Sep 11
/
Latest News
IDScan Confirms Breach After 153 Million Driver’s License Scans Appear on Dark Web
IDScan.net has confirmed that hackers accessed customer data stored on its cloud platform, days after reports linked the identity verification company to a dark‑web database containing more than 153 million scanned driver’s licenses from the United States and Canada.
The Louisiana-based firm, which provides ID scanning and authentication services for car rental companies, retailers, financial institutions, cannabis dispensaries, and hospitality businesses, posted a notice on September 4 acknowledging that certain customer information may have been accessed without authorization. The company said it learned of the issue on or around September 1 and immediately engaged third‑party specialists to investigate.
IDScan’s statement said an unauthorized party “may have accessed and/or copied” customer data stored in its cloud accounts, including names and driver’s license or other government‑issued identification numbers. Although full access to the exposed information reportedly required payment, IDScan says it is notifying potentially affected individuals “in an abundance of caution” and offering free credit monitoring and identity protection. The company also said it is cooperating with federal law enforcement. Bleeping ComputerBleeping Computer. IDScan confirms breach tied to 153 million stolen driver’s licenses
The breach came to light after investigative journalist Brian Krebs reported that a dark‑web marketplace called Nexus was selling access to more than 153 million driver’s license scans, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards. A listing on the Russian cybercrime forum Exploit advertised identity records for more than 170 million people in North America.
Krebs confirmed the authenticity of the data by searching the database for his own records and those of individuals who consented to checks. His own Virginia driver’s license appeared as a free sample. He traced the exposed data back to IDScan.net, whose scanning terminals are used at Hertz rental counters, cannabis dispensaries, hotels, casinos, and shipping centers across the United States. Tech TimesTech Times. IDScan.net Breach Exposes 153 Million Licenses With Infrared Scans That Pass Bank Checks
The stolen images reportedly include not only standard scans but also infrared and ultraviolet captures used by banks and government agencies to verify authenticity, meaning the data could potentially defeat document‑fraud detection systems. Nexus operators claimed they had been continuously exfiltrating new data for more than a year, and the database grew by nearly 400,000 license records within 24 hours of monitoring.
Based on Krebs’s reporting, the FBI’s New Orleans field office opened a formal investigation. The database reportedly contained records belonging to high‑profile individuals, including the U.S. Secretary of Defense and an assistant director of the FBI. Shortly after the story was published, the Nexus identity‑theft service disappeared from the dark web, though cybercriminals likely retain access to the stolen data. TechCrunchTechCrunch. ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen | TechCrunch
Multiple lawsuits have since been filed against IDScan, alleging the company failed to protect sensitive information collected through its identity‑verification systems. Law firms are seeking potential claimants for possible class‑action litigation, noting that anyone whose ID was scanned through businesses using IDScan’s technology may be affected.
The Louisiana-based firm, which provides ID scanning and authentication services for car rental companies, retailers, financial institutions, cannabis dispensaries, and hospitality businesses, posted a notice on September 4 acknowledging that certain customer information may have been accessed without authorization. The company said it learned of the issue on or around September 1 and immediately engaged third‑party specialists to investigate.
IDScan’s statement said an unauthorized party “may have accessed and/or copied” customer data stored in its cloud accounts, including names and driver’s license or other government‑issued identification numbers. Although full access to the exposed information reportedly required payment, IDScan says it is notifying potentially affected individuals “in an abundance of caution” and offering free credit monitoring and identity protection. The company also said it is cooperating with federal law enforcement. Bleeping ComputerBleeping Computer. IDScan confirms breach tied to 153 million stolen driver’s licenses
The breach came to light after investigative journalist Brian Krebs reported that a dark‑web marketplace called Nexus was selling access to more than 153 million driver’s license scans, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards. A listing on the Russian cybercrime forum Exploit advertised identity records for more than 170 million people in North America.
Krebs confirmed the authenticity of the data by searching the database for his own records and those of individuals who consented to checks. His own Virginia driver’s license appeared as a free sample. He traced the exposed data back to IDScan.net, whose scanning terminals are used at Hertz rental counters, cannabis dispensaries, hotels, casinos, and shipping centers across the United States. Tech TimesTech Times. IDScan.net Breach Exposes 153 Million Licenses With Infrared Scans That Pass Bank Checks
The stolen images reportedly include not only standard scans but also infrared and ultraviolet captures used by banks and government agencies to verify authenticity, meaning the data could potentially defeat document‑fraud detection systems. Nexus operators claimed they had been continuously exfiltrating new data for more than a year, and the database grew by nearly 400,000 license records within 24 hours of monitoring.
Based on Krebs’s reporting, the FBI’s New Orleans field office opened a formal investigation. The database reportedly contained records belonging to high‑profile individuals, including the U.S. Secretary of Defense and an assistant director of the FBI. Shortly after the story was published, the Nexus identity‑theft service disappeared from the dark web, though cybercriminals likely retain access to the stolen data. TechCrunchTechCrunch. ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen | TechCrunch
Multiple lawsuits have since been filed against IDScan, alleging the company failed to protect sensitive information collected through its identity‑verification systems. Law firms are seeking potential claimants for possible class‑action litigation, noting that anyone whose ID was scanned through businesses using IDScan’s technology may be affected.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.