IDScan.net, the Louisiana company behind the ID scanners at Hertz counters and cannabis dispensaries, has confirmed that someone got into its cloud and copied customer data. The confirmation came after Brian Krebs reported on September 2 that a service called Nexus was selling search access to more than 153 million U.S. and Canadian driver's license scans. The seller claimed they had been pulling new records for over a year. Krebs watched roughly 400,000 new licenses appear in a single day.
That last number is the story. A dump is a snapshot. This was a tap.
What was on the shelf
Per Krebs's reporting, each record in Nexus held six image files: front and back of the license as a plain scan, again under infrared, and again under ultraviolet. Timestamps were appended to the filenames. Krebs matched those timestamps against the travel calendars of people whose licenses he found, including his own and his mother's, scanned at the same Hertz counter at the same minute. Another subject's timestamp matched a visit to Planet13, a Las Vegas dispensary that announced an exclusive deal with IDScan.net in 2022. That is how the trail led to one vendor.
Nexus also advertised more than 10 million other ID cards, 3 million travel documents, and 579,000 medical cards. The FBI's New Orleans field office opened an investigation after Krebs found Defense Secretary Pete Hegseth's license in the database. The site went dark within hours of the article going up. The data did not.
IDScan.net's own notice says it learned on or around September 1 that data "may have been accessed without authorization" and that the exposed information includes full names and driver's license or other government ID numbers. It does not mention images. It does not put a number on the scope. TechCrunch's September 10 report says the company holds more than 150 million license records and that the FBI is still investigating. Nine class actions were filed in the Eastern District of Louisiana between September 2 and 4, before the company had said anything at all.
The scanner was the product. The archive was the liability.
IDScan.net processes about 21 million verifications a month across more than 20,000 locations, by its own marketing. The job at each of those locations is a yes or a no. The scanner has to answer two questions: is the license real, and is the holder old enough. A bouncer needs that answer for about four seconds. A rental counter needs it until the car comes back.
Nobody at a dispensary needs the ultraviolet layer of a customer's license sitting in a Louisiana cloud eighteen months later. But the vendor kept it, for everyone, in one place, indexed and searchable. Once you build that, the breach is a question of when.
The infrared and ultraviolet scans are the part that should bother people who work in fraud. Those layers are what scanners use to tell a real license from a print. A library of 153 million captures under infrared and ultraviolet is a template set for making fakes that pass the same scanners. Every forger who bought a Nexus subscription now has it. As Seemant Sehgal of BreachLock told Security Magazine, none of the fields on a license can be changed, so the exposure follows each person for life.
I've run infrastructure for 25 years, and the pattern here is one I've seen in smaller form dozens of times. A system collects something because collecting is easy and the data might be useful later. Retention defaults to forever because deleting requires a decision and keeping requires none. Then the store becomes the most valuable thing on the network, and the security around it is whatever the original engineer set up for a scratch bucket.
A year of reads that nobody noticed
The seller's claim of a year of continuous exfiltration has not been confirmed by IDScan.net. But 400,000 records added in 24 hours lines up with the company's own volume of 21 million checks a month, which works out to about 700,000 a day. Someone was reading more than half of the live intake and nobody's dashboard turned red.
That says something about monitoring. Egress from the store that holds your most sensitive data should be the most watched metric in the company. If a single principal is reading hundreds of thousands of image sets a day, that is either your own batch job or your worst day. You should be able to tell which within the hour.
It also says something about trust badges. IDScan.net's site carried the usual compliance logos, a point Techdirt made on September 3. A certification tells you an auditor looked at a policy document. It does not tell you what the retention setting is on the bucket, or whether anyone reads the access logs.
What to ask any vendor you hand IDs to
If you run a business that scans IDs, or you build the integrations that do, you are the one your customers will blame. Hertz, Target, and FedEx were named across the coverage, and IDScan.net was never the brand on the counter. Questions I would put in writing to a verification vendor this week:
- What do you store after the check returns, and for how long? "The result and a timestamp" is the right answer for most use cases.
- Can I set retention to zero per account, and does that setting cover the raw images as well as the parsed fields?
- Who can query stored scans, from where, and what alerts fire on bulk reads?
- When did you last test whether one compromised credential could enumerate every account's data?
Most compliance rules that call for an age or identity check want proof that the check happened. A log entry with a hash proves that as well as a photo does, and a stolen log entry is worth nothing to anyone. Where the law forces you to retain the image, keep it in your own tenant under your own keys, and limit the vendor to the verification call.
I don't expect IDScan.net to survive this as an independent company. Nine lawsuits in three days, a Cabinet secretary in the dataset, and an FBI case in its home city. The scanning hardware will get bought by someone. The customer contracts will get rewritten with retention clauses that should have been in them in 2022. And the 153 million scans will circulate for years, because the site that sold them went offline and the buyers did not.