BREACH2026-09-08T08:03:13.929805+00:005 min read

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now

153 million driver's license scans showed up for sale on the dark web. If you've ever rented a car, visited a FedEx store, or stepped into a dispensary, yours could be in the pile.

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now

Your Driver's License Was Probably Scanned. Here's Where It Ended Up.

You handed over your license at a Hertz counter. Maybe a FedEx location. Maybe a dispensary or a Target customer service desk. A terminal scanned both sides, the clerk handed it back, and you moved on with your day.

That scan did not disappear.

On or around September 1, 2026, a dark web marketplace called Nexus listed more than 153 million driver's license scans for sale. Not just names and numbers. Full high-resolution front-and-back images, plus infrared and ultraviolet captures. The kind of detail a pickpocket never gets, even if they steal the card itself.

The source was IDScan.net, a company you have almost certainly never heard of, even though it has likely scanned your ID.

What Is IDScan.net and Why Does This Matter?

IDScan.net makes the terminals businesses use to verify your identity in person. Hertz uses them. FedEx uses them. Target uses them. Cannabis dispensaries across the country use them. When you show your ID at the counter, there is a good chance an IDScan.net device is reading it.

These companies are not storing your data to be careless. They use these scans to comply with age verification laws, fraud prevention requirements, and rental agreements. The scanning is routine. The breach is not.

What makes IDScan.net's data especially valuable to criminals is the richness of each record. A typical data breach exposes a password or a credit card number. This breach exposed the actual images used to prove you are who you say you are, the same images a bank teller or a government clerk would accept as proof of identity.

Infrared and UV captures go further than what the human eye sees. They reveal the security features embedded in the card itself. With this data, someone can produce a convincing forgery or simply use the scans digitally wherever a copy of ID is accepted.

The Numbers

The Nexus listing included:

  • 153 million+ driver's license scans
  • 10 million ID cards
  • 3 million travel documents
  • 579,000 medical cards

Security journalist Brian Krebs confirmed the data is real. He matched timestamps on stolen license scans to actual verified transactions. Among the confirmed victims: US Defense Secretary Pete Hegseth and Krebs himself. When the journalist investigating the breach finds his own data in it, that tells you something about the scale.

The FBI's New Orleans field office opened a formal investigation. Nexus pulled the listings shortly after Krebs published his findings. But pulling a listing does not delete data. The files are almost certainly still circulating.

What Can Someone Actually Do With Your License Scan?

Open a bank account in your name. Apply for a credit card. Pass identity verification at financial services, crypto platforms, and loan providers. Bypass "upload a photo of your ID" checks that hundreds of apps use as a security layer.

Most people think of a stolen driver's license as a minor hassle, cancel it, get a new one. This is different. The physical card is replaceable. High-resolution scans with UV captures are not. You cannot issue yourself a new face or a new date of birth. The images are permanent and reusable.

The license you get issued next week will photograph identically to the one in this dataset.

What You Should Do Right Now

  1. Freeze your credit at all three bureaus. Experian, Equifax, and TransUnion each let you do this for free online. A freeze stops new accounts from being opened in your name. This is the single most effective step you can take. Unfreeze it when you need to apply for credit, then refreeze.

  2. Set up fraud alerts. If you are not ready to freeze, place a free one-year fraud alert with any bureau. They are required to share it with the others. Any lender must verify your identity before extending credit.

  3. Check your credit reports now. You can pull free reports from all three bureaus at annualcreditreport.com. Look for accounts you do not recognize.

  4. Enable account alerts on your existing bank and credit accounts. Real-time notifications for transactions catch fraud faster than monthly statement reviews.

  5. Watch for unusual government or tax correspondence. License scan data can also be used for identity fraud in benefits systems or tax filings. A letter from an agency you did not contact is a warning sign.

  6. Consider an identity monitoring service. Many offer free tiers. The paid tiers that include dark web monitoring are worth the cost if your data is in a breach like this one.

  7. Use stronger authentication everywhere you can. Passkeys and hardware security keys are more resistant to identity fraud than SMS codes. If a service offers them, use them.

The Quiet Infrastructure We Never Think About

Here is the thing no one talks about: you never agreed to let IDScan.net store your biometric images indefinitely. You agreed to a terms-of-service with Hertz or Target or a dispensary. What happened to your data after that was handled by a vendor you never met, in a database you never knew existed.

This is how modern identity infrastructure works. Dozens of companies you have never heard of hold pieces of your identity, aggregated from the routine moments of daily life. Renting a car. Picking up a package. Buying a legal product.

The breach at IDScan.net did not happen because someone targeted you. It happened because your data was sitting in a system that failed, and that system was one of hundreds like it.

Regulations have not caught up. Audits are infrequent. Breach notifications are often delayed. The default assumption, that your data is safe because you gave it to a reputable business, has never been more wrong.


Do this now:

  • Freeze your credit at all three bureaus (free, takes minutes)
  • Pull your credit reports and look for unfamiliar accounts
  • Enable transaction alerts on all financial accounts
  • Watch your mail for unexpected government correspondence

Sources

WHAT TO DO RIGHT NOW
  1. 01Go to haveibeenpwned.com and check your email address right now
  2. 02Change your password on the breached service — use a unique password you do not use anywhere else
  3. 03Enable two-factor authentication (2FA) on that account if available
  4. 04Monitor your bank statements and credit report for unusual activity over the next 90 days
RECOMMENDED PROTECTIONAFFILIATE

AuraAll-in-one identity theft and scam protection with real-time alerts

Get Aura
Check Have I Been Pwned →
// FAQ

Common Questions About Breach

What should I do immediately after a data breach?

Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.

Should I freeze my credit after a data breach?

Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

// RELATED

More in breach

Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
2026-09-05T08:04:13.891376+00:00 · 5 min read
Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities
2026-09-03T08:04:32.922878+00:00 · 5 min read
Your Doctor Used This Company to Store Your Records. Hackers Took 9.5 Million of Them.
2026-09-02T08:09:38.315513+00:00 · 5 min read

Stay invisible. Follow @hack_decoded