The FBI opened an investigation on September 2, 2026. A dark web marketplace called Nexus — advertised on Russian cybercrime forum Exploit — is selling 153 million driver’s license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. The source is IDScan.net, a Louisiana-based identity verification company that processed 21 million ID verifications monthly for Hertz, Target, FedEx, Caesars Entertainment, and over 1,000 cannabis dispensaries across 19 states.
If your application ever called IDScan.net’s API — or if you built on a platform that did — your users are almost certainly in that dataset. The seller claims the breach has been running for over a year, and records were growing at roughly 400,000 per day when the listing was discovered. Before Nexus went offline, it listed US Defense Secretary Pete Hegseth’s Minnesota license for $100 and an FBI official’s license among its inventory. The FBI’s New Orleans field office is now investigating the same company whose customers’ data is for sale.
What IDScan.net Is (and Why You Might Not Know You Used It)
IDScan.net is not a consumer product. It is developer infrastructure — a RESTful API and SDK that businesses embed into their onboarding flows to verify government-issued IDs. Hertz agents scan licenses at rental counters through it. Dispensaries use it to verify age at point of sale. Car dealerships, retailers, and financial services firms integrated it for KYC compliance. IDScan.net’s API supports 10,700+ document types across 250+ languages and processes verifications in under 15 seconds.
Many developers never touched IDScan.net directly. They built on top of a dispensary POS, a car rental management platform, or a retail compliance tool — and those platforms integrated IDScan.net underneath. If any of those apply to you, your users’ IDs ran through IDScan.net’s systems.
What Was Stolen — and Why the Image Storage Is the Real Problem
The breach is not just metadata. Nexus was selling high-resolution document scans with infrared and ultraviolet imaging — the same multi-spectral captures IDScan.net used to authenticate documents. Timestamps in the stolen records correlate to specific business visits: when a customer rented a car, checked in somewhere, or walked into a dispensary.
Most developers who integrated identity verification APIs assumed they worked like payment processors: process the sensitive data, return a result, discard the raw input. Under PCI DSS, you cannot store raw card numbers. No equivalent mandate exists for ID scans. IDScan.net retained the images indefinitely. At 21 million verifications per month across 20,000 locations, that built into a honeypot of government-issued identity at scale — and it was breached for over a year before anyone noticed.
Driver’s license images are not passwords. They cannot be rotated. The UV and IR scans in the leaked data also expose document security features, making high-quality forgeries easier to produce. The people in that dataset have no recourse.
If You Integrated IDScan.net: Your Legal Clock Is Running
The breach discovery date is September 2, 2026. Your breach notification deadlines start from the date you learned of it. California’s updated breach notification law (effective January 1, 2026) requires notification within 30 days and AG notification within 15 days of notifying consumers if more than 500 California residents are affected. GDPR requires supervisory authority notification within 72 hours of discovery.
There is a compounding risk: if you did not execute a Data Processing Agreement (DPA) with IDScan.net before integrating their API, GDPR Article 28 places the liability for vendor breaches on your organization. Many smaller integrators skipped this step.
Five Things to Do Right Now
- Audit your codebase and infrastructure. Search for any direct IDScan.net API calls, SDK dependencies, or indirect usage via third-party platforms that may have integrated it.
- Check your DPA. Do you have an executed Data Processing Agreement with IDScan.net? If you integrated their API without one, talk to legal today.
- Determine affected users. How many users had IDs verified through IDScan.net? In which states? Any EU residents?
- Start breach notifications. California’s 30-day clock and GDPR’s 72-hour clock are running. Do not wait for IDScan.net to notify you — they have not confirmed full scope.
- Evaluate alternatives. Stripe Identity, Persona, Veriff, and Sumsub all offer document verification. Before migrating, ask directly: do you store raw scans? For how long? Get the answer in writing.
The Harder Question
IDScan.net is not unique in retaining raw ID images. The identity verification industry has no enforceable standard on raw scan retention equivalent to PCI DSS for card data. As Krebs on Security reported, IDScan.net processed 21 million verifications monthly across 20,000 locations worldwide — and the breach ran undetected for over a year. Every third-party ID verification vendor is a centralized archive of government-issued identity. That archive is a high-value target by definition.
Switching vendors fixes nothing if you replicate the same pattern without demanding contractual data minimization, retention limits, and audit rights. The 50-state breach notification landscape is complex enough that most teams have not fully mapped their exposure. Now is the time to do it. Ask your next vendor whether they store raw images. Get the answer in writing. If they cannot tell you, that is your answer.













