US data protection and identity verification

The 153 Million License Breach Shows ID-Verification Vendors Answer to No One

IDScan.net's alleged breach exposes how federal law imposes no baseline security duty on the vendors retailers hire to scan driver's licenses.

The IDScan.net Breach, By the Numbers People of Internet Research · US 153M+ Driver's licenses exposed US and Canadian licenses listed fo… ~400,000 New records added daily Pace at which Nexus claimed its da… 21M Monthly ID verifications by vend… Scale of checks IDScan.net says it… 30 days Federal breach-report deadline Window financial institutions get … peopleofinternet.com
The IDScan.net Breach, By the Numbers People of Internet Research · US 153M+ Driver's licenses exposed ~400,000 New records added daily 21M Monthly ID verifications by… 30 days Federal breach-report de… peopleofinternet.com

Key Takeaways

A breach with no clear owner

On August 31, 2026, a new user on the Russian-language cybercrime forum Exploit began advertising a service called Nexus: a searchable database of more than 153 million U.S. and Canadian driver's licenses, over 10 million ID cards, 3 million travel documents, and 579,000 medical cards — growing by roughly 400,000 records a day. Brian Krebs confirmed the claim was real the way any reporter would want it confirmed: the seller offered his own Virginia driver's license as a free sample (Krebs on Security). Victims traced their scans to Hertz rental counters, pointing investigators toward IDScan.net, a Louisiana-based identity-verification vendor whose front-and-back, infrared, and ultraviolet ID scans reportedly serve more than 20,000 locations and 21 million verifications a month for clients including Hertz, Target, and FedEx (TechCrunch). The FBI's New Orleans field office opened an investigation September 1; Nexus went dark shortly after Krebs published.

The technical failure here is almost secondary to the structural one. IDScan.net is not the entity most consumers ever agreed to trust with their driver's license. A renter hands a license to a Hertz clerk, who feeds it through a scanner running on backend infrastructure the customer has never heard of. If that infrastructure is breached, the company whose brand appears on the counter — Hertz, Target, a cannabis dispensary — is the one with a customer relationship and a reputational incentive to respond. The vendor that actually held the data has neither.

The steelman for stricter vendor rules

There is a real case for treating this differently than an ordinary retailer breach. Driver's license scans are not a password that can be reset — they are permanent biometric-adjacent identity documents, often including the exact document number, address, date of birth, and now infrared/UV security-feature imagery that criminals can use to manufacture convincing fake IDs. Unlike a credit card breach, victims cannot simply cancel the compromised credential without going through their state DMV. And because verification vendors sit invisibly behind dozens of brand-name retailers, a single vendor breach can silently multiply across millions of consumers who never chose to interact with that vendor at all. Regulators who argue that back-end identity infrastructure deserves the same mandatory security baseline as, say, banks or hospitals are not being alarmist — they are describing exactly the failure mode Nexus represents.

Where the law actually sits

The trouble is that no federal law currently imposes that baseline on a company like IDScan.net. The FTC's Safeguards Rule — the closest thing the U.S. has to a federal vendor-security mandate — only reaches "financial institutions" under the Gramm-Leach-Bliley Act: lenders, tax preparers, collection agencies, and similar entities. Since May 13, 2024, those covered entities must report breaches touching 500 or more consumers to the FTC within 30 days of discovery (FTC). An ID-scanning vendor to car-rental counters and retail chains isn't a financial institution and falls outside that rule entirely. There is no equivalent federal floor for companies whose entire business model is warehousing scans of government identity documents.

What fills the gap, unevenly, is the 50-state patchwork of breach notification statutes. Virginia's law, for instance, defines "personal information" to include a driver's license number and requires the entity that "owns or licenses" the data to notify the Attorney General and affected residents "without unreasonable delay" (Va. Code § 18.2-186.6). Every state has some version of this. But these statutes were written with a single retailer breach in mind — the company that collected your data is the company that notifies you. They were not built for a vendor architecture where the entity holding 153 million scans has no direct relationship with a single one of the people it's obligated to notify, and where liability could plausibly be argued to sit with IDScan, with Hertz, or with neither until a court decides.

The proportionate fix, not the broad one

The instinct after a breach this size is to reach for sweeping data-broker legislation or a blanket ban on third-party ID scanning. That would be a mistake. Digital identity verification is not a rent-seeking middleman industry — it is what lets a rental counter, an age-restricted retailer, or a dispensary comply with the law in seconds instead of minutes, and it materially reduces fraud relative to manual ID checks. Banning or heavily restricting it would push verification back toward slower, more error-prone, and no more secure manual processes, at real cost to legitimate commerce.

The narrower, evidence-based fix is to extend something like the Safeguards Rule's own logic — a written security program, defined breach thresholds, and a 30-day federal reporting clock — specifically to companies whose core business is storing scans of government identity documents at scale, regardless of whether they meet GLBA's financial-institution definition. That closes the exact gap this breach exposed without touching the broader identity-verification industry's ability to operate. Congress has federal breach-notification bills pending in nearly every session; this incident is a concrete, narrow case study for why one should finally move — not for why identity verification itself needs to be re-regulated from scratch.

Sources & Citations

  1. Krebs on Security: FBI Probes Service Selling 153M+ Drivers Licenses
  2. TechCrunch: hackers breached a major ID card verification service
  3. FTC: Safeguards Rule notification requirement now in effect
  4. Virginia Code § 18.2-186.6, breach of personal information notification