IDScan.net, the identity-verification company whose scanners sit behind the counter at Hertz, Target, FedEx, GameStop and thousands of cannabis dispensaries, is now facing four class-action lawsuits after a dark-web marketplace started selling 153 million stolen driver's license scans that researchers traced back to its systems. The suits, filed this week in Louisiana where the New Orleans-based company is headquartered, accuse IDScan of failing to protect the identity documents its corporate clients scan every time a customer rents a car or buys age-restricted goods.

The breach itself surfaced three days earlier. Security journalist Brian Krebs reported on September 1 that a new dark-web identity-theft service called Nexus was selling more than 153 million U.S. and Canadian driver's licenses, plus 10 million ID cards, 3 million travel documents and 579,000 medical cards, including marijuana dispensary cards. Krebs and independent researcher Zach Edwards linked the trove to IDScan by matching timestamps on stolen licenses to the exact moments their owners had handed an ID over at a Hertz counter. Among the records: a driver's license belonging to U.S. Defense Secretary Pete Hegseth, listed on Nexus for $100.

RelatedAssuranceAmerica Breach Hit 6.9M Driver's Licenses

How scanned IDs allegedly ended up on a dark-web marketplace Diagram showing IDScan's scanners at client businesses like Hertz, Target and FedEx feeding a central database, which was allegedly breached and the data resold on the Nexus dark-web platform. WHERE THE DATA CAME FROM Hertz counters Target, GameStop FedEx, Caesars 1,000+ dispensaries IDScan.net database scans from every client above, in one place "Nexus" dark-web service 153M+ licenses listed for sale Krebs and researcher Zach Edwards matched leaked-record timestamps to real Hertz rental scans genztech.blog
Fig 1 IDScan's scanners sit behind the counter at car-rental, retail and dispensary chains. Researchers say the data those scanners collected ended up, unaltered, on a dark-web resale platform.

How much data are we actually talking about?

Nexus's own listings, verified against sample records by Krebs, break down like this:

Document typeRecords listed
Driver's licenses (U.S. & Canada)153 million+
State/government ID cards10 million
Travel documents3 million
Medical cards (incl. dispensary cards)579,000

That's not a leaked password list. These are photographs of physical government documents, the kind that carry a full legal name, date of birth, address, license number, photo and often a signature, all in one image file. A stolen password can be reset in thirty seconds; a driver's license number tied to a scanned photo of your face cannot.

Why does IDScan have this much data in the first place?

IDScan makes the hardware and software that businesses use to check IDs quickly, and its systems are common wherever a business needs to verify age or identity at speed: car rental counters, gun shops, liquor and cannabis retailers, hotels, and financial services firms. Every scan gets extracted into structured data and, depending on the client's setup, retained on IDScan's side for compliance or fraud-prevention purposes. The company's client list reported in coverage of the breach includes Hertz, Target, FedEx, GameStop, Motorola Solutions, financial-services firm Jack Henry, Caesars Entertainment, and cannabis retail chain Planet 13, among more than 1,000 dispensaries nationwide. None of those companies scanned the IDs themselves in a way that put them at fault; the concentration risk was created by routing everyone's scans through one third-party vendor's database.

  1. Week of Aug 25Nexus launches on the dark web, advertising a new identity-theft data setfirst quietly promoted in criminal forums
  2. Sep 1, 2026Brian Krebs publishes the first public report, sourcing 153M+ license records to IDScanFBI's New Orleans office opens an inquiry
  3. ~Sep 1-3IDScan begins notifying business customers; Nexus itself goes offlinestolen data already in criminal hands regardless
  4. Sep 4, 2026Four class-action lawsuits filed against IDScan.net in Louisianaallege the company failed to protect client data

What do the lawsuits actually claim?

The suits filed this week allege IDScan failed to adequately protect the identity information it collected on behalf of clients like Hertz, a standard negligence and data-breach theory: that a company holding sensitive personal data owes a duty of care to secure it, and that duty was breached. Law firms including Markovits, Stock & DeMarco and Hall Attorneys had already opened investigations soliciting affected individuals before the formal filings landed. IDScan has not issued a public statement acknowledging the breach and did not respond to press inquiries from BleepingComputer or other outlets covering the story. The company's silence is itself becoming part of the story: three days after Krebs' report and a federal investigation, there is still no official confirmation of scope, cause, or how Nexus obtained the records in the first place.

RelatedLiteLLM breach: 40 minutes, 2,488 companies exposed

Who actually gets hurt here, and what should they do?

Anyone who has rented a car, bought age-restricted goods, or shown ID at a business using IDScan's systems in the past several years is a plausible match. Because a driver's license photo can't be reissued the way a credit card number can, the practical defenses are narrower than in a typical breach: freeze credit with all three bureaus, watch for new accounts opened in your name, and be alert to phishing that references real personal details pulled from the leaked scans, since attackers with a genuine photo ID can pass identity checks that would normally catch a scammer. If your state DMV or an affected business sends a breach notice referencing IDScan, treat it as real; this is one of the rare cases where the underlying document itself, not just an account, is compromised.

What to watch
  • Whether IDScan confirms anything. No acknowledgment yet means no confirmed cause, timeline, or total scope. A formal breach notification would be the first hard data point beyond Krebs' reporting.
  • The FBI investigation's findings. The New Orleans field office's inquiry could establish how Nexus obtained the data, whether it was a direct breach, an exposed database, or an insider, which changes the legal exposure for IDScan considerably.
  • More lawsuits. Four suits filed in the first week is typically the opening wave, not the total; expect consolidation into a multidistrict litigation if the class grows as expected.
  • Client-side fallout. Watch whether Hertz, Target or other named clients face their own separate claims for continuing to route customer data through IDScan after this becomes public.

Our take

This is a supply-chain breach in the purest sense: none of the businesses whose customers are affected did anything wrong at the point of sale, they just all happened to route ID verification through the same vendor. That's exactly the structural risk identity-verification middlemen create, and it's worth remembering the next time a store asks to scan your license instead of just glancing at it. The Hegseth detail matters less as gossip and more as proof of scope: if a cabinet-level official's license ended up in a $100 dark-web listing, the "it won't be my data specifically" assumption doesn't hold for anyone who has rented a car in the last few years. Until IDScan says something concrete, the lawsuits are the only mechanism forcing disclosure at all.

Original analysis by GenZTech Team. Source: BleepingComputer.