153M licenses for sale on Nexus as UV/IR ID scans leak from Hertz, Planet13
Security journalist Brian Krebs exposed Nexus, a dark web ID theft service with 153 million driver's license records including UV/IR scans. The data appears sourced from IDScan.net, used by Hertz and Planet13, with near real-time ingestion. The FBI is investigating after Nexus went dark.
Beat this week
Last 7 days · Data Breaches
Impact not comparable yet. Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.
This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- Security journalist Brian Krebs exposed Nexus, a dark web ID theft service with 153 million driver's license records including UV/IR scans.
- The data appears sourced from IDScan.net, used by Hertz and Planet13, with near real-time ingestion.
- The FBI is investigating after Nexus went dark.
- Ars Technica
- Dan Goodin (US)
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Nexus dark web service offered 153 million driver's license records for sale as of September 1, 2026.
- 2Listings grew by almost 400,000 in a single 24-hour period, indicating ongoing, near-real-time harvesting.
- 3Scans included front and back images plus infrared and ultraviolet captures, which could help counterfeit IDs pass hologram checks.
- 4Records listed source notations like 'CDL' (commercial driver's license) and 'CAC' (Common Access Card), plus marijuana dispensary cards.
- 5IDScan.net has an exclusive arrangement with Planet13 and lists Hertz and 11 other companies as clients; its scans capture IR and UV spectra.
- 6Nexus went dark within hours of KrebsOnSecurity's report, and the FBI is investigating.
Who's Affected
Analysis
For cybersecurity teams, the Nexus case is a live-fire lesson in third-party scanner compromise and enhanced-ID data leakage. The near-real-time appearance of scanned licenses—within hours of being captured at rental counters—means defenders must treat ID scanning vendors as high-value targets and their data pipelines as potential continuous exfiltration channels.
On September 2, 2026, Ars Technica security journalist Dan Goodin reported a disquieting personal confirmation of a massive identity-theft operation. Shortly after renting an SUV from a well-known car rental company, he found that a high-resolution scan of his driver's license was available for purchase on Nexus, a dark web ID theft service. The service, exposed by Brian Krebs of KrebsOnSecurity on September 1, listed more than 153 million driver's license records, including what were purported to be multiple image files for each identity: front and back scans plus captures in the infrared and ultraviolet spectrums. That imaging depth matters because counterfeiters can use UV/IR captures to replicate the physical security features that many bouncers, banks, and government checkpoints rely on to spot fakes.
IDScan.net had announced an exclusive arrangement with Planet13 and listed Hertz and 11 other companies as using its services.
Krebs's investigation showed this was not a static database dump. Over a 24-hour period, the number of listed licenses grew by almost 400,000, a strong sign that Nexus had continuous, near-real-time ingestion from some upstream source. Nexus also advertised other credential types, including records labeled 'CDL,' which may be shorthand for commercial driver's license, and 'CAC,' which may refer to Common Access Cards issued to government personnel. It even offered marijuana dispensary card scans. One victim told Krebs that after visiting a Las Vegas outlet of Planet13, a multi-state dispensary chain, their license appeared on Nexus shortly after. Goodin's own rental-car license appeared within hours. That temporal correlation points directly at the third-party scanning service used at those physical locations.
Public records and prior announcements point to IDScan.net, a New Orleans-based ID scanning company. IDScan.net had announced an exclusive arrangement with Planet13 and listed Hertz and 11 other companies as using its services. Its own documentation states that its scans capture both infrared and ultraviolet spectra, matching the file types offered by Nexus. IDScan.net said it was investigating and did not immediately answer detailed questions. Hertz and Planet13 also did not immediately respond. The FBI has an ongoing investigation. The fact that a common third-party OCR/scanning vendor is the suspected source makes this a classic supply-chain compromise: the businesses themselves may not have been breached, but their customers' credentials flowed through an intermediary that either was compromised or had a malicious insider.
For security leaders, this breach is a case study in third-party risk specific to identity document processing. Rental car counters, dispensaries, and other age- or identity-verifying businesses create high-volume, low-friction scanning environments. They are often staffed by low-wage workers, use commodity scanning hardware, and send images to centralized cloud services. If that cloud service is compromised, every scan can be exfiltrated in real time. The addition of infrared and ultraviolet capture raises the stakes: most privacy laws require notification when driver's license data is exposed, but the physical security implications of UV/IR templates are less well addressed. Organizations may need to reassess whether they truly need to capture and retain UV/IR images, or whether visible-light scans suffice for compliance.
What to Watch
The 153 million figure dwarfs many high-profile identity breaches and suggests Nexus had been operating for months or longer, accumulating both legacy scans and fresh captures. Because Nexus disappeared within hours of the KrebsOnSecurity story, victims cannot check whether their own IDs are included. That takedown pattern is common: dark web marketplaces often go dark after exposure to avoid law enforcement, only to reappear under new branding. Threat intelligence teams should monitor for successor sites and credential resurfacing. For organizations whose customers' IDs may be in the set, this is not just a PR issue; it is a potential regulatory and legal liability, especially given the sensitivity of Common Access Card data and the potential for physical facility compromise.
Forward-looking implications include heightened scrutiny of IDScan.net and its clients from state attorneys general and federal regulators. Class action litigation over biometric/identity data could follow, particularly in states with stringent laws like Illinois's BIPA or California's CCPA/CPRA. The FBI investigation may determine whether the compromise was an external intrusion, an insider abuse, or a misconfigured API. Depending on the findings, every company that uses third-party ID scanning services may need to conduct urgent vendor audits and require vendors to delete UV/IR captures immediately after validation. Finally, defenders should treat this as an early warning: as more physical-world identity verification moves to digital pipelines, these pipelines are becoming high-value targets for both financial fraud and physical security compromise.
Timeline
Timeline
KrebsOnSecurity exposes Nexus
Brian Krebs reports 153 million driver's licenses for sale on Nexus, including UV/IR scans and records labeled CDL, CAC, and dispensary cards.
Nexus goes dark
The dark web service shuts down within hours of publication, preventing victims from checking whether their IDs were exposed.
Ars Technica confirms personal ID exposure
Dan Goodin confirms his own license, scanned at a rental company, appeared on Nexus within hours of being scanned.
Source cluster
Primary reporting
Cite This Page
"153M licenses for sale on Nexus as UV/IR ID scans leak from Hertz, Planet13." Cyber Intelligence Brief, September 3, 2026. https://getcyberbrief.com/story/nexus-153m-license-breach-uv-ir-scans-hertz-planet13
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |