Handing your license across a rental counter is such a routine part of picking up a car that nobody stops to ask where that photo goes afterward. Cybersecurity researcher Brian Krebs just gave everyone a very good reason to start asking. His investigation traced a dark web marketplace selling more than 153 million driver's license scans back to a Louisiana company that verifies IDs for Hertz, and four class-action lawsuits landed within days.

The marketplace, calling itself Nexus, showed up in late August on a Russian-language cybercrime forum, advertising digital scans of more than 153 million driver's licenses from the U.S. and Canada. Thrown in with that haul: over 10 million state ID cards, three million travel documents, and 579,000 medical marijuana cards. A blank search with no filters entered reportedly returned an estimated 11.5 million pages of results. The U.S. has roughly 230 million licensed drivers total, which means whoever built this database had scans covering a meaningful chunk of everyone who's ever gotten behind the wheel.

Each leaked record wasn't just a flat photo. Records reportedly included six separate images per license: front and back shots under standard light, plus infrared and ultraviolet versions of the same document. That's not how a phone camera works; it's how the multi-spectrum ID scanners at rental counters, casinos, and dispensaries authenticate a license, checking for the holograms and security laminates that only show up under UV or IR light and can't be reproduced with a basic photocopier. Finding six-image sets attached to a single scan is a strong technical fingerprint pointing at professional verification hardware, not a stolen phone gallery.

Krebs found his own license listed as a free sample in the seller's opening pitch, along with his mother's, timestamped seconds apart and matching the exact moment they'd both handed their licenses to a Hertz counter agent. Larry Baldwin, a researcher at the cybersecurity firm Cybera, found a leaked scan of his own license with a timestamp matching a Hertz rental from a recent vacation. Security researcher Zach Edwards found his license tied to a Las Vegas trip; he hadn't rented a car that day, but he had scanned his ID at Planet13, a cannabis dispensary chain that has used IDScan.net for age verification since 2022.

IDScan.net is a New Orleans-based identity verification company that says it runs more than 21 million ID checks a month at over 20,000 locations. Its own website lists Hertz, Target, FedEx, Motorola Solutions, financial services firm Jack Henry, and Caesars Entertainment among its clients, though Caesars has since said it hasn't had an active account with IDScan's VeriScan product since February 2025 and never authorized the company to retain its data. IDScan hasn't issued a formal statement on the breach. A company spokesperson told Krebs only that "the updates you have provided have been welcome, and helpful to our team's investigation."

Four class-action lawsuits landed against IDScan.net on September 2 in the U.S. District Court for the Eastern District of Louisiana, IDScan's home turf. The plaintiffs are based in California, Florida, Georgia, and Louisiana, and every one of them traces back to a car rental. One filing states plainly: "On September 18, 2025, Plaintiff rented a car through Hertz in this District." Another plaintiff rented from Hertz-owned Thrifty. All four suits accuse IDScan of violating Federal Trade Commission data security guidelines and ask the court to force stronger safeguards on top of damages.

Don't expect a payday if you end up eligible to join one of these. Data breach class actions overwhelmingly settle for a mix of free credit monitoring, small reimbursement claims capped well under a hundred dollars, and legal fees that dwarf what any single plaintiff sees. The more consequential leverage here is the FTC angle: if the agency opens its own inquiry, it can impose a consent decree with specific, audited security requirements, the kind of mandate that actually changes how a company like IDScan stores and deletes data, rather than just writing a check.

The FBI's New Orleans field office opened a formal investigation on September 1, the same day Krebs published his findings. Within hours, Nexus disappeared from the dark web, its login page replaced with a message reading that the service was no longer available. That's a good sign for anyone hoping the operation gets dismantled, but it does nothing to reverse a year-plus of quiet data harvesting the seller claimed to have already completed. Whoever ran Nexus can stand up a new storefront under a different name, or simply sell the same database through private channels instead.

A leaked password is annoying but fixable; you just change it. A leaked driver's license is a tougher problem, because you can't easily change your face, and getting a new license number typically requires proving identity theft to your state DMV rather than just asking nicely. If you've rented from Hertz, Thrifty, or Dollar in the past couple of years, it's worth pulling your credit reports from all three bureaus, watching for accounts you didn't open, and considering a credit freeze, which is free in every state and blocks new lines of credit from being opened in your name. Because titling and financing a vehicle typically requires a license scan too, keep an eye on your state DMV notifications for title transfers or registration changes you didn't initiate.

IDScan.net isn't an outlier; it's an example of how thoroughly identity verification has been outsourced across the car business. Hertz has been experimenting with pricier rental fleet additions, GM's OnStar data-sharing deal turned driving behavior into a product sold to insurers, and California's AB 311 would unwind a two-decade-old ban on insurers using telematics data. Layer a breach like this on top of that trend and the takeaway is simple: nearly every part of renting, financing, or insuring a car now runs through a third-party data pipeline you never agreed to and can't audit. A federal court ruling that gutted Flock's phone-privacy defense earlier this year showed courts are starting to take that problem seriously; this round of lawsuits is the next test of whether that scrutiny extends to the companies scanning your license at the rental counter.

IDScan hasn't said how the breach happened, whether it's patched whatever let a stranger walk out with over a year's worth of scans, or how long it kept records it apparently didn't need to keep. Until it does, the safest assumption for anyone who's rented a car, visited a dispensary, or checked into a casino in the last year is that their license photo is sitting in a database with a company they've never directly done business with.