FRIDAY, SEPTEMBER 4, 2026|No. 13819
Technology · Security

Massive Data Breach Exposes Over 153 Million Driver's Licenses

A newly discovered data breach has made over 153 million scanned driver's licenses available on the dark web, raising significant privacy concerns.

A digital representation of a driver's license with a padlock icon, symbolizing data security.
A digital representation of a driver's license with a padlock icon, symbolizing data security. · Photo by FlyD on Unsplash
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
0 countries
Related coverage

Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.

from the age-verification-is-another-phrase-for-privacy-breach dept

Thu, Sep 3rd 2026 10:57am - Mike Masnick

From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.

This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database.

There is no safe age verification. There is no age verification that doesn’t put people at risk.

Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches.

The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web:

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary.

That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.

So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned.

Yiiiiiikes.

And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed:

The IDScan.net Trust Center webpage features a security review banner, a search bar, sections for trust and compliance certifications, and a grid of logos from trusted partner organizations.

That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page.

But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records.

And it appears no one internally at the company noticed.

As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system:

The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies. A table titled "Categories" lists various types of identification documents and the number of records associated with each. There are over 153 million drivers licenses.The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale:

A webpage from the NEXUS Identity Document Database shows a locked Minnesota driver's license record for Peter Heg******, featuring a portrait photo of Hegseth and redacted personal details with a "Purchase Record" button at the bottom.

A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license.

Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing.

Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage:

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.

You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems.

Filed Under: age assurance, age verification, data breach, hackers, privacy

Companies: hertz, idscan.net

Short Link - right-click to copyEmail thisReddit This!TweetShare on FacebookShare on LinkedIn

21 Comments Leave a Comment


Comments on “Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.”

Subscribe: RSSLeave a comment

  • Filter comments in by Time
  • Filter comments as Threaded
  • Filter only comments rated Insightful
  • Filter only comments rated funny
  • Filter only comments that are Unread

21 Comments Collapse all replies

This comment is new since your last visit.

Am I the only person left in the entire world who’s old enough to remember the 1990s?

Way back, every so oft, some idiot would announce an urgent need for an Internet Driver’s License for the Information Superhighway kind of online identity scheme to stop crime, protect children, etc., etc., blah, blah, blah. If they were a clueless offline politician, the Internet laughed at them. If they were online, the Internet flamed them to a cinder—and then laughed at them.

Maybe the Internet had good reasons? Lots of good reasons? Like, I dunno, it’s stupid and inherently doomed to disaster? (/me checks news…) Among other reasons, like maybe freedom?

“Age verification” is only an Internet Driver’s License repackaged with ageist propaganda, just like “app-store” locked-down “devices” connected to the “cloud” are only 1990s failed “thin-client” and 1960s failed “utility computing”. 🄯 impurify.

This comment is new since your last visit.

Regular readers of Techdirt aren’t surprised by this revelation. You predicted exactly this…

This comment is new since your last visit.

Every politician behind KOSA and other age verification schemes/scams needs to have their IDs publicly shown like Heg

This comment is new since your last visit.

“Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit.”

In my state, they’re also used as (one form of) proof of identity to register to vote. This is particularly helpful to people who aren’t sure which district they live in, partly because the boundaries are so gerrymandered, and partly because the boundaries have been occasionally redrawn. The local registration process uses (local) accurate and updated maps to assign people to the right district, and they use a crosscheck to verify it.

So this leak — if it’s a leak and not intentional — comes at a critical time, when efforts to shut down the November mid-term elections and suppress the vote are in full gear. Watch for this to be used as a rationale to postpone elections until everyone is forced to get a new driver’s license or something along those lines, because the GOP is increasingly desperate and determined to end representative democracy — or any semblance of it — in the United States.

Beyond that: it’s not just this data. It’s how this data can be correlated with other data/metadata that’s out there and used to build alarmingly comprehensive and dangerous databases on people. This doesn’t require AI, only routine data science techniques, sufficient storage, memory, and CPU, and some time. You can download the tools to do this, the tutorials and books on how to use them, and so even if you’re new to the field, you can probably do something productive — and dangerous — without too much trouble.

This comment is new since your last visit.

Threaded [2]

Don’t give the bastards new excuses!!

This comment is new since your last visit.

Okay, sure, there’s great harm to the public, but have you considered that there’s a lot of lobbying money to be made by supporting spinning up a new industry out of legislation? Without it, the congresscritters will have to settle for having their second gold plated yacht built without platinum highlights. They’ll be the laughingstock of the club!

This comment is new since your last visit.

I think it’s worth keeping in mind that this happened because identity data is a high value target, and not just that the system breached was setup by boneheads (though there’s a solid chance that in the coming days and weeks, we’ll find out that they are in fact boneheads).

Look at the amounts that the hackers wanted: $100 per ID probably meant that they were making enough money for the juice to be worth a really difficult squeeze.

Keep that in mind during the next push for identification laws, when you see claims that “the next company will do better next time”

This comment is new since your last visit.

Threaded [2]

not just that the system breached was setup by boneheads (though there’s a solid chance that in the coming days and weeks, we’ll find out that they are in fact boneheads)

If it wasn’t in Louisiana, I might consider this for a minute. But the entire Fifth Circuit, as a region, exists to cut corners and blame others for it.

This comment is new since your last visit.

Threaded [2]

I’d argue something differently.

It happened because it is not profitable to give a shit about security. Any fine or punishment will be much smaller than the cost of doing it well.

This comment is new since your last visit.

I’m shocked! Oh wait, no. That’s exactly why I’m refused completely.

This comment is new since your last visit.

Only reason for someone to set up shop in Louisiana is to hire morons they barely have to pay.

This comment is new since your last visit.

When someone, Some company, Some TV Evangelist, ANY Person of Company says

TRUST.

My cellphone company has suggested 2 apps to HELP kill Spam calls. I was upto 50 per day.

After 2 months it went down, and at 5 months its at about 20.

At 12:25PM, My phone(on do not disturb) had gotten 10 Calls.

This comment is new since your last visit.

Threaded [2]

When someone, Some company, Some TV Evangelist, ANY Person of Company says TRUST.

A trusted system is one whose failure will fuck you over.

This comment is new since your last visit.

I don’t know what it’s like elsewhere, but up here in Canada, age verification software is sold as having “industry standard” protection of people’s personal information. This is what that industry standard delivers. I’d say to those talking up “industry standard” privacy, “not good enough.”

This comment is new since your last visit.

Can we all agree that Clarence Thomas is an idiot for claiming in Free Speech Coalition v. Paxton that ID verification is just an “incidental” burden for accessing speech??

I wonder how the justices behind that ruling would feel about their data being in one of these leaks…

This comment is new since your last visit.

Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial.

We’ve been living with data breaches of various organizations (DMVs, credit companies, the federal government etc) for well over the past decade. I don’t think people are in denial. They’ve just accepted that’s part of modern life. And the examples here prove it, with stuff like Hertz. This isn’t the first breach, it won’t be the last.

Stuff like age verification for social media is new, but needing an ID to rent a car (in their ancient systems) has been a thing since forever. And comes with the same risks.

Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about.

The problem is the other direction, I think. As long as things like driver’s licenses exist, you’re going to be at risk. To be honest, personally the fact that my driver’s license (and social security, etc) is already out there from 30 other breaches is certainly a factor in muting my alarm. What’s one more marginal vector? I’ve never even given Equifax anything to begin with.

Anyone claiming it’s perfectly safe, is perfectly safe to ignore. There’s no such thing as perfect safety (and even if age verification didn’t exist, it still wouldn’t be perfectly safe, either). It’s all just gradients of more risk or less risk.

At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.

The problem is, you’ll have people who think it’s not needless, and that the risk is worth it. It’s not premised entirely on being perfectly safe. And then you’re back to square one of the underlying argument.

This comment is new since your last visit.

Threaded [2]

You are entirely missing the point which is why make it easier for criminals to acquire PII while only providing downsides for people?

This comment is new since your last visit.

Threaded [3]

You are entirely missing the point which is why make it easier for criminals to acquire PII while only providing downsides for people?

I’m not missing that point, I’m literally saying the article should make that point more directly instead of trying to contrast it with perfect safety/denial.

This comment is new since your last visit.

Threaded [2]

The problem is, you’ll have people who think it’s not needless, and that the risk is worth it.

Those people are sociopaths and need to be thrown out, not caved to.

This comment is new since your last visit.

Threaded [3]

Right, but if we want to throw them out, that means convincing enough voters to throw them out. It’s not enough to not cave, you have to actually beat them.

I don’t think voters are voting for these sociopaths because they’re in denial that privacy risks exist or because they’re falling for the perfectly safe PR, given that one of these breaches happens every few months. At this point pretty much literally all of them have personally had their data leaked and privacy violated at some point.

This comment is new since your last visit.

As an AC said, drivers’ licenses are probably the most common form of ID use for voting.

This breach has been apparently been happening in real time for over a year without the company even knowing about it? That is a bit hard to believe. Kind of sounds like it might be an inside job.

Who has been President for over a year, and constantly screamed about voter fraud, and often joked(?) about a third term? Is this a coincidence?

Think about all the recently gerrymandered districts, and all the removal of polling places.

Throw in the USPS mail-in ballot EO, and what the “whistleblower” has said about what a shit-show that whole thing will become. This is starting to look like a staged kayfabe situation, too.

Given the backdrop, and the current situation with the mid-term elections, and all the hand-wringing and screaming and whatnot about voter fraud, the timing of the long-term breach, and the timing of its revelation, seem almost a little too custom made as a (another?) potentially “plausible” reason to cancel or invalidate the upcoming election.

Maybe I’m just cynical, but it looks like a lot of the pieces of a very ugly and scary puzzle are starting to fit together.


Add Your Comment Cancel reply

Your email address will not be published.Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Name

Email

Subscribe to the Techdirt Daily newsletter

URL

Subject

Comment *

Comment Options:

Use markdown.Use plain text.

Make this the First Word or Last Word.No thanks.( get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Notify me of follow-up comments by email.

Notify me of new posts by email.

Δ

Daily Deal: Babbel Language Learning (All Languages)

Working With ICE Is So Toxic, ICE Is Now Offering Liability Insurance To Local Police Officers

Follow Techdirt

Follow us on BlueskyBecome a fan on FacebookSubscribe to our RSS FeedSubscribe to our Podcast

Techdirt Daily Newsletter

Subscribe to Our Newsletter

Please leave this field empty

Get all our posts in your inbox with the Techdirt Daily Newsletter!

We don’t spam. Read our privacy policy for more info.

Check your inbox or spam folder to confirm your subscription.

Ctrl-Alt-Speech

Podcast Episode

Audio Player

00:00

00:00 | 34:54

Ctrl-Alt-Speech

Move Fast and Settle Things

Aug 28, 2026Season 1Episode 118

Mike Masnick & Ben Whitelaw

Become a Ctrl-Alt-Speech supporter to get extended episodes of the podcast plus the chance to submit stories for us to cover.

In this week's episode, Mike and Ben cover:

And in the extended episode for Patreon supporters, they cover:

Our fun links this week include a new table format for food recipes and Rainbolt’s tear-jerking Geoguessr video.

If you’re already a Patreon supporter, you can get the extended episode on Patreon.

Follow us on Instagram, YouTube, and Bluesky.

Ctrl-Alt-Speech is the podcast where we make sense of the major debates shaping online speech, platform power, content moderation and the future of the internet. It’s co-hosted by Mike Masnick ( Techdirt) and Ben Whitelaw ( Everything in Moderation).

Share Episode

Share on Facebook Share on Twitter Share on LinkedIn Download

Subscribe

Apple PodcastsSpotifyYouTubeAmazon MusicPodcast IndexCastboxOvercastPocket CastsPodcast AddictDeezerListen NotesPodchaserPlayer FMCastroGoodpodsTrueFansRSS Feed

Buzzsprout

Episode ArtworkMove Fast and Settle Things34:54 Episode ArtworkSchool of Hard Blocks42:12 Episode ArtworkWatermark My Words41:17 Episode ArtworkIn the Modi for Takedowns37:33 Episode ArtworkZuck Starts Throwing His Weights Around38:24 Episode ArtworkLive at TrustCon 202656:32 Episode ArtworkSpotlight: PwC’s Dan Hays on the future of Trust & Safety39:20 Episode ArtworkPutting Some Meat On The Bans52:14 Episode ArtworkSell Me Lies, Sell Me Sweet Meta Lies36:41 Episode ArtworkMaking the Best of a Ban Situation47:10 Episode ArtworkTeaser: The Ctrl-Alt-Speech Reading List14:38 Episode ArtworkClose Your Apps and Think of England44:30 Episode ArtworkCupertino d'État37:57 Episode ArtworkGenerous to a Default42:54 Episode ArtworkDeus vs. Machina39:03 Episode ArtworkMessage in a Bottleneck54:20 Episode ArtworkThe Human Element in the Room51:24 Episode ArtworkAge Against the Machine52:31 Episode ArtworkCelebrating 100 Episodes & Launching Our Patreon29:56 Episode ArtworkThe Silence of the LLMs52:27 Episode ArtworkHoney, I Shrunk the Kids’ Internet51:12 Episode ArtworkAge Old Questions50:31 Episode ArtworkFor Meta or Worse53:09 Episode ArtworkMoney for Nothing and Clicks for a Fee52:08 Episode ArtworkWriting Some Wrongs52:29

A weekly news podcast from

Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »

Essential Reading

The Techdirt Greenhouse

Read the latest posts:

Read All »


Trending Posts

Techdirt Deals

Microsoft Windows 11 Pro

Buy Now\ $199.00

Microsoft Windows 11 Pro

Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...

Become an Insider!

Recent Stories

## Friday
05:25Tom Cruise Parrots Paramount's Empty Merger Promises Because He Loves His 'Hollywood Family' (0)
## Thursday
20:04Court Tells HHS To Stop Using AI To Cite Fake Studies, Or Willfully Misinterpret Others In Grant Solicitations (0)
15:19Colorado Sees First Lawsuit Under 'Right To Repair' Law (1)
13:04Working With ICE Is So Toxic, ICE Is Now Offering Liability Insurance To Local Police Officers (2)
10:57Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year. (21)
10:52Daily Deal: Babbel Language Learning (All Languages) (0)
09:30DOJ Issues Memo Saying There's Nothing Illegal About The Military Arresting Migrants (3)
05:24Apple, Google Pathetically Buckle To Trump's Dim And Lazy Effort To Rename Lake Ontario (29)
## Wednesday
20:03Sony Tells Courts Any 'Reasonable Customer' Knows Digital Purchases Are Actually Licenses (22)
15:17Meta's $17 Billion Settlement Is A Bad Deal For Teens And All Social Media Users (7)
Morearrow

×

Email This Story

This feature is only available to registered users.

You can register here or sign in to use it.

Tools & Services

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →