Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.
A driver’s licence record on the service was six image files. Front and back photographs, a plain scan, and then the infrared and ultraviolet versions, each carrying a timestamp [1].
Those last two are the interesting ones. They are not pictures of you. They are pictures of the security features your province or state embeds so a clerk can tell a real licence from a printed one.
The system that captured them exists to detect fakes. It kept the images.
What happened
On September 1, 2026, Brian Krebs reported an identity theft service called Nexus, launched on a Russian-language cybercrime forum, offering digital scans of identity documents belonging to millions of North Americans. The listings covered more than 153 million US and Canadian driver’s licences, over 10 million identification cards, more than 3 million travel documents and international IDs, and roughly 579,000 medical cards [1]. About 1.1 million of the licences were Canadian [3].
Krebs did not take the seller’s word for the volume. He paged through the index without search parameters, found roughly 11.5 million pages at about 15 results each, and reported that the arithmetic supported the claim [1]. That is a small thing and it is the difference between reporting a number and checking one.
The attribution came from timestamps. Researcher Zach Edwards found his own licence in the corpus with a timestamp matching a visit to a cannabis dispensary that publicly uses IDScan.net for ID checks. Krebs found his own record, and its images included the infrared and ultraviolet captures that match IDScan.net’s documented technology. Rental counter visits by several other people lined up the same way [1][2].
IDScan.net’s COO told Krebs the company was investigating [1]. Its CEO did not respond to TechCrunch [2]. The FBI’s New Orleans field office, in the state where IDScan.net is based, opened an investigation on September 1 [1][2]. SecurityWeek reported that some of the exfiltrated licences appear to belong to FBI agents [3], which is one explanation for the speed.
Nexus went offline after the reporting published [2].
Why this matters
The leaked layer is the one that establishes authenticity. IDScan.net’s own documentation describes scanning under white, ultraviolet and infrared light, comparing what appears under UV against the template for that jurisdiction’s format, checking holograms and verifying microprints at pixel level, across more than 400 automated checks [4]. That is a detailed capture of how a genuine document is constructed. Reporting on the leak notes that access to this source material could make fraudulent submissions harder to distinguish from real ones [1].
There is no remediation available to the individual. A password can be rotated and a card number reissued. The security design of Ontario’s licence, or Louisiana’s, is a fixed physical artefact shared by every holder, and nobody is reprinting it because a vendor lost the scans. For the people in this set, the usual advice runs out quickly.
The businesses in the middle are small. Dispensaries, rental desks and retail counters bought a compliance tool to check ages and catch fakes [4]. Almost none of them chose a data retention posture, because that was not the thing they were buying. They now sit inside somebody else’s breach.
Technical breakdown
The intrusion is the part nobody has explained, and that is worth stating plainly before anything else. Neither the company, the FBI, nor any researcher has published how the data was obtained, when the compromise began, or whether access continues [2]. What is documented is the shape of the collection either side of that gap.
On the capture side, authentication requires specialty hardware that images the document under three wavelengths simultaneously, with the results checked against jurisdictional templates by a model IDScan.net says was trained on over 500 million scanned documents [4]. The output is not a yes or no. It is a set of images, and in this corpus those images persisted with per-scan timestamps accurate enough for two researchers to reconstruct where and when they had personally handed over a licence [1].
On the extraction side, timestamps across the corpus spanned roughly a year, which points to sustained access rather than one grab [1]. While the service was live Krebs observed the record count grow by about 400,000 in twenty four hours [1]. The operators separately claimed around 500,000 new documents a day from a major identity verification company [2]. Those two numbers are close and they are not the same number, and only the first one was observed rather than advertised.
- CaptureA customer presents a licence at a dispensary, rental desk or retail till and the scanner images it under white, ultraviolet and infrared light
BREAK THE CHAIN HERE
Configure the deployment to return a pass or fail without persisting imagery wherever the use case allows, and buy on that basis. An age check needs a decision, not a permanent copy of the document that produced it. - RetentionThe images and their timestamps are kept by the verification platform after the pass or fail has been returned
BREAK THE CHAIN HERE
Put a retention period and a deletion SLA in the contract, and ask for the documented deletion process by name. NIST SP 800-63A requires a published deletion process and default retention period for biometric information, so a vendor that cannot produce one for document imagery has told you something. - AggregationRecords from many unrelated businesses accumulate in one place, indexed so a single person can be found by name
- Access obtainedAn actor reaches that store by a method nobody has published, including the company and the investigating agency
- Sustained collectionTimestamps across the corpus span about a year, indicating extraction over time rather than a single export
BREAK THE CHAIN HERE
Alert on sustained bulk reads from the verification store rather than only on failed logins. A year of quiet extraction is a volume signature, and it is the signature that was available to be noticed. - IndexingThe records are loaded into a searchable service, each licence carrying six files including the infrared and ultraviolet captures
- AdvertisementThe service is launched on a Russian-language cybercrime forum and marketed by document type and country
- MonetisationBuyers search by name and purchase document sets, with the authentication imagery reported to raise the quality of fraudulent submissions
- TakedownThe service goes offline after public reporting, which closes the storefront and does nothing about copies already distributed
The three breaks sit before the incident rather than during it, which is the uncomfortable part. Not capturing the image, not keeping it, and noticing when it leaves are the whole defence. Once the corpus exists and is indexed, every remaining step belongs to somebody else.
The standard does not tell anyone to delete it
I expected NIST SP 800-63A to require disposal of identity evidence after proofing, because that is what people cite when they say a verification vendor is compliant. It does not.
Revision 4 requires a credential service provider to have a documented and publicly available deletion process and default retention period for biometric information, and separately requires the practice statement to document retention, protection and deletion of personal, sensitive and biometric data [5]. It sets no timeframe for images of identity documents and prescribes no method. The requirement is to have a policy and publish it, not to minimise.
That is not a flaw hidden in the text. It is the text. And it means “we follow NIST guidance” is compatible with keeping your licence scan indefinitely.
What defenders should do Monday morning
Immediate, within 24 hours. If you operate ID scanning at a counter, find out what your deployment retains and where it goes. The specific question is whether the infrared and ultraviolet captures persist after the check completes, because that is the material at issue here. If you are a consumer in the affected set, place a credit freeze, which is free and reversible, and stop treating identity verification prompts as routine.
Near term, this week. Send your vendor the three questions in writing: what is retained, what the documented deletion process and default retention period are, and whether the deployment can be configured to return a result without storing imagery [5]. Then check your own contract for a retention clause, and note whether you ever asked for one. Review who inside your business can export records in bulk from the platform, and whether anyone would see it happen.
Structural, this quarter. Treat identity evidence the way you already treat payment card data: something you handle, verify and do not keep. Then go through the rest of your vendor estate for the same pattern, which is any supplier that retains a high-value artefact as a by-product of performing a check. Verification exhaust is a category, and this will not be the last time it leaks.
Checklist
- Every ID scanning deployment inventoried, including which businesses and which hardware
- Retention behaviour confirmed for document imagery, including infrared and ultraviolet captures
- Vendor asked in writing for its documented deletion process and default retention period
- Contract checked for a retention clause, and one added where absent
- Deployment reconfigured to return a result without persisting imagery where the use case allows
- Bulk export from the verification platform restricted and monitored
- Alerting in place for sustained high-volume reads, not only for authentication failures
- Consumers advised on credit freezes where you know their documents were scanned
- Vendor estate reviewed for other suppliers retaining artefacts as a by-product of a check
Verification should be built to forget
The failure here is not that a company was breached. Companies are breached constantly and this post would be unremarkable if the losses were names and addresses.
The failure is that an industry built to confirm documents are real decided, by default and without much argument, to keep the evidence it generated while confirming them. Six files per person. Infrared and ultraviolet included. Timestamped precisely enough to place someone at a dispensary on a particular afternoon. None of that was necessary to answer the question the customer at the counter was actually asking, which was whether this person is over nineteen.
The check is the product. The image is exhaust, and exhaust that identifies 153 million people should be treated as a liability from the moment it is created rather than as an asset because storage is cheap. The standards could say so and currently do not, which leaves the decision with the businesses buying these platforms. So make it deliberately. Ask what your vendor keeps, write the answer into the contract, and be prepared to hear that nobody has thought about it, because that is the answer this incident suggests is common.
FREQUENTLY ASKED
- My licence was probably scanned at a dispensary. What can I actually do?
- Less than you would like, and the honest answer matters here. You cannot reissue the security design of your province or state's licence, and requesting a new licence number is rarely possible without a documented reason. What you can do is assume your identity documents are available to someone opening accounts in your name: place a credit freeze with the bureaus, turn on any bank or telecom alerting you have, and treat any unexpected identity verification prompt as suspicious rather than routine.
- We use an ID scanning vendor at our counter. What should we ask them this week?
- Three questions, in writing. What images do you retain after the pass or fail is returned, including the infrared and ultraviolet captures. What is your documented deletion process and default retention period. Can we configure the deployment to return a verification result without persisting the imagery. If the answers are vague, that vagueness is your exposure, because the records in this leak carried per-scan timestamps that tie a person to a place and a time.
- Why does the infrared and ultraviolet part matter more than the photo?
- Because it is the layer that proves the document is genuine rather than the layer that says who you are. Those captures show the security elements a jurisdiction embeds for exactly this purpose, and reporting on the leak notes that access to them could make fraudulent submissions harder to tell apart from real ones. A leaked name and address is a privacy harm. Leaked authentication imagery is a problem for everyone who relies on that check, including people whose documents were never in the set.
- Is this confirmed as an IDScan.net breach?
- Not by the company. Researchers matched timestamps in the leaked records to their own visits to businesses known to use IDScan.net, and the images include the infrared and ultraviolet captures its platform is documented as producing. The FBI opened an investigation. IDScan.net has said it is investigating and has not confirmed a breach. Treat the attribution as strongly evidenced and formally unconfirmed, which is different from either certainty or doubt.
- The site is offline now. Is it over?
- The storefront closed. The data did not. Nexus went offline after the reporting, which removes the search interface that made the corpus convenient and does nothing about copies already sold or held. Records also grew by roughly 400,000 in a single day while it was up, so whatever was feeding it was live at that point, and nobody has published whether it has been cut off.
REFERENCES
- [1]FBI Probes Service Selling 153M Drivers LicensesJOURNALISM
- [2]It sure looks like hackers breached a major ID card verification serviceJOURNALISM
- [3]153 Million Driver License Images Offered on Dark WebJOURNALISM
- [4]ID Authentication and Fake ID DetectionPRIMARY
- [5]NIST Special Publication 800-63A Revision 4, Identity Proofing and EnrollmentPRIMARY
BEFORE YOU GO
Was this useful?
Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.
SEND FEEDBACK ↗