The Scanner at the Counter
On Tuesday, Brian Krebs published a story about a new dark web service called Nexus that was selling digital scans of more than 153 million U.S. and Canadian driver's licenses. Not license numbers. Scans. Front and back, and in many cases infrared and ultraviolet images too — the versions a bank or a rental counter uses to tell a real license from a fake one.
By Tuesday night the FBI's New Orleans field office had opened an investigation and Nexus had gone dark. The apparent source, according to Krebs's reporting, is IDScan.net, a New Orleans identity verification company that says it performs more than 21 million verifications a month at more than 20,000 locations. IDScan.net told Krebs it is investigating. As of Friday, it had not published a formal statement confirming a breach or its scope.
I want to set aside the number for a minute, because the number is not the lesson. The lesson is how Krebs figured out where the data came from.
He Found the Source by Checking His Calendar
Krebs's own license was in the data. So was his mother's, timestamped a few seconds apart. He asked more than a dozen friends and family members for permission to search for theirs, found nine, and every one of them had traveled on or near the date attached to their image. Several had rented a car from Hertz that day. One had not flown at all but had a long-term Hertz rental. Another researcher's timestamp fell in the middle of a Las Vegas trip during which the one place he was sure his ID went into a machine was a marijuana dispensary — a chain IDScan.net had announced as a customer back in 2022.
Think about what that means from the customer's side of the counter. Krebs remembers handing his license to the rental representative, who held it behind the counter for several minutes while he signed forms. He does not recall it going into a machine. None of these people knew the license was going into a scanner, none of them knew who made the scanner, and none of them knew the scanner's vendor was keeping the image. The first time they heard the name IDScan.net was when a journalist told them their license was for sale.
Now think about it from the board's side. If you run rental counters, hotel check-ins, dispensaries, bank branches, or any business that verifies age or identity in person, there is a device at your front line that captures a government ID at full fidelity and sends it somewhere. In my experience, that device was purchased as equipment. Somebody in operations or loss prevention picked it, procurement approved it, and it went on the fixed-asset schedule next to the receipt printers. Nobody classified it as a data processor holding the single most useful document an identity thief can own.
That is the gap. The vendor is not in your third-party risk register because nobody thought of it as a vendor. It is a scanner.
The Data Does Not Leave When the Contract Does
There is a detail in Krebs's update that I would put in front of every audit committee.
IDScan.net's website listed Caesars Entertainment as a customer. On Wednesday, a Caesars spokesperson told Krebs that Caesars has not used the product since February 2025, had no active accounts at the time of the incident, and did not authorize IDScan.net to retain data from those accounts. IDScan.net told Caesars the incident should have no impact on them.
Maybe that is right. But notice what Caesars had to say out loud: we did not authorize you to keep it. That sentence only needs saying if the customer is not certain the vendor deleted it. And most customers are not certain, because most contracts do not require a deletion certificate when the relationship ends, and almost nobody asks for one.
The people behind Nexus claimed they had been "continuously exfiltrating new data for over a year." That is the attacker talking and should be treated that way. What Krebs observed himself is that the record count grew by nearly 400,000 in a single day while he was watching, which suggests the pipeline was still live. If a vendor is holding images from a relationship that ended more than a year and a half earlier, the retention window is not the length of the contract. It is forever.
Three Questions, Pointed at the Front Line
What are we protecting? Not "customer PII." The specific artifact: a scan of a government-issued ID, captured by a device at your counter, transmitted to a vendor, and stored for a period nobody in your company can state. A license scan is worse than a password breach because your customer cannot reset their face or their date of birth. And the infrared and ultraviolet images that verification systems use to tell a real license from a fake are not data points. They are keys.
What happens if we lose it? Your customer will not blame IDScan.net. They have never heard of IDScan.net. They will remember that they handed their license to your clerk. Whether the notification letter carries your logo or the vendor's, the relationship that gets damaged is yours. And if the vendor cannot tell you which of your locations, which dates, and which customers are in the stolen set — and as of this week nothing IDScan.net has said publicly answers that — you cannot answer the first question a regulator or a plaintiff's lawyer will ask.
Who decides? Somebody in your organization decided that verifying identity meant capturing and transmitting a full image rather than checking it and handing it back. That was a business decision with a risk attached, and I would bet it was made two or three levels below anyone who would recognize it as one. The question for the board is not whether the decision was wrong. It is whether anyone with risk authority knew it was being made.
What to Ask Your CISO This Week
Ask for the list of every device or service at a customer-facing location that captures an image of a government ID, who the vendor is, and whether that vendor is in the third-party risk program. If the answer is "we would have to ask operations," that is the finding.
Ask what each of those vendors retains, for how long, and whether your contract lets you require deletion and get proof of it. Caesars had to go on the record saying it never authorized retention. Better to have the clause than the press statement.
Ask whether identity verification at your locations actually requires storing the image, or whether the check can be performed and the image discarded. Confirming that someone is over 21 does not require a permanent copy of their license. Ask whether your vendor can verify without retaining, and if so, whether that setting is on.
Ask what you would tell a customer who calls on Monday and says a reporter found their license for sale, timestamped to the day they visited your store. Not the legal answer. The one the person answering the phone would actually give.
The scanner at the counter is the kind of risk that never shows up in a security budget conversation, because it was never purchased as security. It was purchased as a convenience. This week, 153 million license scans went up for sale to show what it cost.