Brian Krebs found his own Virginia driver’s license offered as a free sample in a dark web sales thread, then found his mother’s scan a few seconds away in the same index. Those two timestamps turned a vague criminal listing into the IDScan.net breach, because he and his mother handed their licenses to the same Hertz agent, at the same counter, in the same minute.

The service calls itself Nexus. It surfaced on the Russian cybercrime forum Exploit on 31 August, advertising more than 153 million driver’s licenses from people in the United States and Canada, along with over 10 million identification cards, roughly three million travel documents, and 579,000 medical cards. Criminal sales copy usually inflates, so the arithmetic matters: a blank search returned about 11.5 million pages, with roughly 15 results per page. The claim holds up against its own index. Canada supplies around 1.1 million of those records, with Ontario alone accounting for 473,673.

The figure I cannot stop looking at is not 153 million. It is the 400,000 records that appeared in the listing during a single 24-hour stretch while Krebs was still reporting the story. A stolen database is a photograph of a bad day. This was a live feed, and the seller claimed to have been pulling from it for over a year.

Attribution came from the light, not the metadata. Every full record carries six image files: front and back of the license under ordinary light, then the same pair in infrared, then again in ultraviolet. Nothing in a consumer phone produces that. Commercial identity terminals do, and IDScan.net’s own documentation describes scanning IDs under infrared and ultraviolet as part of its fraud check. The New Orleans company says it processes more than 21 million verifications a month across upward of 20,000 locations, and its own trust page names Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment, plus more than a thousand marijuana dispensaries in 19 states.

Zach Edwards found his own license in there, stamped in the middle of his DEFCON trip. He never rented a car in Vegas. He showed ID at the TSA checkpoint, at the Aria, and at Planet13, and the dispensary was the only one of the three that definitely fed his license into a device. Planet13 signed an exclusive identity verification agreement with IDScan.net back in 2022. When nine volunteers confirm that their timestamps line up with a rental counter or a dispensary counter, not an airport, the pattern stops being circumstantial.

Krebs also found the license of the FBI’s assistant director in the listing, along with Defense Secretary Pete Hegseth’s. That is apparently what got him added to a conference call with half a dozen agents on 1 September, the same day the Bureau’s New Orleans field office opened a formal investigation into an apparent breach at IDScan.net. Nexus went dark shortly after publication, replaced with a one-line notice saying the service is no longer available. That is not a comfort. Anyone who wanted the index had roughly a day to pull it, and nobody outside the forum knows how many did.

IDScan.net has said only that it received information on 1 September suggesting data may have been exposed and that it is working urgently to validate that information and determine whether unauthorized access occurred. Standard early incident language, and I don’t blame them for it, but it means that right now nobody has confirmed a breach except the people selling the results of one.

Here is what actually bothers me about the IDScan.net breach, and it is not the volume. It is that none of the 153 million people in that index made a decision about IDScan.net. They made a decision about renting a car, or buying weed, or checking into a hotel. The vendor was invisible to them at the moment of the scan; it is invisible in the breach, and it will be invisible in whatever notification letter eventually arrives with a competitor’s logo at the top. Hertz’s customers cannot audit Hertz’s ID vendor. They did not know there was one.

Edwards made the point more sharply: this should stiffen the spine of anyone pushing back on online ID mandates. It is the same architecture that carried Chat Control through the European Parliament in July on a threshold technicality, and the same logic behind every age verification bill that treats “upload your license” as a solved problem. Every one of those mandates creates another third-party terminal, another retention window, another vendor nobody voted for. Verification systems have been failing upward for a while now. Eleven governments already had to warn employers that live video interviews no longer prove who is on the other end, and the answer being pushed everywhere is more document scanning, into more databases, at more counters.

Larry Baldwin at Cybera raised a piece of this I hadn’t thought about until I read his quote: people who cannot change their face. Domestic violence survivors, witness protection placements, anyone living under a new legal identity with the old photograph still attached to it. Credit fraud is recoverable in a way that being findable is not, and current image matching does not need a name to close that loop.

I am leaving the class action angle alone; that is a lawyer’s post, and there will be twenty of them by Friday. What I want to know is narrower: which of those named enterprise clients sends individual notices, and under which state’s breach law, given that the company holding the data has not conceded a breach happened. That part will quietly decide whether 153 million people ever find out they were in it.

We have spent two years arguing about who gets to watch us, and I have written my share of it, from France rewriting its surveillance law seven times in a decade to cinemas and courts writing their own smart glasses rules because nobody in government would. This one is dumber than any of that. Nobody had to compel anything. A rental agent held my hypothetical license behind a counter for four minutes, ran it through a box under three kinds of light, and a year later it is in a searchable index with a date attached. Freeze your credit. It will not do much about the photograph.