Data Breaches Strongly negative 8

153M licenses for sale on Nexus as UV/IR ID scans leak from Hertz, Planet13

Security journalist Brian Krebs exposed Nexus, a dark web ID theft service with 153 million driver's license records including UV/IR scans. The data appears sourced from IDScan.net, used by Hertz and Planet13, with near real-time ingestion. The FBI is investigating after Nexus went dark.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Data Breaches

3 stories
6.7 avg impact
0% positive
100% negative
vs prior 7 days New New vs empty prior window

Impact not comparable yet. Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

8 impact
Strongly negativesentiment
2sources
4min read
  1. Security journalist Brian Krebs exposed Nexus, a dark web ID theft service with 153 million driver's license records including UV/IR scans.
  2. The data appears sourced from IDScan.net, used by Hertz and Planet13, with near real-time ingestion.
  3. The FBI is investigating after Nexus went dark.
Drawn from
  • Ars Technica
  • Dan Goodin (US)

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Nexus dark web service offered 153 million driver's license records for sale as of September 1, 2026.
  2. 2Listings grew by almost 400,000 in a single 24-hour period, indicating ongoing, near-real-time harvesting.
  3. 3Scans included front and back images plus infrared and ultraviolet captures, which could help counterfeit IDs pass hologram checks.
  4. 4Records listed source notations like 'CDL' (commercial driver's license) and 'CAC' (Common Access Card), plus marijuana dispensary cards.
  5. 5IDScan.net has an exclusive arrangement with Planet13 and lists Hertz and 11 other companies as clients; its scans capture IR and UV spectra.
  6. 6Nexus went dark within hours of KrebsOnSecurity's report, and the FBI is investigating.

Who's Affected

Hertz
companyNegative
Planet13
companyNegative
IDScan.net
companyNegative
FBI
governmentNeutral

Analysis

For cybersecurity teams, the Nexus case is a live-fire lesson in third-party scanner compromise and enhanced-ID data leakage. The near-real-time appearance of scanned licenses—within hours of being captured at rental counters—means defenders must treat ID scanning vendors as high-value targets and their data pipelines as potential continuous exfiltration channels.

On September 2, 2026, Ars Technica security journalist Dan Goodin reported a disquieting personal confirmation of a massive identity-theft operation. Shortly after renting an SUV from a well-known car rental company, he found that a high-resolution scan of his driver's license was available for purchase on Nexus, a dark web ID theft service. The service, exposed by Brian Krebs of KrebsOnSecurity on September 1, listed more than 153 million driver's license records, including what were purported to be multiple image files for each identity: front and back scans plus captures in the infrared and ultraviolet spectrums. That imaging depth matters because counterfeiters can use UV/IR captures to replicate the physical security features that many bouncers, banks, and government checkpoints rely on to spot fakes.

IDScan.net had announced an exclusive arrangement with Planet13 and listed Hertz and 11 other companies as using its services.

Krebs's investigation showed this was not a static database dump. Over a 24-hour period, the number of listed licenses grew by almost 400,000, a strong sign that Nexus had continuous, near-real-time ingestion from some upstream source. Nexus also advertised other credential types, including records labeled 'CDL,' which may be shorthand for commercial driver's license, and 'CAC,' which may refer to Common Access Cards issued to government personnel. It even offered marijuana dispensary card scans. One victim told Krebs that after visiting a Las Vegas outlet of Planet13, a multi-state dispensary chain, their license appeared on Nexus shortly after. Goodin's own rental-car license appeared within hours. That temporal correlation points directly at the third-party scanning service used at those physical locations.

Public records and prior announcements point to IDScan.net, a New Orleans-based ID scanning company. IDScan.net had announced an exclusive arrangement with Planet13 and listed Hertz and 11 other companies as using its services. Its own documentation states that its scans capture both infrared and ultraviolet spectra, matching the file types offered by Nexus. IDScan.net said it was investigating and did not immediately answer detailed questions. Hertz and Planet13 also did not immediately respond. The FBI has an ongoing investigation. The fact that a common third-party OCR/scanning vendor is the suspected source makes this a classic supply-chain compromise: the businesses themselves may not have been breached, but their customers' credentials flowed through an intermediary that either was compromised or had a malicious insider.

For security leaders, this breach is a case study in third-party risk specific to identity document processing. Rental car counters, dispensaries, and other age- or identity-verifying businesses create high-volume, low-friction scanning environments. They are often staffed by low-wage workers, use commodity scanning hardware, and send images to centralized cloud services. If that cloud service is compromised, every scan can be exfiltrated in real time. The addition of infrared and ultraviolet capture raises the stakes: most privacy laws require notification when driver's license data is exposed, but the physical security implications of UV/IR templates are less well addressed. Organizations may need to reassess whether they truly need to capture and retain UV/IR images, or whether visible-light scans suffice for compliance.

What to Watch

The 153 million figure dwarfs many high-profile identity breaches and suggests Nexus had been operating for months or longer, accumulating both legacy scans and fresh captures. Because Nexus disappeared within hours of the KrebsOnSecurity story, victims cannot check whether their own IDs are included. That takedown pattern is common: dark web marketplaces often go dark after exposure to avoid law enforcement, only to reappear under new branding. Threat intelligence teams should monitor for successor sites and credential resurfacing. For organizations whose customers' IDs may be in the set, this is not just a PR issue; it is a potential regulatory and legal liability, especially given the sensitivity of Common Access Card data and the potential for physical facility compromise.

Forward-looking implications include heightened scrutiny of IDScan.net and its clients from state attorneys general and federal regulators. Class action litigation over biometric/identity data could follow, particularly in states with stringent laws like Illinois's BIPA or California's CCPA/CPRA. The FBI investigation may determine whether the compromise was an external intrusion, an insider abuse, or a misconfigured API. Depending on the findings, every company that uses third-party ID scanning services may need to conduct urgent vendor audits and require vendors to delete UV/IR captures immediately after validation. Finally, defenders should treat this as an early warning: as more physical-world identity verification moves to digital pipelines, these pipelines are becoming high-value targets for both financial fraud and physical security compromise.

Timeline

Timeline

  1. KrebsOnSecurity exposes Nexus

  2. Nexus goes dark

  3. Ars Technica confirms personal ID exposure

Source cluster

Primary reporting

2articles

Cite This Page

"153M licenses for sale on Nexus as UV/IR ID scans leak from Hertz, Planet13." Cyber Intelligence Brief, September 3, 2026. https://getcyberbrief.com/story/nexus-153m-license-breach-uv-ir-scans-hertz-planet13

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.