Brian Krebs remembers the moment clearly enough. He and his mother stood at a Hertz counter, handed over their driver’s licenses, and waited while a clerk disappeared behind the desk with them for a few minutes to process the paperwork. It’s the kind of moment nobody thinks twice about.
Krebs, a longtime security researcher, didn’t think twice about it either, until he found his own license, and his mother’s, sitting in a dark web marketplace with timestamps a few seconds apart, matching almost to the second when they’d handed those licenses across the counter.
That’s how Krebs traced the origin of what may be the largest single exposure of government-issued identification in U.S. history: more than 153 million driver’s licenses from the United States and Canada, plus over 10 million ID cards, three million passports and travel documents, and more than half a million medical cards, all listed for sale on a dark web service called Nexus. The FBI’s New Orleans field office confirmed it opened an investigation into an apparent breach at idscan.net, a Louisiana-based identity verification company whose scanning technology, according to its own marketing materials, processes more than 21 million ID checks a month at over 20,000 locations.
Skip past the part where this becomes a generic cybersecurity headline, because the automotive angle is sitting right there in Krebs’s own reporting, and it isn’t subtle. Multiple people who helped him trace the leak, including his own family, said the only place they’d handed over a driver’s license around the date on their leaked file was a car rental counter. Krebs specifically named Hertz, which idscan.net’s own site lists as a client brand, alongside Target, FedEx, Motorola Solutions, Caesars Entertainment, and the financial services company Jack Henry.
That client list, it turns out, is not as solid as it looks. After Krebs’s story ran, a Caesars Entertainment spokesperson told him the company has not been an idscan.net customer and has not used its VeriScan product since February 2025, despite still appearing on idscan.net’s site as a client. idscan.net’s response was that the incident should have no impact on Caesars. Maybe. But if a vendor is still advertising a client a year and a half after the relationship ended, the more uncomfortable question is how long it keeps that client’s customer data after the relationship ends, too.
The Dealership Business Nobody Mentioned
Rental counters are only half of idscan.net’s automotive business. Pull up the company’s own site and click into the page built specifically for car dealerships, and the pitch has nothing to do with age checks or convenience. It’s built around a single promise: stop vehicle theft before it starts.
That’s not marketing fluff. Dealerships adopted ID scanning largely to fight test-drive theft, a genuinely common crime in which someone presents a real or forged license, asks to take a car around the block, and never comes back. idscan.net’s own blog keeps a running list of local news stories on the subject stretching back years, everything from a woman who left a fake ID at a dealership and drove off in a customer’s car to a ring that used stolen identities to walk off with a pair of Maseratis. The FBI, for what it’s worth, estimates vehicle theft costs the country roughly $20 million a day.
The other reason dealers scan licenses is less about theft and more about paperwork. Any dealer who arranges financing is legally treated as a financial institution under federal law, which puts it under the Federal Trade Commission’s Safeguards Rule, the same regulation that governs mortgage brokers and payday lenders. That rule requires a written information-security program, encrypted storage of customer data, and, since 2024, a formal breach-notification process. Scanning a license and running it against a database isn’t just about catching a thief mid-test-drive. It’s also how a dealership builds the paper trail regulators expect when loan fraud shows up, and it does show up: a Ventura, California Jeep dealer recently got sued by Santander over allegations it sold fraudulent loans, one recent example of how ugly that fight can get even without a stolen identity involved.
Dealerships don’t exactly need outside help generating fraud headaches, either. Plenty of dealer owners have managed that fine on their own.
The Irony Nobody at the Company Wants to Discuss
There’s a detail in Krebs’s reporting that’s almost too on the nose. idscan.net’s own blog post cataloguing test-drive fraud, the one warning dealerships about criminals using fake IDs to steal cars, was written by Jillian Kossman, the company’s marketing and operations lead. When Krebs emailed idscan.net asking what happened to the 153 million real IDs sitting in its systems, the person who answered was, once again, Jillian Kossman. She told him she couldn’t share details while the investigation was ongoing, but that his findings had been “welcome, and helpful.”
idscan.net has not, as of this writing, published its own breach notice. That’s worth noting mainly because the company markets itself, in its own words, as the fix for exactly this kind of exposure.
Why This Is Bigger Than One Vendor
Zoom out and the uncomfortable pattern is that identity verification, the industry built entirely around stopping fraud, has become one of fraud’s biggest single targets. It makes sense once you think about it. A company that verifies IDs for car rental counters, marijuana dispensaries, casinos, and dealerships in one shared system is sitting on exactly the kind of concentrated, cross-industry data set that used to take criminals years to assemble one breach at a time.
Organized theft rings already lean on forged paperwork to move stolen cars across state lines long before anyone gets to a rental counter. A dataset like this one doesn’t need to be assembled from a dozen separate hacks anymore. It’s already assembled.
We’ve already covered a case where a cloned VIN let a stolen Nissan Rogue sail through a clean Carfax check, right up until it didn’t. A leak like this one works the same way on identity instead of paperwork. Everything checks out, until the moment it doesn’t.
What To Actually Do About It
If you’ve rented a car, financed one, or visited any business that scans IDs for compliance reasons in the past year or two, there’s a reasonable chance your license is part of this. The FTC’s identitytheft.gov recommends checking your credit reports, considering a credit freeze, and reporting any fraud you find.
If you’re on the business side of this, a dealership, a rental franchise, or anyone who outsourced ID verification to a third party, this is also the moment to ask your vendor, in writing, how long it retains scanned images after a transaction closes. Because apparently no longer being a customer is not a guarantee your customers’ data left with you.
The next time someone behind a counter asks for your license and disappears with it for a few minutes, remember what that wait is actually for. It was never really about verifying who you are. It was about creating a permanent copy of who you are, sitting on a server somewhere, for as long as somebody else decides to keep it.

