IDScan.net Breach Exposes Driver’s Licenses for Sale

A massive data breach at IDScan.net has exposed driver's licenses in near real-time, with 400,000 scans appearing on the dark web within 24 hours.

By Central
The breach involves near real-time access to driver's license scans, including UV and IR security features.
Highlights
  • The breach exposed driver's licenses in near real-time, with 400,000 scans appearing on the dark web within 24 hours.
  • The stolen data includes ultraviolet and infrared scans, making the breach more dangerous than typical document disclosure.
  • The FBI is investigating the breach, which appears to involve a third-party scanning service used by companies like Hertz.

The breach of IDScan.net has exposed driver’s licenses from thousands of individuals in near real-time, with scans appearing on the dark web within hours of victims presenting them at car rental counters and other businesses. A dump of 400,000 newly available license scans over a 24-hour period suggests the data is being harvested as it flows through a third-party scanning service, and a KrebsOnSecurity investigation has identified the source as a New Orleans-based ID scanning firm with exclusive arrangements including Planet13 and a client list that features Hertz. The FBI is investigating, but the purported availability of ultraviolet and infrared scans—security features designed to prevent forgery—makes this breach far more dangerous than a simple document disclosure.

IDScan.net Breach Exposes Driver’s Licenses in Near Real-Time: 400,000 Added in 24 Hours

The timing of newly available scans—typically within a day, if not hours, of victims presenting their licenses at rental companies or similar businesses—indicates that Nexus, the entity behind the dark web dump, has near real-time access to data flowing through the third-party scanning service these businesses use. Over a span of 24 hours, security journalist Brian Krebs observed that the number of driver’s licenses listed as available grew by almost 400,000. This rapid accumulation is another indication that the breach has been ongoing and that new cards become available shortly after they are harvested.

Using publicly available information, Krebs found that IDScan.net, a New Orleans-based ID scanning service, has announced an exclusive arrangement with Planet13, a cannabis dispensary chain. It also listed Hertz and 11 other companies as using its services. IDScan.net has said that its scans capture both infrared and ultraviolet spectra, which means the stolen data includes not just the visual image of a driver’s license but also the hidden security features embedded in the document.

Representatives from IDScan did not immediately answer questions sent by email. An IDScan.net spokesperson told Krebs the company is investigating. Representatives from the car rental company involved also did not immediately answer questions.

Why the Speed of This Breach Matters

The near real-time nature of the leak sets this incident apart from typical data dumps. Most breaches involve stolen files that are eventually posted or sold weeks or months after the theft. Here, the data appears almost immediately after a victim swipes their license at a point of sale or rental counter. This suggests that the scanning devices themselves—or the backend systems that receive the scan data—have been compromised, allowing the attacker to siphon off copies as they are captured. For an industry that relies on verifying identity at the moment of transaction, that kind of access is devastating: the very tool meant to prevent fraud has been turned into a pipeline for fraudsters.

Who Is IDScan.net and How Does Its Technology Work?

IDScan.net is a provider of automatic ID scanning solutions used by a variety of businesses to verify the authenticity of driver’s licenses, passports, and other government-issued IDs. Its technology is designed to capture images in visible light as well as in the infrared and ultraviolet spectra. These hidden spectral scans are critical because modern driver’s licenses contain security features—special inks, holograms, and patterns—that are only visible under UV or IR light. Legitimate scanners use these features to detect counterfeits. In the wrong hands, however, the UV and IR scans provide a blueprint for creating far more convincing forgeries.

The Exclusive Arrangement with Planet13 and Clients Like Hertz

IDScan.net announced an exclusive arrangement with Planet13, a major cannabis dispensary chain. In regulated cannabis markets, age verification is mandatory, and ID scanning is the standard compliance tool. Hertz, the car rental company, also appears on the list of 11 other companies using IDScan.net services. The KrebsOnSecurity report did not disclose which of these clients’ transactions were compromised, but the pattern of scans appearing within hours of a rental suggests that at least some of the data originates from Hertz or a similar business that requires repeated, frequent ID checks. The exact list of affected clients remains unclear, and IDScan.net has not released a public statement beyond confirming an investigation.

Why Ultraviolet and Infrared Scans Raise the Stakes

The purported availability of driver’s license scans in ultraviolet and infrared spectra is what makes this dump more troubling than a typical breach. Most data dumps that include driver’s licenses offer only a JPEG or PDF of the front and back. Those images can be printed and used for some types of fraud, but they often fail when inspected by trained personnel or by scanners that test for UV/IR features. A UV scan of a license reveals the “ghost image,” the holographic overlay, and the invisible patterns that are baked into the card during manufacture. An IR scan can reveal the embedded security thread or the secondary barcode that encodes data in a different way.

With both UV and IR scans in hand, an attacker can replicate not just the visual appearance of a license but its full set of anti-forgery features. This makes it possible to produce a physical counterfeit that could pass through a simple visual inspection and even through some automated scanners that do not check for the original security features. The breach therefore upgrades the threat from simple identity theft—where credentials are used to open accounts—to the ability to produce actual counterfeit documents that could be used to bypass airport security, border crossings, or age verification at government-regulated sites.

What Is a UV Scan and How Is It Used?

A UV scan captures the image of a driver’s license while it is illuminated by ultraviolet light. Most licenses have fluorescent elements that are invisible under normal light but glow under UV. Common features include the state seal, a second photo, or a series of tiny dots forming a pattern. IDScan.net’s scanners are designed to capture both the visible and UV images to confirm that these security elements are present. In the hands of criminals, that UV map becomes a template for printing fake licenses with the correct glowing features, defeating simple handheld UV lamps used by many businesses.

The IDScan.net Response and FBI Investigation

An IDScan.net spokesperson told Krebs that the company is investigating the breach. No further details have been provided, and the company has not disclosed whether the breach affects all of its clients or only a subset. The dark web marketplace known as Nexus went dark within hours of the KrebsOnSecurity scoop, which also means that there is no way for individuals to check whether their IDs are included in the dump. Somewhat consoling is the ongoing investigation by the FBI, though federal agencies typically do not communicate directly with individual victims during active probes.

The sudden disappearance of Nexus suggests that the operators saw the coverage and shut down the listing to avoid further scrutiny. This is a common pattern in cybercrime: attackers vanish when their method is exposed, only to reappear later under a new alias or on a different platform. The short window when the scans were available means that the thieves may already have those copies in hand, even if they are no longer publicly visible. There is no reasonable way for victims to determine whether their license was part of the 400,000-plus set that was listed.

How the Breach Occurred and What It Reveals About Third-Party Risk

The near real-time availability of scans points to a compromise at the integration point between IDScan.net’s scanning devices and the businesses that use them. The scans are captured locally at the point of sale or rental counter, then transmitted to IDScan.net’s cloud storage for verification and record-keeping. If an attacker gained access to that transmission channel—either by compromising the physical scanner, the network it connects to, or IDScan.net’s backend infrastructure—they could intercept every scan as it is uploaded. The fact that scans appear within hours suggests that the attacker is pulling them directly from the live data stream rather than from a delayed backup.

This type of breach is a stark reminder of the third-party risk that every business faces when outsourcing identity verification. The companies that use IDScan.net—Hertz, Planet13, and others—trusted the service provider with highly sensitive biometric-level data. That trust was not misplaced in the sense that IDScan.net likely had reasonable security, but no system is immune to an advanced persistent threat. The breach also underscores the danger of storing UV and IR scans alongside visible images. While it makes sense for verification purposes, it creates an enormous target because those scans are exactly what forgers need.

What Does This Mean for Businesses Using ID Scanning Services?

Businesses that rely on IDScan.net or similar services should immediately review their data-sharing agreements, ask whether UV and IR scans are being stored, and demand assurances that such data is encrypted at rest and in transit. The fact that 400,000 scans were added in a single day indicates that the breach was not a one-time dump but an ongoing siphoning. That means the attacker may still have access to the data pipeline, or at least had prolonged access. Companies should also consider whether real-time scanning is truly necessary for their use case, or whether a local-only verification model—where the scan is checked and immediately discarded—could reduce the attack surface.

What Victims Can Do After the IDScan.net Breach

If you have recently rented a car from a company that uses IDScan.net, or if you have visited a Planet13 dispensary that uses the service, your driver’s license scan may be among those exposed. Unfortunately, because Nexus has gone dark, you cannot check whether your specific license is listed. The lack of a public notification from IDScan.net or the affected businesses makes it difficult to take targeted action. However, you can take general protective steps.

Place a fraud alert on your credit file with all three major bureaus (Equifax, Experian, and TransUnion). This lasts for one year and requires businesses to verify your identity before opening new accounts. Consider a credit freeze for more robust protection. Monitor your accounts for unusual activity, especially attempts to open new lines of credit or apply for loans. In the long term, be aware that counterfeit licenses could be used for identity theft in physical contexts—such as someone using a fake license with your information to pass a background check or to rent a car in your name. Keep an eye on your driving record and any notices from the DMV about duplicate licenses.

The most alarming personal factor is that for many victims, this is not the first time their data has been compromised. Social Security numbers, addresses, and demographic details have been exposed in previous breaches. Now the photographic, UV, and IR scans are also in the wild. That combination makes it far easier for criminals to assemble a complete identity profile that can be used to answer security questions and pass verification checks that rely on document features.

Broader Implications for Identity Security and Digital ID Infrastructure

This breach is a canary in the coal mine for the growing industry of digital identity verification. As more businesses move to contactless, automated ID scanning—driven by demands for speed, hygiene, and compliance—the amount of sensitive identity data flowing through third-party services is exploding. Each service becomes a potential single point of failure. The IDScan.net breach shows that even if the scanning device is secure, the data that moves from the device to the cloud can be intercepted. The fact that UV and IR scans are being captured means that the stolen data is more than just a photo; it is a forensic-grade reproduction of the document’s security features.

Government agencies that issue driver’s licenses may need to consider whether the current security features—which assume that UV and IR information can be kept secret—are still viable in a world where those scans are routinely digitized and transmitted. Some states are already moving to digital driver’s licenses that rely on cryptographic signatures rather than physical security features. The IDScan.net breach could accelerate that shift, as it demonstrates that the physical anti-forgery measures are now easily captured and reproducible.

Regulators may also take a closer look at the data retention policies of ID scanning companies. Currently, there is no federal standard for how long a business can keep a scanned driver’s license. Many companies retain the scan for months or years for compliance and audit purposes. That retention made the IDScan.net breach possible: if the scans were deleted immediately after verification, the attacker would have had a much smaller window to steal them. The breach could prompt state legislatures to pass laws requiring that ID scan data be deleted within a certain timeframe or stored in an encrypted form that makes interception less valuable.

The near real-time nature of the leak also has implications for incident response. Businesses that detect a breach often have time to shut down access or rotate credentials before the data becomes public. Here, the data was appearing on the dark web within hours of capture, leaving victims with no time to react. This suggests a new breed of threat where attackers monetize data as it is generated, rather than waiting to sell it in bulk. For consumers, it means that the window to protect yourself after a breach can shrink from weeks to minutes.

Ultimately, the IDScan.net breach is a reminder that identity verification is inherently risky because it requires collecting the very information that criminals want to steal. The tension between convenience and security is not new, but the scale and speed of this breach make it particularly unsettling. The fact that the FBI is investigating offers some hope that the perpetrators will be identified, but the real challenge is structural: as long as businesses rely on third-party services that store high-resolution, multispectral scans of identity documents, the potential for similar breaches will remain. The long-term solution may involve redesigning the verification process itself so that the sensitive data—especially UV and IR scans—never leaves the local device in a form that can be intercepted.

Share This Article