TodayFriday, September 04, 2026

IDScan Data Breach Puts 153 Million Driver’s Licenses Up for Sale on the Dark Web

The FBI is investigating IDScan after criminals advertised the Defense Secretary's driver's license to market a 153-million-record dark web sale.
September 4, 2026
Driver's license scan representing the IDScan data breach that exposed 153 million records to the dark web
Driver's license scans of the type processed by IDScan, the Louisiana-based identity verification firm at the center of the FBI investigation. [Image Source: Engadget]

WASHINGTON — The promotional pitch was hard to ignore. When a new dark web marketplace called Nexus launched this week to sell stolen identity records, its operators needed a marketing hook. They chose Pete Hegseth.

The U.S. Defense Secretary’s driver’s license scan, processed at some point during an ordinary prior transaction, appeared as a free sample advertisement on the Russian cybercrime forum Exploit, designed to draw buyers toward a catalog claiming 153 million other Americans and Canadians. That single detail reveals something specific about what went wrong: the same commercial identity verification system that handled the credentials of the nation’s top defense official handled those of everyone who rented a car, checked into a hotel, or walked into a casino in the last several years.

The FBI’s New Orleans field office has opened an investigation into IDScan, a Louisiana-based identity verification company, after cybersecurity journalist Brian Krebs reported Tuesday that digital scans of more than 153 million driver’s licenses had appeared for sale on the dark web. IDScan processes more than 21 million verifications per month for clients that include Hertz, Target, FedEx, Motorola, Jack Henry, and Caesars Entertainment.

The likely common thread for many victims: a rental car counter. Krebs found that a significant number of people whose data appeared in the breach had recently rented vehicles from Hertz, which uses IDScan’s platform to scan licenses during the checkout process. Renting from Hertz does not require knowingly sharing data with a third-party vendor, and most customers have no visibility into what happens to their license scan after it is processed. There is no opt-out. Scan your license to get the car keys, and your data enters a system that, according to the investigation now underway, may have been exposed to criminal access for an undetermined period.

The stolen archive was broader than driver’s licenses. The Nexus catalog included medical cards, employment records, and Canadian residence cards, together forming a comprehensive identity package for millions of people who had no meaningful way to know their documents had been digitized, stored, and potentially stolen. Most people hand over a license at a counter without knowing which vendor processes it, where that data lives, or what happens when that vendor is compromised, as Gizmodo reported in its investigation of the breach’s scope.

Target, named as an IDScan client, said it was not involved in the attack because it does not transmit guest data to IDScan. FedEx, Motorola, and Jack Henry had not publicly commented as of publication. IDScan itself has not issued a statement.

Digital identity verification illustrating how IDScan's breach exposed 153 million driver's license scans to the dark web
Digital identity checks like this one now carry systemic risk after the IDScan breach. [Image Source: Engadget]
The Nexus marketplace has since gone dark. Its login page now displays a notice that the platform is no longer available. Dark web marketplace closures rarely mean the underlying data disappears. Operators walk away, records migrate to other channels, and the people whose documents were copied have no reliable way to know what has been sold, to whom, or for what purpose.

For the millions of people who rented from Hertz, or used IDScan-connected services at Target or Caesars, there is no immediate recall. A driver’s license cannot be changed the way a password can. State DMVs do not routinely issue new license numbers following private-sector breaches. The practical options available, including credit freezes, identity monitoring services, and fraud alerts, address only the downstream consequences of the exposure rather than the exposure itself.

What makes this breach structurally different from a typical corporate data leak is the verification-chain problem it exposes. IDScan exists precisely to make identity confirmation more reliable and defensible. Businesses outsource ID scanning to specialized firms because they want accuracy, compliance coverage, and a higher standard of security. The breach inverts that proposition: the companies that trusted IDScan with their customers’ documents are now the conduit for a mass exposure they did not authorize and cannot contain. As Engadget reported, the verification infrastructure meant to protect identity became the mechanism for compromising it.

That verification gap connects to a broader pattern in how identity data fails at scale. A separate incident in 2025 produced one of the largest data leaks on record, demonstrating that identity infrastructure built for industrial throughput carries industrial-scale risk that ordinary users bear without knowledge or consent. The Eastern Herald also reported on FBI efforts targeting account hacking and sextortion, crimes that become significantly easier when verified photo ID data circulates on criminal markets.

What the investigation does not yet know: how long IDScan’s systems were exposed before Krebs’ report surfaced the breach publicly, the precise method of intrusion, and whether clients beyond Hertz were affected in materially different ways. IDScan has not confirmed the breach or provided any technical explanation. The FBI does not disclose findings from active investigations.

There are 153 million people whose driver’s license scans are now somewhere they should not be. Most of them will find out through a credit monitoring alert, if they find out at all. The Defense Secretary can pick up a secure phone. Everyone else waits.

Technology Desk

Technology Desk

The Technology Desk leads The Eastern Herald's coverage of consumer technology, online platforms, artificial intelligence, and internet policy.

Leave a Reply

Don't Miss