IDScan confirms breach tied to 153 million stolen driver’s licenses

by · BleepingComputer

Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans.

IDScan disclosed the incident in a September 4 security notice, saying it learned on or around September 1 that certain data may have been accessed without authorization.

"Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident," IDScan said.

The company says its investigation remains ongoing but has determined that an unauthorized third party "may" have accessed or copied customer information stored within accounts on the IDScan.net cloud.

The exposed information can include customers' full names, and driver's license or other government-issued identification numbers. While not mentioned in the notification, the breach reportedly also allowed threat actors to steal scans of driver's licenses.

TechCrunch spotted IDScan's breach notification, which was published on September 4 but configured with a noindex directive that instructed search engines not to index the page.

BleepingComputer previously reported on September 4 that multiple lawsuits had been filed against IDScan after hackers allegedly breached the company and offered access to a database containing more than 153 million driver's licenses.

At the time, IDScan had not publicly acknowledged the incident or responded to BleepingComputer's requests for comment.

The company said that although full access to the exposed information required payment, it is notifying potentially impacted individuals "in an abundance of caution" and providing free credit monitoring and identity protection services.

Massive ID database linked to IDScan

The incident first came to light after Brian Krebs reported on September 1 that a dark-web platform called "Nexus" was advertising access to more than 153 million U.S. and Canadian driver's license scans.

The service also allegedly contained 10 million ID cards, 3 million travel documents, and 579,000 medical cards.

Krebs verified samples from the database by searching for records belonging to himself and others who consented to the searches and traced the exposed information back to IDScan.

IDScan provides identity verification technology that businesses use to scan, authenticate, and extract information from government-issued identification documents. Its platform is used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses.

After news of the Nexus service spread, the platform was taken offline, though the cybercriminals likely still have access to the database.

Since then, multiple threat actors have claimed to be selling the entire database, but BleepingComputer has not been able to confirm if these sales are legitimate.

IDScan said it is cooperating with federal law enforcement, with the FBI previously confirming to BleepingComputer that it was investigating the incident.

"In response to this incident, we immediately began an investigation and reviewed our policies and procedures related to data security," IDScan said.

"We are also cooperating with federal law enforcement on their investigation."

BleepingComputer has contacted IDScan multiple times with questions about the incident but has not received a response.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report