A dark web service called Nexus went on sale on 31 August 2026 offering searchable access to more than 153 million driver’s licences, and within a day Brian Krebs had traced the corpus to IDScan.net, a New Orleans identity-verification firm that runs over 21 million checks a month. The FBI’s New Orleans field office opened an investigation. IDScan’s own notice names three things: full names, driver’s licence numbers and other government ID numbers, and offers credit monitoring.
The reporting describes something the notice does not. Each record reportedly holds up to six image files, including infrared and ultraviolet captures. Those are the layers a document-authenticity check reads to prove a licence is real, and they cannot be reissued. This piece traces each leaked asset against the statute that governs the notice, and against the controls that will meet it at somebody else’s onboarding flow.
- 153 million licences, 10 million ID cards and 3 million travel documents were offered through a searchable service traced to IDScan.net; the FBI New Orleans field office is investigating and no charges have been filed.
- The record is six image files deep. Front, back, basic scan, infrared, ultraviolet and a capture timestamp, per Krebs. IDScan’s notice names only names and ID numbers.
- Louisiana’s breach statute enumerates identifiers, not images. Under R.S. 51:3073 the licence number is covered and the photograph, the infrared layer and the face are not, so everything the notice reaches can be reissued and everything that cannot be reissued sits outside it.
- The statutory notice does not run to you. R.S. 51:3074(B) points a processor’s notice at the businesses that own the data, not the person in the photograph.
- Document checks pass a replayed genuine capture, correctly. Only capture-path evidence still separates a live scan from a leaked file.
What Brian Krebs found on Exploit
An advertisement went up on the Russian-language cybercrime forum Exploit on 31 August 2026 for a service called Nexus, offering searchable access to more than 153 million United States and Canadian driver’s licences. Brian Krebs reported the following day that a blank query against the database returned roughly 11.5 million pages of results at about fifteen records a page, and that he confirmed the corpus was real by finding his own record in it. Alongside the licences, the listing advertised 10 million identity cards, 3 million travel documents and 579,000 medical cards, according to eSecurity Planet and BleepingComputer.
Krebs traced the corpus to IDScan.net, a New Orleans company that processes more than 21 million identity verifications a month across more than 20,000 locations for venues, hotels, car rental desks and cannabis dispensaries, per CyberInsider. The attribution did not rest on a claim by the seller. Timestamps embedded in the leaked filenames lined up with the moments victims had handed a licence to a Hertz counter, to Planet 13 dispensaries and to hotel front desks. Nexus disappeared within hours of publication, replaced by a line reading that the service was no longer available.
IDScan posted a security notice on 4 September saying it had learned on or around 1 September that certain data may have been accessed without authorisation from customer accounts on its cloud platform. The FBI’s New Orleans field office opened a formal investigation, and the bureau confirmed to TIME that it was looking into the incident while declining to comment further.
Why six files is not one record
The number that travelled was 153 million. The number that matters to anyone running identity verification is six, which is how many image files Krebs reported sitting inside a single record: a front photograph, a back photograph, a basic scan, an infrared capture, an ultraviolet capture, and a timestamp appended to the filenames. Some records also carried cannabis dispensary cards.
Most coverage of a breach this size reaches for the count of people affected, because that is the figure that scales. It is the wrong axis here. A leak of 153 million licence numbers is a large credential problem with a known shape, and states can reissue a licence number. A leak of 153 million multi-spectral capture sets is a different class of asset, because those files are not descriptions of documents. They are the documents, photographed under exactly the conditions a verification system asks for.
The distinction runs through everything below. It is the reason the remedy IDScan offered, complimentary credit monitoring and identity repair, is a sensible answer to the leak the company described and no answer at all to the leak the corpus listing describes.
How infrared proves a document
Physical identity documents defend themselves with features that are invisible in ordinary light. Under infrared illumination, some inks drop out entirely while others stay, so a genuine licence shows a specific pattern of presence and absence that a colour photocopy cannot reproduce. Under ultraviolet, fluorescent overlays and security fibres light up in patterns the issuing authority controls. A document reader captures these layers precisely so that software can check them, which is why a commercial ID scanner has infrared and ultraviolet lamps in it at all.
That machinery works well against the attack it was designed for. Someone printing a fake licence on a home printer produces an object with no correct infrared response, and the check catches it immediately. The assumption underneath is that possession of a correct multi-spectral capture implies possession of the physical card, and possession of the card implies a person standing at the counter.
A corpus of leaked captures breaks that chain at the first link. The attacker never needs the card, because someone already photographed it correctly and the photographs are now indexed and searchable by name. We have written before about how stolen ID scans bypass document verification, and this incident is the largest concrete instance of that argument we have seen: the leak does not contain the ingredients for a forgery, it contains the finished article.
The timeline IDScan has confirmed
What the breach notice leaves out
IDScan’s notice names three things: full names, driver’s licence numbers, and other government-issued identification numbers. It does not mention images. BleepingComputer states the gap plainly, reporting that threat actors were able to steal scans of driver’s licences while IDScan’s official statement did not explicitly mention image scans. TechCrunch describes photographs as included in the stolen database. Krebs describes six image files per record.
Two readings survive that gap, and we are not in a position to choose between them. Either the notice is describing a narrower set of records than the one advertised on Nexus, in which case the relationship between the two datasets is the central unanswered question of this incident, or the notice is describing the same records in the vocabulary of a breach notification statute, which enumerates data elements rather than file types. The second reading is the one the law makes likely, and it is worth following because of where it leads.
Where the statute stops covering you
IDScan is a Louisiana company, and Louisiana’s Database Security Breach Notification Law (R.S. 51:3071 to 51:3077) defines what has to be disclosed. It is one statute among several that would reach a corpus this size, and what follows is a worked example of how these laws are built rather than a compliance assessment. Under R.S. 51:3073, "personal information" means an individual’s name in combination with one or more enumerated elements: a social security number, a driver’s licence or state identification number, an account or card number with its access code, a passport number, or biometric data. Every one of those is a number or a code. None of them is a photograph.
Biometric data is the element that looks like it should cover a face. It does not, on the statute’s own wording. The definition is data generated by automatic measurements of an individual’s biological characteristics, such as fingerprints, voice print, eye retina or iris, or other unique biological characteristic "that is used by the owner or licensee to uniquely authenticate an individual’s identity when the individual accesses a system or account". The qualifying clause is doing the work. A photograph taken at a hotel desk to check that a guest is who the booking says is not being used to authenticate access to a system or an account. It is a document image captured during an in-person check.
So the licence number falls squarely inside the statute and the licence photograph, the infrared layer and the ultraviolet layer sit outside every enumerated element. That is not a criticism of IDScan’s drafting. A notice written to a statute names what the statute enumerates, and the statute enumerates identifiers that can be revoked and reissued, because it was built in 2005 around a threat model of account opening and card fraud. The 2018 amendment that added biometric data and passport numbers extended that model rather than replacing it.
Read the last two columns together. Everything the statute names can be reissued or watched. Everything that cannot be reissued is outside what the statute names. That is not a coincidence; it is the same design assumption expressed twice, and it holds right up until the leaked asset is an image of a person rather than a string identifying them.
Who the law says must tell you
There is a second structural problem, and it explains why so many people will never hear about this at all. Under R.S. 51:3074(A), the party that owns or licenses the data notifies the affected residents. Under subsection (D) of the same section, any person that maintains computerised personal information it does not own notifies the owner or licensee of that information, not the individual.
IDScan is the maintainer. The owners are its business customers: the dispensary, the stadium, the rental desk, the hotel. The statutory notice runs from the processor to those businesses, and the obligation to tell the person in the photograph sits with whichever venue scanned them, possibly years ago, in a transaction the person has long forgotten. IDScan said it is notifying affected individuals in an abundance of caution, and the phrase is precise rather than modest. Notifying individuals directly is the thing a maintainer does over and above what subsection (D) requires of it.
The practical result is that the person whose face, licence and whereabouts are in the corpus has no relationship with the company that lost them, did not choose that company, cannot enumerate which venues scanned their licence, and depends for notice on a chain of businesses with no particular reason to be diligent about a vendor incident. Louisiana attaches a private right of action for failure to disclose in a timely manner under R.S. 51:3075, which is the hook plaintiffs’ attorneys are currently examining; no class action had been filed as of 15 September.
Two dates are worth writing down, because they are checkable later. Louisiana's administrative rule at LAC Title 16, Part III, §701, published in current form on the Attorney General's own breach-reporting page, requires written notice to the Consumer Protection Section of the Attorney General’s Office, including the names of all affected Louisiana citizens, and treats that notice as timely if received within ten days of notices going out to residents. Each day late counts as a separate violation carrying a fine of up to $5,000, and the 2018 amendments to the statute left these reporting deadlines unchanged. Subsection (E) of R.S. 51:3074 sets the outer limit for the notices themselves: the most expedient time possible and without unreasonable delay, but not later than sixty days from discovery of the breach. IDScan puts discovery on or around 1 September, which places the statutory deadline at the end of October. Neither date is checkable from outside yet. Whether IDScan has filed with the Consumer Protection Section, and on what date, is not public, and no state attorney general or federal regulator had announced enforcement action as of 15 September. Nothing here asserts the company has missed anything; the dates are written down so the record can be checked once it exists.
One detail from CyberInsider belongs here rather than in the timeline. IDScan’s breach notification page initially carried a noindex directive, which keeps a page out of search results, and the notice went largely unnoticed until TechCrunch reported it on 10 September. A notice that exists and cannot be found occupies an odd position: it satisfies the posting, and it does not do the thing posting is for. For a population that has no relationship with the company and no way to know the company holds their licence, search is the only discovery mechanism there is.
How a genuine scan gets replayed
Consider what an attacker does with one record. The target is not the venue that scanned the licence originally, because that transaction is over. The target is any remote onboarding flow that accepts a document image: a challenger bank, a lender, a crypto exchange, a gig-work platform, a telco doing a SIM swap, a payroll system.
Those flows ask the applicant to photograph a document and often to take a selfie. Between the phone camera and the verification service sits a capture stack the applicant controls. An attacker with a leaked capture set does not photograph anything. They present the stolen files to that stack directly, through a virtual camera, an instrumented build of the app, or an intercepted upload, so that the verification service receives a genuine multi-spectral capture of a genuine licence that has never been near the attacker’s hands.
This is the difference between a presentation attack and an injection attack, which we have set out in detail elsewhere. A presentation attack holds something up to a camera and can be caught by asking whether the thing in front of the lens is a real document or a screen. An injection attack never goes in front of a lens. The same distinction governs how deepfakes bypass liveness checks on the selfie side of the same flow, where a leaked portrait is the reference image a face swap needs.
Why document checks return a pass
Three of the four checks in that diagram are asking about the document. The document is real, so they pass, and they pass correctly. A document-authenticity engine that flagged this submission would be wrong on its own terms, because the artefact it is examining genuinely is a correct capture of a valid licence. The failure is not a detection failure in the ordinary sense. It is a category error in what the system was asked to establish.
Barcode parsing behaves the same way. The back photograph travelled with the front, so the machine-readable zone decodes cleanly and cross-matches the printed data. A database check against the licence number returns valid, and keeps returning valid until the holder learns there is something to report, which per the notification chain above may be never. The pattern generalises: it is the same reason high-volume eKYC pipelines struggle once the attacker stops fabricating and starts replaying.
James E. Lee of the Identity Theft Resource Center told TIME that high-quality government ID images make impersonation easier and can facilitate opening fraudulent credit lines. Edgar Whitley of the London School of Economics put the durability point more sharply in the same piece: you can reissue a new password but not a new face, and ID images can be used to create AI deepfakes. Both observations are about the asset, not about any particular vendor’s controls.
The one check that still separates
What survives the collision is the question of where the image came from. Path A has a live sensor behind it, producing frames now, with the optical and temporal characteristics of an actual capture event. Path B has a file. Everything downstream of the capture stack is identical, so the only place the distinction still exists is at the capture stack itself.
That reframes the control set. Document authenticity, barcode integrity and number validity are all necessary and none of them is sufficient any more, because a leaked corpus supplies correct answers to all three. The controls that retain discriminating power are the ones that interrogate provenance: whether the video stream originates from a physical camera rather than a virtual device, whether the frames carry the sensor noise and compression history of a real capture, whether the timing of the session is consistent with a person holding a phone, and whether the submitted image is bit-identical or near-identical to material seen before.
DuckDuckGoose builds detection for exactly that layer, and the honest framing of what it buys you is narrow: it does not tell you the document is fake, because the document is not fake. It tells you the image did not come from where the flow assumed it came from. For teams mapping their own coverage, the practical question is the one in how anti-spoofing works and where it stops working: which of your checks would return a different answer if the input were a perfect file rather than a live capture?
What an IDV team should change
Four changes follow from the analysis above, in rough order of how quickly they can be made.
Stop treating a clean document result as an identity result. Split the two outcomes in your decision logic so that "the document is authentic" and "this submission is a live capture by the holder" are separate signals with separate thresholds. Most stacks collapse them, which is what makes a replayed genuine capture an automatic pass.
Instrument the capture path, not just the artefact. Virtual camera detection, device attestation and stream integrity checks are the controls whose answers actually change between the two paths. If the flow accepts an uploaded file at all, that branch has no capture-path evidence by construction and should carry a different risk weight.
Hash and check for reuse across your own population. A corpus this size will produce the same licence arriving at different institutions, and sometimes at the same institution twice. Near-duplicate detection on submitted document images is cheap and it is one of the few signals that gets stronger as the leaked corpus circulates more widely.
Reconsider what a licence number proves in step-up authentication. Any process that verifies a caller or a customer by asking for a licence number, an address and a date of birth is now verifying that the other party has access to a commodity dataset. The same reasoning applies to knowledge-based checks generally, and it is the reason attacks that bypass KYC increasingly start from real data rather than invented data.
Two further reference points for teams doing this mapping. The distinction between checking a document and checking a face is set out in liveness detection versus deepfake detection, and the way these attacks are recognised once they are in flight is covered in how AI impersonation attacks are detected. Markets where remote onboarding volume is highest tend to see this first, which is the pattern behind regional targeting of high-volume onboarding.
What this article could not verify
The six-file record structure, including the infrared and ultraviolet layers, comes from Krebs’s inspection of the Nexus listing. TIME repeated the claim as something the service itself advertised, but no outlet has independently examined the corpus, so every account of the file structure traces back to that one inspection and to the seller's listing. IDScan has neither confirmed nor denied that the fuller image sets came from its systems, and has not disclosed how the access occurred. BleepingComputer and TechCrunch both report that scans and photographs were taken, without describing the spectral layers. IDScan has not addressed the image question publicly at all. The analysis in this piece depends on that file structure being accurate, and a reader should weigh it accordingly.
Record counts differ across sources. The Nexus listing advertised 153 million licences. IDScan has not confirmed any figure. ClassAction.org cites more than 170 million individuals in North America, which appears to aggregate licences with the separately listed identity cards, travel documents and medical cards rather than to contradict the 153 million.
How the attacker obtained the data is unreported. None of the sources read for this article names credential theft, an exposed API or a misconfigured storage bucket, and IDScan says only that an unauthorised third party may have accessed and copied customer information from cloud accounts. Which of IDScan’s business customers were affected is also unreported, as is whether the notification chain described above has actually run. The Louisiana analysis assumes Louisiana law governs; a processor holding records on residents of many states and two countries will face overlapping obligations, and nothing here should be read as advice on this company's compliance.
Whether any of these captures have actually been submitted to an onboarding flow is also unreported. No source read for this article describes an observed campaign, an account opened with a record from this corpus, or a verification vendor reporting a change in what it is seeing. The replay path set out above follows from the reported file structure and from how document checks are built. It is a mechanism argument, not a description of something anyone has watched happen.
The reported inclusion of a United States government Common Access Card in the corpus, and the report that the Defense Secretary’s licence was among the records, both come from single sources and neither has an official response attached. We have not repeated them as findings. For the broader pattern of document-led fraud we have written up previously, see how forged photo IDs bypass hiring verification and the mechanics of reused document scans.
Methodology and what we checked
Eight news sources and three statutory texts were opened and read for this article. The incident reporting comes from KrebsOnSecurity, TechCrunch, BleepingComputer, Help Net Security, TIME, eSecurity Planet, CyberInsider and ClassAction.org. Where a figure appears in only one of them, Table 3 says so.
The statutory analysis is taken from the text rather than from commentary. The definition of personal information and of biometric data was read at legis.la.gov; the notification duties and the sixty-day deadline in R.S. 51:3074 were read at the legislature’s page for that section; the private right of action in 51:3075 and the Attorney General reporting rule were read from the full chapter text. Two sources we could not open are excluded and none of their detail is used: govinfosecurity.com returned 403, and IDScan’s own security notice page returned 404 at the URL we tried, so every description of that notice here is at one remove, through outlets that quoted it.
No DuckDuckGoose product analysed any material connected to this incident. Nothing in this article is a detection finding, and no claim is made about the authenticity of any specific file.
Frequently Asked Questions About This Breach
Was my driver’s licence in the IDScan breach? There is no public lookup, and you probably have no direct relationship with IDScan. Its customers are venues, hotels, rental desks and dispensaries that scanned your licence at the door or the counter, so your exposure runs through those businesses. IDScan says it is notifying affected individuals and offering credit monitoring and identity repair.
Why does a stolen licence scan matter more than a stolen licence number? A number can be reissued by the state and watched by a monitoring service. A correct photographic capture of the document, especially the infrared and ultraviolet layers, is the exact artefact a document-authenticity check asks for, and neither the image nor the face in it can be reissued.
Can document verification detect a replayed genuine scan? Not by examining the document, because the document is genuine. Detection has to move to the capture path: whether the image arrived from a live camera rather than a file or a virtual device, and whether the same image has been seen before.
Is IDScan legally required to tell me? Under Louisiana R.S. 51:3074(D), a company that maintains data it does not own notifies the owner of the data, which here means its business customers rather than you. IDScan has said it is notifying individuals in an abundance of caution, which is a step beyond that subsection. Notices themselves fall due within sixty days of discovery under subsection (E).
Has anyone been charged? No. The FBI’s New Orleans field office has an open investigation, the Nexus service went offline within hours of Krebs publishing, and as of 15 September no class action had been filed, although plaintiffs’ attorneys are publicly investigating claims.














