153 Million Licenses, One Wrong Lesson
ATLANTA, Ga. — September 3, 2026 — On August 31, a new account on the Russian cybercrime forum Exploit advertised an identity-theft service called Nexus. Its inventory, as KrebsOnSecurity reported: digital scans of more than 153 million driver's licenses from the United States and Canada, plus more than 10 million other identification cards, 3 million travel documents, and 579,000 medical cards — identity documents for more than 170 million people in North America. The FBI's New Orleans field office opened an inquiry on September 2; by evening the story was everywhere, from TechCrunch to Dexerto. Nexus went dark that night with a note that the service was "no longer available." The data is not.
The evidence points to IDScan.net, a New Orleans identity-verification vendor whose scanners sit at the check-in counters of car-rental agencies, hotels, retailers and, by its own count, more than 1,000 marijuana dispensaries in 19 states. It says it runs more than 21 million verifications a month across 20,000-plus locations. Brian Krebs found his own Virginia license in the trove, offered as a free sample, timestamped to the moment he and his mother handed their IDs to a Hertz counter in June 2025; nine of his friends and relatives confirmed the same pattern. Security researcher Zach Edwards's record matched his visit to the Planet 13 dispensary in Las Vegas, which signed an exclusive ID-verification agreement with IDScan.net in 2022. Defense Secretary Pete Hegseth's license was in there too. IDScan.net says it is investigating and has not confirmed that its systems are the source.
What was actually taken
This is not a list of license numbers. Each record held up to six image files — the front and back of the card as a plain scan, under infrared light, and under ultraviolet light, the very captures a scanner uses to decide whether a card is genuine — each stamped with the date and time of the scan and, where available, a photo of the customer. The sellers claimed to have been "continuously exfiltrating new data for over a year," and the count grew by nearly 400,000 records in the 24 hours Krebs watched it. A license number can be reissued. A face, a date of birth and a home address cannot. As BreachLock's Seemant Sehgal put it to Infosecurity Magazine, "every person in this dataset will carry this exposure with them for life."
"The check took seconds. The copy lasted more than a year. Only one of those was necessary."
— Morris M
The wrong lesson
Within a day the diagnosis had hardened. "Identity verification is broken," Gizmodo declared; Coin Center's Peter Van Valkenburgh called the breach "inevitable" and said we are "long, long, long overdue to reduce the amount of KYC we do." A second camp drew the opposite conclusion: that ID stores should be defended like payment-card data. A third said the real fix is mobile driver's licenses, and that adoption is years away.
All three miss what actually failed. The dispensary that scanned Edwards's license was required by Nevada law to confirm he was 21. Hertz has to know who is driving its car. Those checks are not going away, and most of them worked, in seconds. What failed was the decision to keep the pictures afterwards — Krebs's own scan was more than a year old when it went up for sale. Verification is a question with a short answer: is this document genuine, and is this person old enough, or who they claim to be? Nexus is what happens when a yes-or-no question is answered by warehousing the evidence, six images at a time.
"Reduce KYC" gets the target wrong: the merchant's obligation is to check, not to collect. "Defend it like card data" gets the history wrong: payments did not get safer because merchants bought better locks for card numbers; they got safer when the industry stopped letting merchants hold card numbers at all — tokenization, not vaults. And "wait for digital IDs" gets the timing wrong. Proving you are 21 without surrendering your address and license number does not require a new wallet standard at every counter. It requires that the verifier discard what it does not need, and that the person keep the rest.
It was a setting
Here is the part that should worry every business with a scanner at the door. IDScan.net's own support documentation for VeriScan, its in-store product, states: "The default setting for new customers is to retain all records in our secure cloud." Those records include "high-resolution scans of the front and back of the ID" and "live photos taken by webcam at time of scan." A business can choose to purge that data after eight hours, a day, or a year — if it knows to look. The company's DIVE online product defaults to 30 days. Its privacy policy names no retention period at all, only "the length of time that is reasonably necessary."
Seventeen states regulate the scanning or retention of license data, according to the ACLU, and several restrict retention outright; IDScan.net's own blog notes that in some states "PII and data retention is banned" and in others "the data must be deleted after 30 days." Thousands of merchants believed they were buying a compliance check. Many were also buying, by default, a growing archive of their customers' faces and addresses, hosted by a vendor whose 2022 press release promised dispensaries a way to "reduce liability and protect their licenses." The liability did not shrink. It moved — onto 153 million people who never chose the vendor and never saw the setting.
We do not yet know which system was breached or how, and IDScan.net deserves the chance to say. But a retention setting is not an architecture. If the images exist in one place, reachable with one company's credentials, the only open question is when.
What a check should leave behind
PersonaBlocks was built so that a check leaves nothing worth stealing. A person verifies once — document, liveness, face match — and every document is encrypted to that individual before it is stored; for wallet users, the key is derived from a signature only their wallet can produce. The platform holds ciphertext, not an archive. A merchant that needs an age or identity check receives the answer and a reference to the person's Verifiable Identity Certificate, not a copy of the license. A merchant that genuinely needs the document must request it, the person must approve, every view is logged on-chain, and every image is forensically watermarked so a leaked copy can be traced to the viewer who leaked it. There is no vault of six-image scans, because the design never creates one.
Our own exposure
We owe readers some candor. From April to July of this year, during platform testing, PersonaBlocks used IDScan.net's DIVE API as a second opinion on document authenticity alongside our own checks. Each call sent the front of the ID, the selfie, and the name. That happened 60 times, all in our development environment; none came from the production platform. Every one of those records carried DIVE's 30-day retention setting, and the last was submitted on July 8, so under IDScan.net's documented policy none of that data should still exist. We disabled the integration on September 3, are asking IDScan.net to confirm deletion, and will notify anyone affected if the company's investigation shows DIVE data was involved. We were not immune to the habit this article criticizes: a second opinion seemed prudent, and it came bundled with a copy. The fix was to remove it.
The lesson of Nexus is not that we verify too much. It is that we keep too much — and that "keep" is usually a default nobody chose. Don't stop verifying. Stop keeping.
Read the full case in our white paper, Beyond KYC Theater, and our July analysis of the AssuranceAmerica breach — the same failure, with a smaller number.
Addendum — September 4, 2026
Techdirt's Mike Masnick followed the Krebs report with a piece whose headline says it plainly: hackers had a live feed of every ID this verification company scanned, for over a year. Two things in it deserve a response. (IDScan.net has still not confirmed the breach or its scope; the "live feed" rests on the sellers' own claim of continuous exfiltration and the roughly 400,000 records Krebs watched appear in a single day.)
The first is a fact we should have included. IDScan.net is not just a vendor caught in a breach. It has been a public advocate for age-verification mandates, publishing its own analysis of the Kids Online Safety Act and tracking state age-verification laws as market opportunities. A company that argues for more mandatory ID checks while defaulting its customers to "retain all records in our secure cloud" is the clearest case yet that the industry's incentives run toward collection. Every mandate it championed would have fed the same feed.
The second is where we part ways. Masnick's conclusion is absolute: "You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target." Half of that is right. A verification always creates a record. The mistake is assuming the record must be the document. What Nexus sold was not a list of verification outcomes; it was 153 million license images, retained by a third party long after the check that needed them was over. A record that says this person's license was genuine, this face matched it, on this date — signed, and held by the person it describes — can be designed to carry no license number, no address and no image of the card. It is not the same target as a warehouse of licenses, and it is worth almost nothing to steal.
That distinction is the whole argument of this article, and it is the one the mandate debate keeps skipping. Laws that require age checks without requiring data minimization are writing honeypots into statute. Laws that require the check and forbid the copy would be doing for identity what the payment industry did for card numbers two decades ago. Neither Techdirt's "never verify" nor the vendors' "trust our cloud" gets there. Verify, don't keep — and put that in the law.