The rapid appearance of newly scanned driver’s licenses—often within hours or a day, according to several victims who encountered their scans at rental car companies and other businesses—suggests that the Nexus data marketplace may have near-real-time access to information processed by third-party ID-scanning services. Krebs reported that the number of driver’s licenses listed for sale increased by nearly 400,000 in a single 24-hour period, indicating that the alleged breach may still be active and that additional identity documents could soon be exposed.
According to publicly available information, IDScan.net is an identification-scanning company based in New Orleans. The company has announced an exclusive arrangement with Planet 13. Hertz and at least 11 other businesses are also listed as customers. IDScan.net’s 2025 identity fraud report states that its technology can capture scans across both infrared and ultraviolet spectrums.
IDScan.net representatives did not immediately respond to emailed questions. A company spokesperson later told KrebsOnSecurity that the matter is under investigation. Representatives of the rental car company involved also did not immediately respond to requests for comment.
The possibility that criminals can obtain a person’s driver’s license scan for a fee raises serious identity theft and privacy concerns. Many people’s personal details—including current and former addresses, Social Security numbers, and demographic information—have already been exposed in previous data breaches affecting millions, and in some cases billions, of people worldwide.
This alleged driver’s license data dump is especially concerning because it reportedly includes ultraviolet and infrared images that may contain security features not visible in standard photographs. The Nexus marketplace went offline within hours of KrebsOnSecurity’s report, but the shutdown also means users currently have no reliable way to determine whether their identity documents were included. An ongoing FBI investigation may provide more answers about the source of the stolen scans and the scope of the breach.
Source: arstechnica.com


