Product1 distinct publisher3 min readPublished
IDScan.net sells the compliance layer behind age and ID checks at thousands of dispensaries and at Hertz, and Techdirt notes its trust page stayed up for days after the dark web store opened. The FBI is now asking where the images came from.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
You hand a licence across a counter so a clerk can check one number on it. The scanner beeps, the screen turns green, the card comes back. What Brian Krebs describes is that same moment producing an image that ends up in a catalogue somebody else sells access to [1][2].
The 400,000 records added on the day the store was exposed are the more useful figure, because they measure rate rather than volume [4]. Divide 153 million by 400,000 and the corpus takes about 383 days to assemble at that pace [1]. Four hundred thousand a day is roughly 4.6 images a second [2]. That tempo tracks ordinary transaction traffic, which is part of why, according to Techdirt, nobody inside the company appears to have noticed [9].
Then there is the paperwork. IDScan.net's Trust Center page, which explains how the company protects data, maintains system reliability and earns the confidence of customers and their users, was still live days after the breach became public [7]. Techdirt notes the claims of GDPR and CCPA compliance sitting alongside it [8]. Every artifact a procurement reviewer knows how to ask for existed, and each was accurate about the control it described. But none of it was built to see a feed.
Separate the thing being sold from the thing being done. The company sells an assertion about age; what actually happens is image capture, and an image of a driver's licence is a reusable identity document, which is why the buyers on this store are identity thieves rather than bouncers [1]. Krebs interviewed people whose licences are for sale and matched the date each record appeared against their own calendars, surfacing IDs handed over at a rental counter and at a pot dispensary [10][5]. Those people never chose the vendor and have nowhere to send a question.
Teams tend to assume the scan is a transient step: the licence goes back in the wallet and the check is over. The archive tells a different story. The check produced an object with a long life and a resale value.
Two questions get further than a questionnaire. First, twenty-four hours after a successful check, what artifact still exists and on whose disk. Second, if a copy of every artifact left continuously for thirteen months, which log line would show it and whose job is reading that line. Put retention on one axis and detectability on the other, and only one quadrant is comfortable to sign: no image retained, plus a monitored egress path. A vendor answering the first question with "nothing" has removed the liability rather than insured it.
The tradeoff belongs in the same paragraph as the recommendation. A verifier that keeps no image cannot re-run a disputed check six months later, and some auditors and insurers want that record to exist. That is a cost you can size and argue about at signing time.
Ranked by verification strength, evidence, and original report placement.
A new identity theft service launched on the dark web is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada, as reported by Brian Krebs (KrebsOnSecurity) and relayed by Techdirt.
Based on interviews with individuals whose licenses are available for purchase, the service appears to be siphoning images collected by a widely-used identity verification company based in Louisiana.
Krebs checked with a number of people who were in the database and, by comparing the date they were added against their calendars, found examples of people who had shared their ID at places including a rental car company and a pot dispensary.
Techdirt describes the breach as a long-standing ongoing leak in which records and ID scans were swiped in real time by the hackers over the course of more than a year.
The New Orleans field office of the FBI launched an official inquiry into the source of the images.
On the day the breach was revealed, and right before the site was taken down, the service added another 400,000 records to its available database.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Nexus sells 153 million license scans that Krebs traces to a Louisiana IDV vendor5 distinct publishers
product
World open-sources ProveKit to keep age checks on the user's own phone1 distinct publisher
product
Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name1 distinct publisher
invest
Tariff refunds are landing, and where the cash stops tells you who has pricing power1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Everything at one remove
Strip this back and the chain is short: Techdirt reading Brian Krebs, Krebs reading a criminal sales post and spot-checking a handful of victims' calendars. The tracing to IDScan.net is hedged even in the wording Techdirt quotes — the service 'appears to be siphoning' the images. What Techdirt saw for itself is narrower but real: the trust and compliance pages still standing days later. No company response, no forensic timeline, no second newsroom.
The pipeline is genuinely wide
Whatever remains unproven about the breach, the deployment is not speculative: ID checks at thousands of dispensaries plus Hertz, FedEx and Target, and age verification sold to technology companies. That is why 153 million is a plausible order of magnitude at all — the scans exist because ordinary counters generate them daily. The customer counts come from one publisher's characterisation and no vendor disclosure, which keeps this short of a firm figure.
Conclusion arrives before the confirmation
Techdirt's thesis — no age verification can be safe — is broader than what this one incident, reported once and unanswered, can carry. The scale figure is the sellers' advertisement, the duration is their boast, and 'nobody noticed' is an inference. The gap is real but modest, because the underlying observations are specific and the arithmetic holds: 400,000 a day is about 4.6 licences a second, and 153 million at that pace is roughly the year the thieves claim.
Nobody in the frame is disinterested
The vendor sells the compliance layer that age verification mandates create and has written approvingly of KOSA, so its security reputation is its market. The thieves advertising 153 million records profit from sounding bigger than they are. And Techdirt files this under a department name that states the argument before the reporting begins. None of that makes the account wrong; it does mean each number has an interested party behind it.
Act on the direction, wait on the detail
Two things anchor this: a federal field office has opened an inquiry, and the company's trust page was verifiably still live days on. That is enough to take the story seriously. It is not enough to fix the record — the total, the timeline and the entry point all await a source that is neither the thieves nor an outlet quoting them.