Security1 publisher2 min readPublished
Four class actions hit IDScan.net over the 153 million licences Krebs linked to it
The vendor runs more than 21 million document checks a month for clients including Hertz, GameStop and FedEx, and the plaintiffs suing in New Orleans infer their own exposure from a car rental because nobody has told them otherwise.
The Watch · Security desk
What happened
- Brian Krebs reported on Tuesday that identity-verification vendor IDScan.net appears to be the source of Nexus, a dark web site claiming to sell access to over 153 million US and Canadian driver's licences.
- Four class actions were filed on Wednesday in the US District Court for the Eastern District of Louisiana by plaintiffs in California, Florida, Georgia and Louisiana who suspect they used IDScan's services.
- All four suits allege IDScan likely breached FTC guidelines on protecting sensitive data, and ask the court for damages and an order compelling stronger security.
- IDScan.net, based in New Orleans, says it runs more than 21 million verifications a month to help clients spot forged documents, driver's licences among them.
- The FBI told PCMag it is looking into the incident and would say no more, while IDScan.net did not answer a request for comment and the Nexus site has gone dark.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Exposure here was created by procurement, not by consumer choice: anyone whose licence was scanned at a Hertz, GameStop or FedEx counter is reachable through a vendor they never contracted with.
- constraint Nobody downstream can scope their own loss, because the record of which checks ran sits with IDScan; the plaintiffs are reduced to pleading a rental date as a proxy for being in the set.
- precedent Suing the verification processor within a day of a journalist's report, before any confirmed breach, points liability at the outsourced layer rather than the brand that collected the document.
- contradiction The only public link between IDScan and the 153 million records is Krebs's reporting; the company is silent and the FBI is noncommittal, so the party that could confirm scope has not.
A pleading that opens with a car rental is a pleading written blind. The plaintiff does not allege that his licence record was in the set advertised on Nexus. He alleges that on September 18, 2025 he rented a car through Hertz in that district, and that Hertz is a client of IDScan [8]. Another plaintiff arrives by way of Hertz-owned Thrifty [9]. All four say only that they suspect they used IDScan's services at some point [7].
That is the shape of third-party proofing. The consumer hands a licence to a rental clerk; the scan is checked by a company the consumer never chose and cannot name from any receipt. The client list is the only handle anyone downstream has, and PCMag reports that list includes Hertz, GameStop and FedEx [3].
Scale check, using the only two numbers on the table. IDScan says it performs more than 21 million verifications a month [4]. Divide the 153 million records the seller advertised by 21 million and you get about 7.3 months of the vendor's own stated throughput [14], against roughly 252 million checks in a year [15]. That comparison doesn't pin the set to seven months of IDScan's own scans; it shows a set this size is unremarkable next to what this one vendor moves, which is the reason a single verification supplier is worth an attacker's time at all.
IDScan's stated job is catching fake documents, licences included [4]. Bulk genuine licence data is the reference material for building documents that survive a clerk's glance. PCMag's account does not say which fields, or whether document images, are in the advertised records [16], and that gap is the difference between a nuisance and a working forgery kit.
Krebs reported on Tuesday that IDScan.net appears to be the source [5]. The company has offered no confirmation, has not responded to PCMag [11], and the FBI has said only that it is looking into the incident [12]. The Nexus site is down [6]; that closes the storefront, not the underlying question. Until IDScan states which checks it ran and for whom, its clients are answering for a data set they cannot inventory.
What to watch
- Whether IDScan.net confirms or denies a breach, and whether it tells clients and state attorneys general which verification records were touched.
- Whether Hertz, GameStop or FedEx are added as defendants, or issue notifications of their own to customers whose licences they scanned.
- Whether the 153 million-record set resurfaces on a new site or in private sales, and whether anyone samples it to establish which fields it actually carries.