🛡️ Defense & Cyber
A Dark-Web Service Listed 153 Million License Scans. Reissuing Them Could Take Every DMV in America Up to 5 Years.
Nexus said it was selling six-image scans of 153 million driver's licenses, as few as 38 million people if regulars were scanned again and again, and 153 million only if every record is unique. Divide that by the nation's annual renewal flow and the only real remedy is out of reach.
Once a year. That is roughly how often the average licensed American driver hands a card to a scanner run by IDScan.net, a Louisiana company that says it performs 21 million verifications a month at 20,000 locations, which works out to 252 million scans a year against 235 million licensed drivers. Most of those drivers have never heard of it. On September 1, Brian Krebs reported that a dark-web service called Nexus, which had surfaced on a Russian-language crime forum the day before, was selling 153 million of those scans.
IDScan confirmed a breach on September 10, after a September 4 notice that said an unauthorized party "may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud," and that the data "may include full names and driver's license or other government-issued identification numbers." It has not confirmed the seller's inventory. Nexus advertised one anyway: 153 million driver's licenses from the United States and Canada, each as a set of six images including infrared and ultraviolet passes, plus 10 million identity cards, 3 million travel documents, and about 580,000 medical cards, dispensary cards among them. According to Krebs, Defense Secretary Pete Hegseth's license was listed at $100. The FBI is investigating the service, and at least eight federal complaints were filed within the week. Nexus went dark within days.
Coverage has compared it to Equifax, which exposed 147 million people in 2017, but a license scan is a different object from a credit file, and the difference decides what a remedy can fix. Equifax leaked numbers. If Nexus's inventory is accurate, this leaked the card itself, including the infrared and ultraviolet layers that scanners use to tell a real license from a fake. So: if the remedy for a stolen card is a new card, what would that take?
Scans Are Not People
Start with who is in the archive. At IDScan's stated volume of more than 21 million scans a month, 153 million records is at most about seven months of throughput, or a deduplicated slice of the year-plus that Nexus claims. That 153 million is a ceiling on people, not a count, because bars, casinos, dispensaries, and rental counters scan the same regulars repeatedly while most drivers are scanned rarely or never. If the average archived person appears twice, the set holds about 76 million people; if the regulars dominate and the average is four, it holds 38 million. Nobody has said how many records are unique.
| Quantity | Number | Divided by | Result |
|---|---|---|---|
| Records advertised on Nexus | 153 million | 21 million IDScan scans per month | 7.3 months of throughput |
| People in the set, at 2 to 4 scans each | 38 to 76 million | 235 million U.S. licensed drivers | 16% to 32% (ceiling 65% if every record is a different person) |
| For scale: Equifax, 2017 (share of drivers if all 147 million drove) | 147 million people | 235 million U.S. licensed drivers | 63% |
The Reissue Math
A stolen credit card number is fixed by mailing a new card, which is why card breaches, however large, fade. Try that here. It fails twice over, because replacement fees run $11 to $45 by state, so reissuing a license to everyone in the set would run from $0.4 billion, at 38 million people paying $11, to $6.9 billion, at 153 million paying $45. Time is the harder limit, because states renew licenses on four- to eight-year cycles, so the country's motor vehicle departments turn over roughly 29 to 59 million licenses a year. That is a renewal rate, not a ceiling on card production, so the years below are an upper bound. Reissuing 153 million would consume that entire renewal flow for 2.6 to 5.2 years; reissuing 38 million, eight to fifteen months. Nobody has proposed it.
A new card fixes less than it sounds. California will issue a new license number to an identity-theft victim who files a fraud review. Texas decides case by case. Florida will not change the number, because Florida derives it from your name, date of birth, and sex; a new card carries the same number. Then there is the design: if the seller's inventory is right, the stolen sets include the infrared and ultraviolet security layers that defeat the remote, image-based checks rental apps, casino cages, and bank onboarding flows rely on, so a new number helps against lookups but a same-design card re-exposes the layers. A forger's kit does not expire when the victim's card does.
| Reissue input | Low | High | Source |
|---|---|---|---|
| Replacement fee per license | $11 | $45 | State DMV fee schedules |
| People to reissue | 38 million | 153 million | Low scenario (4 scans per person) to absolute ceiling (every record unique) |
| Fees to reissue everyone | $0.4 billion | $6.9 billion | Calculated |
| Renewal cycle | 4 years | 8 years | State renewal rules |
| Steady-state renewals per year | 29 million | 59 million | 235 million divided by cycle |
| Years of the full renewal flow, 38 million low case to 153 million high case | 0.6 | 5.2 | Calculated; treats every record as a U.S. license |
The Retention Paradox
In several of the largest states where these scans are taken, the images were not supposed to be kept. California's Civil Code permits a business to scan a license only for enumerated purposes, to verify age or authenticity, to meet a legal record-keeping requirement, to approve a payment, or to prevent fraud, and bars retention outside them. Illinois, Arizona, and Texas go further and bar retention after an age check, and Montana caps it at 180 days, according to a 2026 survey of state scanning laws. Two things cut the other way: the fraud-prevention and record-keeping exceptions plausibly cover rental agencies, casinos, and dispensaries, and whether vendor-held images even fall under statutes written about information obtained by scanning is untested; at least one analysis argues IDScan had no legal duty to delete them. Either the archive came from uses the law allows, or from configurations that kept what it says to discard; the answer decides who pays. IDScan has not said which, and nine days into an FBI investigation with eight lawsuits pending, that silence is ordinary.
What the Precedents Say It Costs
Equifax settled for $575 million, rising to $700 million, which is $3.91 to $4.76 per person. Applied to 38 to 153 million people, that rate puts the exposure at $150 to $730 million. Against that, the FTC logged $12.5 billion in reported fraud losses in 2024 alone. Settlements are priced per head, once; fraud is priced per victim, repeatedly.
What You Can Do
If you have handed a license to a scanner at a rental counter, casino, or dispensary in the last two years, there is a meaningful chance your card is in the set, so act as if it is: freeze your credit at all three bureaus, free, and take any identity monitoring IDScan offers affected customers. Customers named in coverage of IDScan include Hertz, Target, FedEx, Caesars, and a thousand-plus dispensaries; none has been identified as a source. If you live in California, file the DMV's fraud review and get a new number. If you live in Florida, a new card will not change it, so watch for accounts opened in your name instead.
If you run a business that scans IDs: ask your vendor two questions in writing. What does the scanner keep, and for how many days? For a bare age check in California, Illinois, Arizona, or Texas, the scanning statutes generally allow no retention at all, so a configuration that keeps images anyway may expose you to liability alongside the vendor.
If you write policy: the fix is not a bigger settlement. Twenty-one states already issue mobile driver's licenses that can prove "over 21" without handing over a single other field. A venue that accepts one never holds a scan to lose.
Limitations
Every fact here comes from press coverage and from IDScan's notice as relayed by that coverage, via search summaries because the primary pages were unreachable. IDScan has confirmed unauthorized access to customer data; the 153 million count, the six-image sets, and the year-long duration rest on the seller's advertisement and Krebs's reporting. Our people range assumes two to four scans per archived person and treats every record as American, though an unquantified minority are Canadian; the renewal figure treats renewals as the DMVs' whole throughput, ignoring new issues, duplicates, and the surge capacity shown before REAL ID deadlines, so the years are an upper bound. Settlement comparisons are per-person precedents, not predictions, and whether the state statutes reach images held by a vendor on a customer's behalf is an open legal question, not a finding.
The Strongest Case Against This Analysis
The strongest objection is that the image set is seller puffery. IDScan's notice describes names and identification numbers, not six-image capture sets, and Nexus vanished before anyone verified a sample at scale. If the real breach is the narrower one the notice describes, this piece measures a remedy for a theft that may not have happened. Reissuing licenses is also a remedy nobody has proposed, so measuring DMV capacity against it is a straw man. Freezes and fraud alerts scale fine. A license number is a weaker key than a Social Security number. The retention question may resolve in IDScan's favor.
That argument is right about the uncertainty, which is why every number here is a bound, and wrong about what the bounds are for. IDScan's own product materials describe scanners that capture exactly the infrared and ultraviolet passes Nexus listed; whether the company retained those passes or only processed them is the unanswered question, and Nexus claimed a year of exfiltration. Freezes protect credit files and do nothing at the hotel desk, the casino cage, or a bank's onboarding flow, which authenticate you with exactly the images at issue; the reissue calculation shows that the one remedy that would work at the point of misuse cannot be delivered, which is why the lever is retention.
The Bottom Line
A vendor most Americans have never dealt with directly held card images for a sixth to a third of the country's drivers, and for more than a year, if the seller is to be believed, someone else held them too. The number on the card cannot be changed in Florida, the card itself cannot be reissued in less than months to years of national renewal capacity, and the security features that made the card trustworthy may now be a download. Under the age-verification statutes of several of the largest states, much of that archive looks like it should have been deleted within days; whether those statutes reach a vendor's copy is untested, and unanswered. The 153 million is not the number that needs explaining. The year is.