Security1 publisher3 min readPublished
KrebsOnSecurity traced the records toward New Orleans ID-verification vendor IDScan after nine people matched timestamps on their stolen scans to the day they handed a license over. The FBI's New Orleans field office says it is looking into the incident.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
IDScan's own figures put its technology performing more than 21 million identity verifications a month across more than 20,000 locations, according to KrebsOnSecurity [11]. Set that against the 153 million licenses advertised on Exploit [2] and the listing amounts to roughly seven months of that throughput [17]. Whatever the source turns out to be, a corpus that size is retained imagery, kept long after the verification it was collected for returned its yes or no.
The infrared and ultraviolet frames carry something a license number does not: a picture of how a genuine document behaves under lights a forger would otherwise have to guess at [3]. Fraudulent-ID detection is one of the things IDScan sells [6]. A library of authentic captures, front and back, in the same channels a scanner reads, is useful to precisely the people those checks exist to stop.
What is public is the Exploit listing [2], the FBI New Orleans field office saying Thursday that it is looking into the incident and declining further detail [13], and IDScan marketing and operations executive Jillian Kossman telling Krebs the company is investigating and cannot yet say more [15]. Also public is that Krebs was added to a call with roughly half a dozen FBI agents, including senior cyber division officials, who disclosed that the New Orleans office had opened a case [14].
The inference, not yet confirmed by any authority, is that the data came out of IDScan [4]. NOLA.com reports investigators appear to be examining that question [5]. The evidence is correlation, and the correlation is specific. Krebs found people in the database tied to businesses running IDScan technology [7]. He and his mother turned up seconds apart after handing their licenses to the same Hertz representative [9]. Another researcher found his record after a Las Vegas trip that included the dispensary Planet 13, an IDScan customer [10]. Neither the breach date nor the entry vector is public.
Zach Edwards, whose own license is in the set, told NOLA.com that no driver's license breach has reached this scale and that the actors look both sophisticated and financially motivated, which he reads as a bad sign for stopping the data spreading further [16]. The financial motive is the operative half of that. Data sold to buyers moves by design.
What anyone downstream actually controls is retention and reliance: how long a verification vendor holds the images after it answers the question, and whether a document scan is allowed to stand alone in an account-recovery or age-gate decision. Licenses get reissued slowly, and the captured image of a card already presented stays good for as long as the card does.
Ranked by verification strength, evidence, and original report placement.
KrebsOnSecurity reports the dark-web service Nexus advertised access to more than 153 million driver's licenses from the U.S. and Canada, along with more than 10 million other identification cards, more than 3 million travel documents or international IDs and at least 579,000 medical cards, on the Russian cybercrime forum Exploit.
According to KrebsOnSecurity the breach may be connected to a New Orleans-based identity-verification company whose technology businesses use to scan and authenticate government-issued IDs; authorities have not confirmed the connection.
NOLA.com reports that investigators appear to be examining whether the stolen information came from IDScan, a New Orleans company that provides identity-verification technology.
Zach Edwards, a cybersecurity researcher whose own license appeared in the database, told NOLA.com there has never been a breach of driver's license data at this scale and that the threat actors seem both sophisticated and financially motivated, which he called a bad sign for efforts to prevent the data spreading further.
The FBI is investigating how scans of more than 150 million U.S. and Canadian driver's licenses and other identification documents ended up for sale on the dark web, according to reports.
Some records in the Nexus database included multiple images of the front and back of a license, as well as infrared and ultraviolet scans and timestamps showing when the documents were scanned.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Careful relay of one investigation
The strongest material here is Krebs's timestamp matching: nine people placing a stolen scan on the day they handed a licence over, and two family members appearing seconds apart after one Hertz transaction. That is a real method and it points somewhere specific. Everything else is second-hand through WWL, whose own contribution is a line saying it has asked IDScan for comment, and the record counts are lifted from what the seller advertised rather than from anything an investigator has enumerated.
Footprint sized by the vendor's own numbers
What can actually be counted: one listing on Exploit, a vendor claiming 21 million verifications a month across more than 20,000 locations, four named brands on its site, and a service that went dark after publication. Set the advertised 153 million licences against that monthly rate and it works out to about seven months of scanning, which suggests retained history rather than a snapshot. Nobody has published how many people were affected or notified any of them.
Hedged prose, unhedged number
WWL hedges where it should. The headline says 'may', the IDScan link is labelled unconfirmed twice, and the closing line concedes that nobody knows how the data was taken or how many people are in it. The strain is arithmetical: 153 million comes from a criminal seller's pitch, and Edwards's 'never been a breach of drivers license data at this scale' measures against that same unverified figure, so the most quotable line in the story rests on the least verified one.
Every party has a reason to shade it
The counts come from a vendor of stolen data whose price depends on volume. IDScan, facing a federal inquiry, said it was investigating and would share nothing further, while thanking the reporter for the information he had passed on. The FBI confirmed an open case to Krebs on a call and gave the local press one sentence. Krebs's own reporting is the origin of the story, the vendor link and the pressure that took the service offline, and Yahoo's role is republication rather than verification.
Enough to act on, short of proof
Two facts are firm: a federal case is open, and a database of licence scans existed with timestamps that people recognised. Beyond that the reporting is one investigator deep, the causal chain to IDScan rests on circumstantial matching, and the two parties who could settle it are both declining to. Treat the vendor link as a strong lead and the 153 million as a claim awaiting a count.
security
Nexus sells 153 million license scans that Krebs traces to a Louisiana IDV vendor7 publishers
invest
Krebs traces infrared license captures on a dark web market to a vendor scanning 21 million IDs a month1 publisher
product
World open-sources ProveKit to keep age checks on the user's own phone1 publisher
product
Krebs traced 153 million leaked driver's licence scans to a single Louisiana ID verifier1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026