You hand over your driver’s license.
A rental car counter scans it. A hotel scans it. Maybe a dispensary scans it. A few seconds later, you get the card back and go about your day.
It feels like the transaction is over.
But what if the scan isn’t?
A dark web service called Nexus recently advertised more than 153 million U.S. and Canadian driver’s license scans, along with millions of other identity documents. The FBI is now investigating the apparent breach, while researchers have been able to match some of the leaked scans to real-world ID checks.
Some of those scans contained far more than a photograph.
The physical license came back to its owner. The digital copy may have gone somewhere else entirely.
Table of Contents
The Scan Was More Than a Photograph
KrebsOnSecurity was able to examine samples from the database and compare the timestamps on some scans with real-world events. In one case, scans of Krebs’s own driver’s license and his mother’s appeared alongside timestamps that matched a Hertz rental. Another person’s license could be tied to a trip to Las Vegas, where the same ID had been presented at several locations.
The timestamps suggested that at least some of the records were created when people were actually presenting their IDs.
And the scans themselves contained more than the information printed on the card.
The database reportedly included front and back images, along with infrared and ultraviolet captures. Those additional images are normally used by verification systems to inspect security features on an ID and determine whether a document is genuine.
That makes the data far more revealing than a database containing names and email addresses.
Someone wasn’t just storing a record that you had an ID.
They may have been storing the digital evidence used to verify that the ID was real in the first place.
The Company Behind the Scanner
Most businesses don’t build their own identity verification systems from scratch. They can use specialized companies that provide the hardware and software needed to scan and verify IDs.
One of those companies is IDScan.net.
KrebsOnSecurity traced several of the sampled records to IDScan’s VeriScan system, based on details visible in the scans and comparisons with real-world ID checks. That doesn’t establish that IDScan was the source of the entire Nexus database, and the company has not publicly confirmed that the leaked data came from its systems.
But it does show how these identity checks can work.
IDScan says its technology processes more than 21 million verifications each month across more than 20,000 locations worldwide. Its systems can capture information from an ID under visible, infrared and ultraviolet light, then use that data to verify the document.
For the business using it, this can make checking an ID quick and simple.
For the person holding the ID, there is another layer they may never see.
The company asking for your license may not be the company scanning it, processing it or storing the resulting data.
That distinction is easy to miss because the entire process happens in a few seconds.
Your ID Becomes Data the Moment It Gets Scanned
There is a reason businesses use systems like this.
Scanning an ID is faster than manually checking every detail. The software can read the document, check its security features and return a verification result in seconds.
The problem is what happens to everything captured along the way.
A driver’s license contains far more than a name. It can include your date of birth, address, photograph, license number and other information used to establish that the document belongs to you. A detailed scan can add another layer by capturing the document’s security features and the circumstances in which it was presented.
The timestamp matters too because it can show when you were asked to prove who you were.
That turns an ID verification system into database of identities, documents and the moments when those identities were verified.
And the more businesses rely on these systems, the more copies of our identities end up sitting outside the places we normally think of as holding our personal information.
Also Read: You Talk to ChatGPT Like a Therapist. A Court May Treat the Conversation Like Evidence.
The Copy Doesn’t Come Back
The FBI is investigating the apparent breach, but the full scope is still unclear.
We don’t yet know exactly how the database was obtained, how many unique people are affected, or how long unauthorized access may have continued. Nexus claimed the collection had been growing, but those claims have not been independently verified.
Nexus itself disappeared after Krebs published the investigation.
For now, the investigation will have to answer where the data came from, who had access to it and how long it was being collected.
But there’s a big question the investigation won’t answer for everyone else.
When you hand over your license, are you proving who you are, or creating another permanent copy of your identity?
The physical card comes back.
The digital record doesn’t necessarily disappear with it.




