Product1 distinct publisher3 min readPublished
Brian Krebs reports a hacker selling searchable access to 153 million US and Canadian licences, with suspicion pointing at the vendor IDScan.net. Any age gate built on a document scan owns that exposure.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Handing a licence across a counter feels like showing something, not sending it. The reader beeps, the card comes back, and the customer's model of the event is that a person checked a birth date and moved on.
Teams buying that reader tell themselves a simple story: we verify age, we do not keep IDs. The plumbing tells a different one. A document gets scanned and parsed, a vendor returns a decision, and something derived from that document outlives the four seconds it took. For the suspicion Krebs raises to hold at all, data from scans like that had to sit somewhere after the check [6]. The seller's own pitch on the Russian-language forum Exploit describes more than a year of continuous collection into a private database [5].
The page count is the closest thing to an inventory anyone outside has. About 11.5 million pages at roughly 15 results each works out to something near 172.5 million records [1], around 13% more than the 153 million advertised [2]. That is why Krebs judged the seller likely not to be exaggerating [4]: the index is bigger than the sales copy. Pricing one cabinet secretary's licence at $100 [3] says the seller is charging by target, not by the record.
IDScan.net and the FBI did not immediately respond to PCMag, and Krebs says both are already investigating [9]. So the vendor link is suspicion with two data points behind it, not a confirmed disclosure, and PCMag's own framing stays conditional: the outlet called it, if real, one of the worst breaches in recent history [10]. The people who run the checkout do not get to wait for that resolution, because the customer email arrives before the incident report does.
A password can be rotated after a breach. A licence number and the face on a scan cannot be reissued the same way, so the remedy available to an affected customer is monitoring rather than repair, and that cost lands on them.
The grid worth running has two axes. First: does the check need the document, or only a claim derived from it, such as over 21 or name matches booking. Second: after the check, who holds the image, and for how long. A dispensary door or a game shop needs the claim. A rental desk handing over a car has a stronger argument that it needs identity. The expensive cell is a boolean requirement served by a document-retaining pipeline, where you carry the whole exposure of a government ID to answer yes or no.
The forcing function is narrower than a security review. What a company needs from the vendor is the retention period as it appears in the contract, plus a deletion record specific enough to paste into a reply to a named customer. If what comes back is a policy page, then the honest answer to that customer is that you do not know where their scan is, and the scanner at your counter is collecting on someone else's terms. The companies named on the client list [6] are working that out this week with counsel attached. Everyone with a smaller reader and the same plumbing is working it out through a support inbox.
Ranked by verification strength, evidence, and original report placement.
A hacker has been spotted trying to sell access to over 153 million driver's licenses from the US and Canada, including the IDs of US Defense Secretary Pete Hegseth and an FBI assistant director.
The hacker created a site called Nexus to offer the IDs; Krebs learned about the sales after the hacker offered him his own Virginia driver's license as a free sample.
The hacker offered Pete Hegseth's driver's license for $100.
Krebs wrote that a blank search in Nexus with no parameters entered returns approximately 11.5 million pages of results, with roughly 15 results displayed per page, and that the seller is likely not exaggerating the 153 million figure.
The hacker advertised Nexus on the Russian-language hacking forum Exploit, writing: "We have been continuously exfiltrating new data for over a year into our private database."
Cybersecurity researcher Zach Edwards found his own driver's license on Nexus and noted his ID had recently been scanned while visiting a Las Vegas marijuana dispensary operated by Planet 13, which has a partnership with IDScan.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
security
Twenty dollars a photo: the FBI's O'Hare affidavit is a fence-line problem, not a network one1 distinct publisher
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One relay, one investigator
Everything reaches the reader through a single chain: PCMag summarising Brian Krebs, who in turn worked from what the seller chose to show him. The strongest independent element is small and concrete — Krebs's blank search, and Edwards finding his own licence — while the load the story actually carries, that IDScan was breached, is labelled a suspicion by the only person who has looked.
Two named records, one traced door
Real-world confirmation runs to a handful of individuals: Krebs's licence, Hegseth's listing, and Edwards's record traced back to a dispensary scanner. That is enough to show the index is not fiction and enough to show how records got in, but nobody has published a victim count, a state-by-state footprint, or a single confirmed downstream fraud.
Severity asserted, cause assumed
Interestingly, the count is the part least likely to be inflated — Krebs's own arithmetic points above the advertised 153 million, not below. The stretch sits elsewhere: PCMag's 'one of the worst breaches in recent history' is conditional on the sales being genuine, and the IDScan attribution has hardened into the story's frame while remaining an informed guess with no vendor confirmation behind it.
The seller is the primary source
Follow who benefits from each number. The 153 million figure originates in a criminal sales pitch on Exploit, where a larger database commands a better price, and the free sample to a well-known journalist is marketing. On the other side, IDScan's silence is the cheapest available move for a vendor whose contracts depend on being trusted with licence images. PCMag sits in the middle, aggregating with a visible conditional.
Act on the exposure, not the culprit
Two different levels of certainty are tangled here. That a large searchable licence index existed and was for sale is well enough attested to act on; that IDScan is where it came from is not, and the site's disappearance means the easiest check is gone. Anyone scanning IDs at a counter can move on the first without waiting for the second.