Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.
from the age-verification-is-another-phrase-for-privacy-breach dept
Thu, Sep 3rd 2026 10:57am - Mike Masnick
From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.
This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database.
There is no safe age verification. There is no age verification that doesn’t put people at risk.
Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches.
The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web:
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.
Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary.
That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.
So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned.
Yiiiiiikes.
And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed:

That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page.
But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records.
And it appears no one internally at the company noticed.
As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system:
The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.
The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.
“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”
Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.
And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale:

A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license.
Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing.
Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage:
Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).
This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.
“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.
At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.
You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems.
Filed Under: age assurance, age verification, data breach, hackers, privacy
Companies: hertz, idscan.net
Short Link - right-click to copyEmail thisReddit This!TweetShare on FacebookShare on LinkedIn
Comments on “Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.”
Subscribe: RSSLeave a comment
- Filter comments in by Time
- Filter comments as Threaded
- Filter only comments rated Insightful
- Filter only comments rated funny
- Filter only comments that are Unread
21 Comments Collapse all replies
This comment is new since your last visit.
Am I the only person left in the entire world who’s old enough to remember the 1990s?
Way back, every so oft, some idiot would announce an urgent need for an Internet Driver’s License for the Information Superhighway kind of online identity scheme to stop crime, protect children, etc., etc., blah, blah, blah. If they were a clueless offline politician, the Internet laughed at them. If they were online, the Internet flamed them to a cinder—and then laughed at them.
Maybe the Internet had good reasons? Lots of good reasons? Like, I dunno, it’s stupid and inherently doomed to disaster? (/me checks news…) Among other reasons, like maybe freedom?
“Age verification” is only an Internet Driver’s License repackaged with ageist propaganda, just like “app-store” locked-down “devices” connected to the “cloud” are only 1990s failed “thin-client” and 1960s failed “utility computing”. 🄯 impurify.
This comment is new since your last visit.
Regular readers of Techdirt aren’t surprised by this revelation. You predicted exactly this…
This comment is new since your last visit.
Every politician behind KOSA and other age verification schemes/scams needs to have their IDs publicly shown like Heg
This comment is new since your last visit.
“Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit.”
In my state, they’re also used as (one form of) proof of identity to register to vote. This is particularly helpful to people who aren’t sure which district they live in, partly because the boundaries are so gerrymandered, and partly because the boundaries have been occasionally redrawn. The local registration process uses (local) accurate and updated maps to assign people to the right district, and they use a crosscheck to verify it.
So this leak — if it’s a leak and not intentional — comes at a critical time, when efforts to shut down the November mid-term elections and suppress the vote are in full gear. Watch for this to be used as a rationale to postpone elections until everyone is forced to get a new driver’s license or something along those lines, because the GOP is increasingly desperate and determined to end representative democracy — or any semblance of it — in the United States.
Beyond that: it’s not just this data. It’s how this data can be correlated with other data/metadata that’s out there and used to build alarmingly comprehensive and dangerous databases on people. This doesn’t require AI, only routine data science techniques, sufficient storage, memory, and CPU, and some time. You can download the tools to do this, the tutorials and books on how to use them, and so even if you’re new to the field, you can probably do something productive — and dangerous — without too much trouble.
This comment is new since your last visit.
Threaded [2]
Don’t give the bastards new excuses!!
This comment is new since your last visit.
Okay, sure, there’s great harm to the public, but have you considered that there’s a lot of lobbying money to be made by supporting spinning up a new industry out of legislation? Without it, the congresscritters will have to settle for having their second gold plated yacht built without platinum highlights. They’ll be the laughingstock of the club!
This comment is new since your last visit.
I think it’s worth keeping in mind that this happened because identity data is a high value target, and not just that the system breached was setup by boneheads (though there’s a solid chance that in the coming days and weeks, we’ll find out that they are in fact boneheads).
Look at the amounts that the hackers wanted: $100 per ID probably meant that they were making enough money for the juice to be worth a really difficult squeeze.
Keep that in mind during the next push for identification laws, when you see claims that “the next company will do better next time”
This comment is new since your last visit.
Threaded [2]
not just that the system breached was setup by boneheads (though there’s a solid chance that in the coming days and weeks, we’ll find out that they are in fact boneheads)
If it wasn’t in Louisiana, I might consider this for a minute. But the entire Fifth Circuit, as a region, exists to cut corners and blame others for it.
This comment is new since your last visit.
Threaded [2]
I’d argue something differently.
It happened because it is not profitable to give a shit about security. Any fine or punishment will be much smaller than the cost of doing it well.
This comment is new since your last visit.
I’m shocked! Oh wait, no. That’s exactly why I’m refused completely.
This comment is new since your last visit.
Only reason for someone to set up shop in Louisiana is to hire morons they barely have to pay.
This comment is new since your last visit.
When someone, Some company, Some TV Evangelist, ANY Person of Company says
TRUST.
My cellphone company has suggested 2 apps to HELP kill Spam calls. I was upto 50 per day.
After 2 months it went down, and at 5 months its at about 20.
At 12:25PM, My phone(on do not disturb) had gotten 10 Calls.
This comment is new since your last visit.
Threaded [2]
When someone, Some company, Some TV Evangelist, ANY Person of Company says TRUST.
A trusted system is one whose failure will fuck you over.
This comment is new since your last visit.
I don’t know what it’s like elsewhere, but up here in Canada, age verification software is sold as having “industry standard” protection of people’s personal information. This is what that industry standard delivers. I’d say to those talking up “industry standard” privacy, “not good enough.”
This comment is new since your last visit.
Can we all agree that Clarence Thomas is an idiot for claiming in Free Speech Coalition v. Paxton that ID verification is just an “incidental” burden for accessing speech??
I wonder how the justices behind that ruling would feel about their data being in one of these leaks…
This comment is new since your last visit.
Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial.
We’ve been living with data breaches of various organizations (DMVs, credit companies, the federal government etc) for well over the past decade. I don’t think people are in denial. They’ve just accepted that’s part of modern life. And the examples here prove it, with stuff like Hertz. This isn’t the first breach, it won’t be the last.
Stuff like age verification for social media is new, but needing an ID to rent a car (in their ancient systems) has been a thing since forever. And comes with the same risks.
Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about.
The problem is the other direction, I think. As long as things like driver’s licenses exist, you’re going to be at risk. To be honest, personally the fact that my driver’s license (and social security, etc) is already out there from 30 other breaches is certainly a factor in muting my alarm. What’s one more marginal vector? I’ve never even given Equifax anything to begin with.
Anyone claiming it’s perfectly safe, is perfectly safe to ignore. There’s no such thing as perfect safety (and even if age verification didn’t exist, it still wouldn’t be perfectly safe, either). It’s all just gradients of more risk or less risk.
At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.
The problem is, you’ll have people who think it’s not needless, and that the risk is worth it. It’s not premised entirely on being perfectly safe. And then you’re back to square one of the underlying argument.
This comment is new since your last visit.
Threaded [2]
You are entirely missing the point which is why make it easier for criminals to acquire PII while only providing downsides for people?
This comment is new since your last visit.
Threaded [3]
You are entirely missing the point which is why make it easier for criminals to acquire PII while only providing downsides for people?
I’m not missing that point, I’m literally saying the article should make that point more directly instead of trying to contrast it with perfect safety/denial.
This comment is new since your last visit.
Threaded [2]
The problem is, you’ll have people who think it’s not needless, and that the risk is worth it.
Those people are sociopaths and need to be thrown out, not caved to.
This comment is new since your last visit.
Threaded [3]
Right, but if we want to throw them out, that means convincing enough voters to throw them out. It’s not enough to not cave, you have to actually beat them.
I don’t think voters are voting for these sociopaths because they’re in denial that privacy risks exist or because they’re falling for the perfectly safe PR, given that one of these breaches happens every few months. At this point pretty much literally all of them have personally had their data leaked and privacy violated at some point.
This comment is new since your last visit.
As an AC said, drivers’ licenses are probably the most common form of ID use for voting.
This breach has been apparently been happening in real time for over a year without the company even knowing about it? That is a bit hard to believe. Kind of sounds like it might be an inside job.
Who has been President for over a year, and constantly screamed about voter fraud, and often joked(?) about a third term? Is this a coincidence?
Think about all the recently gerrymandered districts, and all the removal of polling places.
Throw in the USPS mail-in ballot EO, and what the “whistleblower” has said about what a shit-show that whole thing will become. This is starting to look like a staged kayfabe situation, too.
Given the backdrop, and the current situation with the mid-term elections, and all the hand-wringing and screaming and whatnot about voter fraud, the timing of the long-term breach, and the timing of its revelation, seem almost a little too custom made as a (another?) potentially “plausible” reason to cancel or invalidate the upcoming election.
Maybe I’m just cynical, but it looks like a lot of the pieces of a very ugly and scary puzzle are starting to fit together.
Add Your Comment Cancel reply
Your email address will not be published.Required fields are marked *
Have a Techdirt Account? Sign in now. Want one? Register here
Name
Subscribe to the Techdirt Daily newsletter
URL
Subject
Comment *
Comment Options:
Use markdown.Use plain text.
Make this the First Word or Last Word.No thanks.( get credits or sign in to see balance) what's this?
What's this?
Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »
Notify me of follow-up comments by email.
Notify me of new posts by email.
Δ
Daily Deal: Babbel Language Learning (All Languages)
Working With ICE Is So Toxic, ICE Is Now Offering Liability Insurance To Local Police Officers
Follow Techdirt
Follow us on BlueskyBecome a fan on FacebookSubscribe to our RSS FeedSubscribe to our Podcast
Techdirt Daily Newsletter
Subscribe to Our Newsletter
Please leave this field empty
Get all our posts in your inbox with the Techdirt Daily Newsletter!
We don’t spam. Read our privacy policy for more info.
Check your inbox or spam folder to confirm your subscription.
Podcast Episode
Audio Player
00:00
00:00 | 34:54
Ctrl-Alt-Speech
Move Fast and Settle Things
Aug 28, 2026Season 1Episode 118
Mike Masnick & Ben Whitelaw
Become a Ctrl-Alt-Speech supporter to get extended episodes of the podcast plus the chance to submit stories for us to cover.
In this week's episode, Mike and Ben cover:
- Meta Just Paid Nearly $17 Billion To Make Sure It Gets To Write The Kid Safety Rules For Every Other Social Media Platform (Techdirt)
- Mark Zuckerberg Wants to Make Sure His Competitors Share His Pain (New York Times)
- Meta settlement opens new front in global fight over social media harm (Reuters)
And in the extended episode for Patreon supporters, they cover:
- UK expects Meta to match US child safety measures after $18bn settlement (The Guardian)
- What Meta’s US Settlement on Child Safety Means for Europe (TechPolicy.Press)
- Did Meta’s Big Settlement Actually Help It? (New York Times)
Our fun links this week include a new table format for food recipes and Rainbolt’s tear-jerking Geoguessr video.
If you’re already a Patreon supporter, you can get the extended episode on Patreon.
Follow us on Instagram, YouTube, and Bluesky.
Ctrl-Alt-Speech is the podcast where we make sense of the major debates shaping online speech, platform power, content moderation and the future of the internet. It’s co-hosted by Mike Masnick ( Techdirt) and Ben Whitelaw ( Everything in Moderation).
Share Episode
Share on Facebook Share on Twitter Share on LinkedIn Download
Subscribe
Apple PodcastsSpotifyYouTubeAmazon MusicPodcast IndexCastboxOvercastPocket CastsPodcast AddictDeezerListen NotesPodchaserPlayer FMCastroGoodpodsTrueFansRSS Feed
Move Fast and Settle Things34:54
School of Hard Blocks42:12
Watermark My Words41:17
In the Modi for Takedowns37:33
Zuck Starts Throwing His Weights Around38:24
Live at TrustCon 202656:32
Spotlight: PwC’s Dan Hays on the future of Trust & Safety39:20
Putting Some Meat On The Bans52:14
Sell Me Lies, Sell Me Sweet Meta Lies36:41
Making the Best of a Ban Situation47:10
Teaser: The Ctrl-Alt-Speech Reading List14:38
Close Your Apps and Think of England44:30
Cupertino d'État37:57
Generous to a Default42:54
Deus vs. Machina39:03
Message in a Bottleneck54:20
The Human Element in the Room51:24
Age Against the Machine52:31
Celebrating 100 Episodes & Launching Our Patreon29:56
The Silence of the LLMs52:27
Honey, I Shrunk the Kids’ Internet51:12
Age Old Questions50:31
For Meta or Worse53:09
Money for Nothing and Clicks for a Fee52:08
Writing Some Wrongs52:29
A weekly news podcast from
Mike Masnick & Ben Whitelaw
Subscribe now to Ctrl-Alt-Speech »
Essential Reading
The Techdirt Greenhouse
Read the latest posts:
- Winding Down Our Latest Greenhouse Panel: The Lessons Learned From SOPA/PIPA
- From The Revolt Against SOPA To The EU's Upload Filters
- Did We Miss Our Best Chance At Regulating The Internet?
Trending Posts
- RankHackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.
- RankSony Tells Courts Any 'Reasonable Customer' Knows Digital Purchases Are Actually Licenses
- RankX Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...
Recent Stories
More
×
Email This Story
This feature is only available to registered users.
You can register here or sign in to use it.
Tools & Services
- RSS
- [Podcast](http://fee

The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.




