The FBI’s New Orleans field office has opened a formal inquiry into a dark web marketplace that claims to be selling digital scans of more than 153 million American and Canadian driver’s licenses, and the fallout is now moving from cybersecurity blogs into federal court. At least four class-action lawsuits have been filed in the Eastern District of Louisiana against IDScan.net, the New Orleans-based identity verification firm that researchers say is the likely source of the leak, according to ClassAction.org. The case has gone from a single investigative report on September 1, 2026, to a multi-front legal and regulatory problem in under a week.

Independent journalist Brian Krebs broke the story on KrebsOnSecurity, reporting that a dark web identity theft service calling itself “Nexus” had begun offering scans of driver’s licenses, ID cards, and travel documents tied to people across the US and Canada. Krebs verified the claim was real by finding his own license scan in the data set, and other individuals he contacted confirmed their documents matched too. Working with security researcher Zach Edwards, Krebs traced the likely origin to IDScan.net, a company whose scanning technology sits behind ID checks at bars, rental counters, and dispensary registers nationwide.

What the FBI Is Actually Investigating

The FBI has not confirmed the scope of the breach, and it has been careful about what it will say publicly. TIME reported on September 3 that the bureau confirmed it was “looking into the incident” but declined to comment further “due to the ongoing nature of the investigation,” per its report at TIME. That is a standard holding statement, and it leaves open basic questions: how the data was obtained, whether it came from a single intrusion or an ongoing feed, and how many of the 153 million-plus records are duplicates, expired documents, or test data mixed in with real scans.

TechCrunch’s September 2 report captured the ambiguity well, framing the incident as something that “sure looks like” a breach of a major ID verification vendor without yet having a confirmed root cause, according to its coverage at TechCrunch. IDScan.net told Krebs it was investigating the matter but has not confirmed unauthorized access, named which systems were touched, or given a victim count. That gap between what the seller claims, what journalists have verified, and what the company and the FBI will confirm on the record is exactly why this case matters beyond one bad week for one vendor: it is a test of how identity-verification infrastructure holds up under public scrutiny.

Inside the Nexus Marketplace and Its 153 Million-License Claim

Nexus advertised its inventory in categories, not just a single dump. Malwarebytes reported the listing included more than 153 million driver’s licenses, over 10 million ID cards, more than 3 million travel documents or international IDs, and at least 579,000 medical cards, based on its review of the marketplace at Malwarebytes Labs. Tom’s Hardware cited a lower figure for the travel-document category, closer to 1.9 million, a discrepancy outlets have not reconciled as of this writing, per its report at Tom’s Hardware. Tom’s Hardware also reported that the listing reportedly included a scan tied to Defense Secretary Pete Hegseth, a detail that has drawn attention from national security reporters as well as consumer-tech outlets.

Techdirt’s analysis, published September 3, raised a more troubling possibility than a one-time dump: that the operators had what amounts to a live feed of IDs scanned through the compromised system, running for over a year, according to Techdirt. Researchers tracking the listing told outlets the driver’s-license count grew by close to 400,000 records within a single 24-hour window after the story broke, which suggests either an active pipeline still pulling in new scans or a seller drip-feeding a larger cache to build buzz. Either read is bad for anyone whose ID has passed through an IDScan.net terminal in the last year.

IDScan.net’s Client List Turns a Vendor Breach Into a Household-Brand Problem

Most people have never heard of IDScan.net, but they have likely stood in front of one of its scanners. The company says it processes over 21 million ID verifications a month for clients spanning car rental, retail, logistics, gaming, and cannabis retail, a client roster that includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry, Caesars Entertainment, and GameStop, along with more than 1,000 marijuana dispensaries across 19 states, according to reporting compiled by Krebs and corroborated by Yahoo News. That breadth is the real story here: a breach at a single back-end vendor can expose people who never dealt with that vendor directly, only with the household brand at the counter.

This is the same structural weakness that has hit other sectors this year. Shattered.io covered a similar dynamic in the McKesson breach, where a single healthcare data processor’s exposure rippled out to millions of patients who never signed up for anything with McKesson directly. When identity checks get outsourced to a specialist vendor, the blast radius of any single incident scales with how many downstream brands rely on that one company, not with how careful any individual consumer was at checkout.

What Nexus Claims to Be Selling

Document CategoryReported VolumePrimary Source
US and Canadian driver’s licenses153 million+Krebs on Security
ID cards10 million+Malwarebytes
Travel documents / international IDs1.9 million to 3 million (disputed)Tom’s Hardware / Malwarebytes
Medical cards (including dispensary IDs)579,000+Malwarebytes
24-hour growth in listed driver’s-license count~400,000 new recordsTechdirt

Add every category together and several outlets have pushed the combined document count past 170 million, though the headline figure that has stuck across most coverage, including Krebs, TIME, and Security Affairs, remains the 153 million driver’s-license claim, per Security Affairs. No outlet has independently verified the full count against a deduplicated data set, so treat the totals as the seller’s marketing claim until IDScan.net or the FBI confirms a real number.

Four Lawsuits Land in Louisiana Federal Court

Litigation moved fast. ClassAction.org opened an investigation into potential claims against IDScan.net within two days of Krebs’s report, and its tracking page now lists at least four class-action complaints filed in the US District Court for the Eastern District of Louisiana, according to ClassAction.org. Plaintiffs’ firms, including Markovits, Stock & DeMarco, are soliciting affected individuals for potential claims tied to the alleged exposure of driver’s-license images and personal data.

None of the suits has produced a ruling, a settlement figure, or an admission of liability, and IDScan.net has not confirmed the underlying breach on the record. The legal exposure is “alleged” at this stage, not adjudicated, and any consumer coverage of this story should hold that line carefully. What the filings do establish is that plaintiffs’ attorneys view a scanned government ID, tied to a name, date of birth, and license number, as different in kind from an email-and-password leak, and courts have historically been more willing to find concrete harm when government-issued identity documents are involved.

Timeline: How the Story Moved From Blog Post to Federal Docket

Date (2026)OutletDevelopment
September 1Krebs on SecurityFirst report on the Nexus marketplace and its 153M+ license claim
September 2TechCrunchConfirms circumstantial evidence pointing to a major ID verification vendor
September 2MalwarebytesBreaks down document categories: IDs, travel docs, medical cards
September 3TIMEFBI confirms it is “looking into the incident,” declines further comment
September 3TechdirtReports evidence of a live data feed running for over a year
September 3-4ClassAction.org / law firmsAt least four class-action suits filed in Eastern District of Louisiana

Why a Driver’s License Scan Beats a Password in the Wrong Hands

A leaked password gets reset in minutes. A leaked driver’s license does not expire on your schedule, and most states will not reissue one just because it showed up in a dark web listing. A scanned license carries a full name, date of birth, address, license number, photo, and signature in one image, which is close to a complete identity-fraud starter kit. Fraudsters use that bundle to open credit lines, port phone numbers, and pass “photo ID” checks at exchanges and banks that still rely on visual document review rather than live verification against a government database.

That is also why this breach cuts differently than the credential-stuffing incidents that dominate weekly security news. A stolen password can be rotated. A stolen face-and-license combination becomes a durable building block for synthetic identity fraud, where criminals blend a real person’s static data with fabricated details to open accounts that take months to trace back to a single source.

How This Compares to Other 2026 Mega-Breaches

IncidentRecords ExposedData Type
Nexus / IDScan.net153 million+ (disputed, unverified)Driver’s licenses, ID scans, medical cards
McKesson (ShinyHunters)284 million claimedHealthcare records
Manchester Airports Group8.7 millionPassenger and staff records
Trezor / SafePal53,487Crypto wallet owner data

The comparison matters because it shows the Nexus case sits in a different category than a typical customer-database leak: it is government-issued identity documents, not account credentials, and that changes both the fraud use case and the legal theory available to plaintiffs. Shattered.io’s earlier coverage of the original Nexus marketplace listing focused on the scale of the offer itself; this piece tracks what has happened since regulators and plaintiffs’ lawyers got involved.

The Identity-Verification Industry’s Exposure Problem

ID verification vendors sit in an unusual spot in the security stack. They exist specifically to capture and store the most sensitive static identity data a consumer has, often for retention periods set by state age-verification or anti-fraud rules rather than by the vendor’s own security posture. That means a single back-end compromise can outlast the retail relationship that generated the scan in the first place. If IDScan.net retained scans for months or years after a rental car return or a dispensary visit, the exposure window for any one consumer could be far longer than the “over a year” live-feed window Techdirt described.

Competing identity-verification vendors, including Jumio, Socure, and Onfido, have not been named in connection with this incident, and nothing in current reporting suggests the Nexus data came from anywhere other than IDScan.net’s systems. But enterprise security teams evaluating any vendor in this category are almost certainly re-reading their contracts this week, checking data retention clauses, breach-notification timelines, and whether their agreements require the vendor to carry cyber insurance sufficient to cover a nine-figure consumer class action.

What Consumers Should Do Right Now

Consumer-protection guidance circulating in the wake of this story is consistent across outlets, and it maps to the standard identity-theft playbook rather than anything Nexus-specific, since no company has published a way to check whether a specific license was included in the listing.

  • Place a credit freeze with all three major bureaus: Equifax, Experian, and TransUnion.
  • Watch for phishing texts, emails, and calls that reference the breach or ask you to “verify” your license number.
  • Use IdentityTheft.gov to build a personal recovery plan if you suspect misuse.
  • Consider requesting an IRS Identity Protection PIN to block fraudulent tax filings in your name.
  • Contact your state DMV if you believe your specific license was exposed, and ask about replacement options.
  • Check bank and credit card statements more often than usual for the next several months, not just this week.

If you want a broader sense of how much of your data may already be circulating from unrelated incidents, shattered.io’s guide to checking whether your data has leaked online walks through the major lookup tools. None of these steps require confirmation that your specific data appeared in the Nexus listing. Given that IDScan.net has not published a breach notification or a lookup tool, and the FBI investigation is ongoing, the safer assumption for anyone who has scanned a license at a rental counter, dispensary, or retailer in the past year is that they should act as if they were affected.

What Businesses That Rely on ID Verification Should Do

For the retailers, rental agencies, and dispensaries named in reporting, the immediate task is not public relations, it is contract review. Companies should confirm in writing what data their verification vendor retains after a transaction closes, how long it is kept, and whether encryption at rest was actually enforced rather than just listed in a sales deck. Security teams should also ask whether their vendor’s breach-notification clause has already been triggered, since a delay in notification can create separate legal exposure even if the underlying breach was not the retailer’s fault.

Longer term, this incident adds weight to arguments already circulating in enterprise security circles for reducing raw document retention: verify an ID at the point of transaction, store a hash or a pass/fail result, and avoid keeping the underlying scan longer than a regulator requires. A verification result cannot be resold on a dark web marketplace. A stored scan can.

Historical Context: From Equifax to Nexus

Large-scale identity-document exposure is not new, but the profile of what gets leaked has shifted. The 2017 Equifax breach exposed Social Security numbers and financial profiles for roughly 147 million Americans, and it reshaped how credit bureaus handle freezes and monitoring. What makes the Nexus case different is the document type: not a database record describing a person, but a photographic scan of the actual government-issued credential, which is harder to invalidate and easier to weaponize for in-person fraud, since a printed or displayed scan can pass a visual check that a stolen database record alone cannot.

That evolution tracks with a broader pattern shattered.io has followed all year: attackers increasingly target the specialist vendors that sit behind consumer-facing brands, from the Manchester Airports Group breach to the McKesson incident, rather than attacking retailers and airlines directly. The common thread is that a single mid-size vendor breach can now generate a consumer notification list larger than most Fortune 500 companies’ entire customer base.

Regulatory and Market Fallout to Watch

IDScan.net is privately held, so there is no stock price to track, but the regulatory angle is where this story will keep generating headlines. State attorneys general in Louisiana and any state with a large number of affected residents can open independent investigations under state data-breach notification laws, separate from the federal criminal inquiry the FBI has opened, a pattern shattered.io has tracked in cases like the CISA-driven remediation deadlines now facing federal contractors. Cannabis dispensaries in the 19 states where IDScan.net verifies purchases face their own layer of exposure, since many operate under state rules that require strict recordkeeping around age verification, and a breach touching that data could trigger state cannabis-regulator scrutiny on top of consumer litigation.

Insurers underwriting cyber policies for identity-verification vendors are also watching closely. A confirmed breach affecting more than 150 million documents, if it holds up, would rank among the largest identity-document exposures on record, and claims payouts at that scale tend to push the entire underwriting category toward higher premiums and stricter retention requirements industry-wide, not just for the company involved.

Predictions: Where This Story Goes From Here

  • More class-action suits will be filed and eventually consolidated into a multidistrict litigation, following the pattern set by the McKesson and Dropbox breach suits this year.
  • IDScan.net will face pressure to issue a formal breach notification with a confirmed victim count within weeks, once state attorneys general get involved.
  • At least one named client, most likely a large retailer or rental company, will publicly distance itself from IDScan.net or announce a vendor switch to manage reputational risk.
  • Cannabis regulators in one or more of the 19 states where IDScan.net verifies dispensary purchases will open a separate compliance inquiry tied to age-verification recordkeeping.
  • Expect renewed legislative attention on data retention limits for identity-verification vendors, an area that has lagged behind rules governing financial and healthcare data.

These are informed predictions based on how similar mega-breaches have unfolded this year, not confirmed developments, and they should be read as analysis rather than fact.

Frequently Asked Questions

Is the 153 million driver’s license breach confirmed?

Partially. Krebs on Security verified that real, current driver’s license scans were listed for sale on the Nexus marketplace, and the FBI has confirmed it opened an investigation. IDScan.net has confirmed it is investigating but has not confirmed unauthorized access, a root cause, or an official victim count.

Who is IDScan.net?

IDScan.net is a New Orleans-based identity verification company that processes more than 21 million ID checks a month for clients including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, Caesars Entertainment, and more than 1,000 marijuana dispensaries across 19 states, according to reporting gathered by Krebs on Security.

Has anyone been arrested or charged?

No. As of September 4, 2026, no arrests or criminal charges have been reported in connection with the Nexus marketplace or the alleged IDScan.net breach. The FBI’s investigation is ongoing.

How can I find out if my driver’s license was included?

No official lookup tool exists as of this writing. If you have used a rental car company, retailer, or dispensary that relies on ID scanning in the past year, security researchers recommend treating your information as potentially exposed and following standard identity-theft precautions.

What is the difference between this and a typical password breach?

A password can be reset immediately. A driver’s license scan includes a photo, signature, date of birth, and license number that do not change on demand, and replacing a physical license through a state DMV takes longer and is not always available purely because your data appeared in a leak.

Are the class-action lawsuits against IDScan.net likely to succeed?

That remains to be seen. At least four suits have been filed in the Eastern District of Louisiana, but none has reached a ruling or settlement, and IDScan.net has not admitted liability. Courts have historically been more receptive to breach claims involving government-issued identity documents than claims involving less sensitive data, which may work in plaintiffs’ favor.

Is the Nexus marketplace still active?

Reporting indicates the listing’s driver’s-license count was still growing as of early September 2026, roughly 400,000 records in a single 24-hour period according to Techdirt’s analysis. Marketplaces like this frequently go offline or rebrand once they draw law enforcement attention, so its current status can change quickly.

Does this affect people outside the United States?

Yes. Reporting from Krebs on Security and other outlets describes the listing as covering both US and Canadian driver’s licenses, meaning affected individuals are not limited to one country.