The 153 Million License Dump Is Not a Password Problem
A Priwall perspective on the idscan.net breach and what individuals and enterprises should actually do about it.
Published on the Priwall blog · September 2, 2026 · by Tom Daly, CEO
| Records | Document type |
|---|---|
| 153,000,000+ | Driver's licenses |
| 10,000,000 | Identification cards |
| 1,900,000 | Travel documents |
| 1,300,000 | International driver's licenses |
| 579,000 | Medical cards, including marijuana dispensary cards |
| 429,000 |
Common Access Cards
Government-issued IDs granting physical access to secure federal facilities |
| 91,000 | Residence cards |
| 77,000 | Employment authorizations |
| 5,000,000 | Other identity documents |
Krebs, working with security researcher Zach Edwards and Cybera's Larry Baldwin, traced the source to idscan.net, a New Orleans-based identity verification vendor. The FBI's New Orleans field office opened an inquiry the same day. Nexus went offline hours after the story published — but the underlying dataset had already been sold, and idscan.net had been silently exfiltrated for over a year.
The customer list is the story
Idscan.net's own trust page and public records (per security researcher vx-underground and Protos coverage) list its customers as: Hertz, FedEx, Target, Shell, AMC Theaters, DraftKings, Dutchie, Chevrolet (GM), GameStop, Jack Henry, MRI (Checkpoint ID), Polaris, Simmons Bank, LendingUSA, Circa Resort & Casino, Planet 13, Rouses Market, Caesars Entertainment (disputed), Motorola Solutions, MeridianLink, and — critically — the US Coast Guard Academy. Idscan processes 21+ million verifications per month across 20,000+ locations.
That customer footprint explains why:
Records include the driver's license of US Defense Secretary Pete Hegseth, an FBI assistant director, and multiple security researchers.
429,000 CACs are in the dataset — likely from Coast Guard Academy processing, but consequential for anyone in the DoD/cleared community whose CAC has been scanned by an idscan-powered kiosk.
Timestamps line up with car rentals from Hertz, hotel check-ins at the Aria, dispensary purchases at Planet13, and FedEx alcohol deliveries.
Jack Henry — the financial-services core provider on idscan's client list — disclosed a concurrent cyber incident the same week (per fintech analyst Jason Mikula), which nobody has confirmed is related, but which every bank on Jack Henry's core should be asking about.
This isn't one company's problem. It's a chain-of-custody problem that touches almost every American who has rented a car, stayed at a hotel, walked into a dispensary, opened a bank account, or been through federal onboarding in the last three years.
What makes this dump different
Most breach advice — "change your password, freeze your credit" — assumes the stolen artifact is a secret you can rotate. A driver's license image is not rotatable in any practical sense.
Nexus offered six image files per person: front, back, plus infrared and ultraviolet captures. The IR/UV scans are exactly the signals that downstream KYC vendors use to decide whether a submitted document is authentic — and idscan.net's own documentation confirms it captures under both. Combined with a cheap deepfake liveness bypass, this dump is a functional starter kit for:
Synthetic and full-takeover identity fraud at any institution that accepts a document upload plus a selfie — banks, brokerages, crypto exchanges, telecoms, unemployment and tax portals.
Executive and government-official targeting. For any executive, board member, or cleared employee, this data enables spearphishing that opens with verifiable personal details and physical-world pretexting.
Corporate account takeover through the employee. The chain we care about most: license image + broker-sourced home address, phone, and relatives → SIM swap → MFA reset → SSO takeover → lateral movement.
Physical-world fraud — vehicle rentals, apartment leases, and medical identity theft. Note the 579,000 medical cards; that category is growing and punishing to unwind.
Life-safety exposure for the most vulnerable. As Larry Baldwin at Cybera pointed out, this dump is uniquely dangerous for domestic-violence survivors and witness-protection participants — populations who cannot rotate their face and whose safety depends on not being locatable.
This isn't the first IDV vendor breach — it's the biggest one so far
The identity-verification vendor category has been failing publicly for years, and the frequency is accelerating:
Sumsub — a KYC provider used by major crypto exchanges — disclosed in early 2026 that an intruder had been inside its support environment for 18 months (Europe-Infos).
Persona, the identity vendor behind Discord's age verification, left 2,456 files of its government-dashboard codebase on a public FedRAMP server in February 2026 (Fortune).
IDMerit left 1 billion identity records exposed on an unprotected MongoDB database (Forbes).
A Mysterium VPN report documented 88 identity-verification breaches since 2011 (Security Affairs).
The pattern is consistent: verify, store, forget. Then a year or more later, someone discovers a private database on a Russian cybercrime forum with your face in it.
Does it make sense to get a new driver's license?
For most people: no, and only as one piece of a larger response — not as the response.
A new license number helps in narrow cases: if your number is being actively used for fraud, if you're a plausible high-profile target, or if your state actually issues a new number (many just reissue the same one on a new card). Most states will only reissue a new number with a police report or documented fraud.
What a new card doesn't fix: the stolen images are already circulating, your name, DOB, address, and photo don't change, and the biometric-grade IR/UV captures remain valid-looking to any verifier who doesn't cross-check issuance dates.
For executives, cleared personnel, DV survivors, and anyone whose license appears in the Nexus sample: yes, request a reissue with a new number where your state permits, and update it with your bank, brokerage, and employer HR.
CAC holders: coordinate with your unit security officer or FSO. A CAC compromise is a chain-of-command issue, not a personal action item.
What individuals should do this week
Freeze credit at all three bureaus (Equifax, Experian, TransUnion) plus ChexSystems and NCTUE. Freezes are free and block the most common downstream fraud paths.
Lock your mobile carrier account with a port-out PIN and, where the carrier supports it, a port freeze. SIM swap is the highest-leverage attack that follows an ID dump.
File an IRS IP PIN so a criminal can't file a return in your name.
Move off SMS-based MFA for banking, brokerage, email, and any SSO-connected account. Use hardware security keys or passkeys.
Remove your personal data from the broker ecosystem. The license dump is one input; the amplifier is the 300+ people-search sites that publish your address history, relatives, and phone numbers. Cutting that surface is the single highest-leverage move a non-technical person can make. This is exactly what Priwall does.
Reissue your license if you're a plausible target and your state supports a new number.
The Fourth Circuit recently ruled that dark-web exposure of driver's license data is sufficient for standing in class-action litigation. If you're in that circuit and your data is confirmed in Nexus, you may have a live claim.
What enterprises should do this quarter
Assume every employee license is compromised. Rotate any workflow that treats a license image as an authentication factor — expense reimbursements for travel, remote I-9 refreshes, wire-approval flows.
Audit your identity verification vendor. In writing, ask them: where do you store scanned images, for how long, in what jurisdictions, and have you had unauthorized access in the last 24 months? Get an updated SOC 2 with the storage and retention boundaries called out explicitly.
If you're a Jack Henry-cored bank or fintech, ask about the concurrent cyber incident disclosed the same week idscan was outed. Correlation is not causation — but you're entitled to know.
Harden executive and board coverage. Assume every VP+ has a full-fidelity license record in criminal hands. The right response combines data-broker removal, credit and telecom freezes, SIM-swap protection, and a physical-security review for those individuals. This is the core of Priwall's Ultimate and executive coverage tiers.
Deploy phishing-resistant MFA (FIDO2 / passkeys) across SSO — especially for anyone whose license appears in Nexus. Push-notification MFA is not sufficient against an attacker who can pass a "verify your identity" step with a genuine document.
Refresh your incident-response playbook for the scenario this breach exposes: a trusted vendor was silently exfiltrated for 12+ months and you didn't know. That is the actual lesson.
The Priwall view
The identity-verification industry keeps treating documents like passwords: issue, verify, store, forget. They aren't passwords. They're biometrics with a paper backing, and this dump — following Sumsub, Persona, and IDMerit — proves that any vendor storing raw scans is a single point of failure for tens of millions of people. The right architecture is verify and discard — or verify against a cryptographic hash — not "store the UV scan indefinitely because a Fortune 500 customer asked us to."
The right personal defense is to shrink your data-broker footprint so that a stolen license can't be paired with your address, relatives, and phone to become a full takeover kit. A new license card, by itself, is theater. Reducing the surrounding data exhaust — and hardening the accounts a criminal would attack next — is what actually moves risk.
If you or your team need help getting started, reach out. We do this every day.
Priwall is an open-data and PII removal operations layer for individuals, executive protection teams, and enterprises. Clarity builds trust.
Sources:
Brian Krebs, KrebsOnSecurity, "FBI Probes Service Selling 153M+ Drivers Licenses," Sep. 1, 2026.
Dan Goodin, Ars Technica, "My driver's license is one of 153 million for sale on a new dark website," Sep. 2, 2026.
Zack Whittaker, TechCrunch, "It sure looks like hackers breached a major ID card verification service," Sep. 2, 2026.
Yahoo News, "FBI investigating 153 million US and Canadian driver's licenses," Sep. 2, 2026.
Malwarebytes Labs, "153M+ driver's licenses for sale on new dark web platform," Sep. 2, 2026.
CyberInsider, "153 million driver's licenses exposed in suspected IDScan breach," Sep. 2, 2026.
vx-underground, customer list, Sep. 2, 2026.
Protos, "150 million IDs allegedly stolen — including Pete Hegseth's," Sep. 2, 2026.
Europe-Infos, "Identity-Check Vendor Sumsub Says Hack Went Undetected for 18 Months," Mar. 23, 2026.
Security Affairs, "88 ID Verification Breaches Show the Cost of Collecting Identity Data," Aug. 26, 2026.
Ready to try Priwall by mePrism yourself?
If you are an individual executive evaluating personal coverage outside an employer-funded program, you can start with a free exposure scan.
Sign up for Priwall by mePrism coverage.Tom Daly is the founder and CEO of Priwall by mePrism, the enterprise open-source data-removal platform used by security, executive-protection, and digital-risk teams to shrink broker exposure across 700+ U.S. data brokers. He writes on data privacy, cybersecurity, and constitutional privacy at the Priwall blog and on LinkedIn.