Start your free trial — no credit card required.
153 Million License Scans for Sale: Stop Treating a Photo ID as Proof of Anything
Kabir11 min read

153 Million License Scans for Sale: Stop Treating a Photo ID as Proof of Anything

The IDScan breach put 153 million driver's license scans on a dark web search engine. If your account recovery ends with 'show us your ID', it now ends with the attacker.

Share:

On August 31, a new service called Nexus opened for business on Exploit, the Russian-language cybercrime forum. Its pitch was simple: type a name, get a driver's license. Front and back. Plain scan, infrared scan, ultraviolet scan. A timestamp in the filename. Often a photo of the person holding it.

According to Brian Krebs, who broke the story on September 1, a blank search on Nexus returned roughly 11.5 million pages at 15 results a page. The operators claimed more than 153 million U.S. and Canadian driver's licenses, over 10 million ID cards, more than 3 million travel documents and at least 579,000 medical cards. Krebs watched the database grow by about 400,000 licenses in a single day.

The source turned out to be IDScan.net, a Louisiana company whose scanners sit at rental car counters, retail tills, casinos and cannabis dispensaries. IDScan has since confirmed that "an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud." The FBI's New Orleans field office opened an investigation the same day Krebs published. Nexus went dark soon after, replaced with a one-line notice that the service was "no longer available."

I've spent most of my career on the incident response side, and I'll say plainly what I think this breach means. For consumers, it's an identity theft problem. For anyone who runs a help desk, a KYC flow or an account recovery process, it's something worse: the end of the photo ID as evidence that the person in front of you is who they claim to be.

What made this dump different

Leaked identity data isn't new. Social Security numbers have been effectively public for a decade. What made Nexus unusual was the format and the freshness.

The format was images, not rows. Most identity breaches give you text: name, date of birth, license number. You can use that to fill in a form. You can't use it to hold a card up to a webcam. Nexus sold the pictures themselves, including the infrared and ultraviolet captures that IDScan's hardware takes to check security features. Krebs reported that some records also carried a photo of the customer. That's a much closer match to what a verification flow actually asks for.

The data was live. This wasn't a stale archive from 2019. Krebs traced his own license to a June 2025 Hertz rental, down to the minute, and found his mother's scan taken seconds later at the same counter. Researcher Zach Edwards matched his timestamp to a Planet13 dispensary visit during a DEF CON trip. The operators claimed they'd been "continuously exfiltrating new data for over a year," and the 400,000-a-day growth backs that up. Anyone who showed a license at an IDScan-equipped counter in the past year should assume a current scan of it was for sale.

The client list was mainstream. Krebs named Hertz, Target, FedEx, Motorola Solutions, Jack Henry, Caesars Entertainment and Planet13 among IDScan's customers, and IDScan's own marketing cited more than 21 million verifications a month across 20,000 locations. This isn't a niche population. It's anyone who rented a car or bought a bottle of wine with an ID check.

Nobody is safe by job title. Krebs found the licenses of two FBI employees, and TechCrunch reported the dataset included a record for the sitting U.S. Secretary of Defense. The Pentagon said it was aware of the suspected breach. If the people whose identities are most carefully protected by the state were in the pile, your CFO is too.

Where a license scan is a password

Here's the part most breach coverage skips. Over the last three years, as organizations pushed MFA and then passkeys, the attacker's best path moved from the login page to the recovery flow. You can't phish a hardware key. You can call the help desk and say you lost it.

And what do mature help desks do when someone says they lost their authenticator? Increasingly, they ask for a photo ID. Sometimes it's a video call where the employee holds a license up to the camera. Sometimes it's a third-party identity verification step: upload the front and back, take a selfie, wait for a match score. I've seen it written into runbooks as the "strong" path, reserved for privileged users because it's supposed to be harder to fake than knowledge questions.

That assumption held when getting a clean, current, high-resolution scan of a specific person's license was hard. As of September, for a very large slice of North American adults, it was a search box.

Three flows deserve a hard look this week.

1. Help desk MFA resets

This is the one I worry about most, because it's where the losses have already been. In the McKesson breach we covered earlier this month, the intrusion started with a phone call to support and ended with 284 million records gone in four days. Vishing crews like ShinyHunters don't need a technical exploit. They need a reason for the agent on the other end to say yes.

A help desk agent who has been trained to "verify with ID" will accept a license held up on a video call. If that license is a printout of a genuine scan, with the right photo, the right number and the right issue date, the agent has nothing to catch. The name matches HR. The face roughly matches the directory photo. Every check passes.

2. Automated identity verification in recovery

Many workforce and customer platforms now outsource recovery to a document-plus-selfie vendor. Those vendors run liveness checks, and the good ones are genuinely hard to beat with a static photo. But I'd push back on anyone who tells you the license half of that check still carries weight. The document check was the part you were relying on to establish identity. The liveness check only establishes that a live human is present. If the attacker owns a perfect document image and only has to pass liveness with their own face, or with a face-swap injected into the camera stream, you've reduced the control to "is the face close enough to a 2x3 cm photo on a card."

I'm not going to claim IR and UV scans let someone clone a physical card. I don't have evidence of that and neither does the reporting. What I will say is that the attacker now has every image a remote verification system could ask for, at the same quality the counter scanner saw.

3. Consumer account takeover and new-account fraud

Malwarebytes put it well in its coverage: a driver's license is more useful to an identity thief than a password, because you can't reset it. For customer-facing businesses, expect a rise in account recovery requests that come with a perfect ID attached. Banks and fintechs should also re-read our Revolut post-mortem. In that case an attacker went the other way, tricking a bank into sending out 680 customers' passports and selfies. Stolen ID images flow in both directions, and both directions feed recovery fraud.

"But we check liveness." Fine. What else do you check?

The pushback I hear from IAM teams is that photo ID was never the only factor. Good. Then let's test that.

Pull your last 50 help desk MFA resets for privileged accounts. For each one, write down what evidence the agent actually used to approve it. In the incident reviews I've done, the honest answer is usually some mix of: the caller knew their employee ID (in the directory, often leaked), their manager's name (on LinkedIn), and showed a photo ID (now for sale). Remove the ID and the stack collapses to public information.

Zach Edwards said it bluntly to Krebs: "These systems are putting sensitive data into 3rd party vendors, and we don't have nearly the oversight to ensure they are safe." I'd add a second problem. We also don't have the oversight to know which of our own controls quietly depend on those vendors staying unbreached.

What I'd change, in order

None of this requires a new product. It requires removing the ID card from the list of things that can unlock an account on its own.

Make recovery require something the attacker can't buy. For privileged users, that means in-person recovery or a pre-registered second device that already holds a passkey. For everyone else, a callback to a number on file from before the reset request, plus manager approval through a separate channel, beats any document check. If you're mid-rollout on passkeys, our piece on how passkey enrollment became a phishing pretext covers why the enrollment and recovery windows are exactly where attackers are aiming.

Add a delay to high-risk resets. A four-hour hold on a privileged MFA reset, with a notification to the user's existing devices and their manager, kills most live vishing operations. The attacker's advantage is speed. McKesson went from a phone call to mass exfiltration in four days, and SNARKY SPIDER, per CrowdStrike's 2026 threat hunting report, has gone from account takeover to data theft in under five minutes.

Stop storing ID images you don't need. If your business scans IDs for age checks, ask the vendor where the images go and for how long. IDScan's customers almost certainly didn't think they were running a year-long archive of their visitors' licenses. Many of them were.

Treat every post-recovery session as untrusted for a while. This is where I think most teams have the biggest gap, and it's where I've changed how I work. Once recovery succeeds, the attacker holds a valid identity. Your MFA logs are clean. Your SIEM sees a normal user signing in from a normal-looking device. You're not going to catch the reset. You have to catch what comes after.

Catching the person who passed every check

Every recovery fraud I've investigated has one thing in common: the attacker who got through doesn't know the environment. They know one person's name and face. They don't know which file share is real, which admin account is actually used, or which AWS key in a config file is live. So they look around. Fast.

That's the window deception is built for. A few examples from real deployments:

  • A decoy privileged account that nobody ever resets. Create an account that looks like a senior admin or a break-glass identity, with a plausible name and group memberships, and no real human behind it. Any help desk ticket, recovery attempt or sign-in for it is an attacker by definition. I like this one because it tests the help desk process itself: if someone calls in claiming to be that person and holds up an ID, you've learned something about Nexus buyers in your threat model.
  • Honeytoken credentials in the places a freshly recovered user would look. A saved password in the browser profile, a .aws/credentials file, a "vpn-admin-backup.txt" in OneDrive. A real employee who just got locked out and back in goes straight to their work. An attacker who just impersonated them goes looking for more access. The honeytoken fires on first use, and there's no benign reason for anyone to use it.
  • Decoy services on the network paths an intruder would scan. If recovery lands the attacker on a VPN or VDI session, the next move is discovery. A decoy RDP or SMB service from MineField sits where nothing legitimate should connect, so a single connection attempt is a clean signal.

The point isn't to replace better recovery. It's to accept that recovery will sometimes be fooled, especially now, and make sure the fooled state is loud. Mine2's deception solutions are built on that premise: zero false positives because the decoy has no legitimate user, which is exactly the property you want when every other signal says "authorized."

The data won't go away

Nexus is offline. That doesn't mean the data is. Whoever had the IDScan pipeline for a year didn't keep one copy, and buyers who paid for access didn't delete what they pulled. The license in your wallet will be valid for years, and the scan of it will outlive the card.

I'd put it this way to any board that asks: we spent a decade teaching users that passwords leak and must be rotated. A photo ID leaks too, and it can't be rotated at all. Any control that treats it as secret is already broken for a large part of your workforce. We just didn't find out until someone built a search engine for it.

If you want to see what a decoy privileged account and post-recovery honeytokens look like inside your own tenant, book a Mine2 demo and we'll walk through the recovery path an attacker with a stolen ID would take.

M2

Kabir

Incident Response Lead, Mine2

Kabir leads incident response work at Mine2, dissecting breaches after the fact to show where earlier detection would have changed the outcome.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.