IDScan Data Breach: 153 Million Driver’s Licenses Stolen in Major Security Alert
IDScan has acknowledged a data breach involving the unauthorized access of customer information stored on its cloud platform, following reports of a database containing over 153 million driver’s license scans.
Breach Announcement and Investigation
IDScan disclosed the incident in a security notice dated September 4, stating it became aware of potential unauthorized access on or around September 1. The company initiated immediate measures to secure its systems and engaged third-party experts to assess the scope of the incident.
Scope of the Incident
While the investigation is ongoing, IDScan has concluded that an external party may have accessed or copied data from user accounts on its IDScan.net cloud service. The compromised information includes full names, driver’s license numbers, and other government-issued identification details.
Breach Notification Page
A breach notification page published on September 4 was marked with a noindex directive, preventing search engines from indexing the content.
Leak Details and Legal Actions
Prior to the official disclosure, multiple lawsuits were filed against IDScan after hackers allegedly leaked a database containing over 153 million U.S. and Canadian driver’s license scans. The company confirmed that access to the full dataset required payment but is notifying affected individuals and offering free credit monitoring and identity protection services.
Dark Web Leak Discovery
The breach first emerged when cybersecurity journalist Brian Krebs reported on September 1 that a dark web platform named “Nexus” was selling access to a database containing 153 million driver’s license scans, alongside 10 million ID cards, 3 million travel documents, and 579,000 medical records.
Verification and Source Tracing
Krebs verified the data by cross-referencing samples with his own records and those of volunteers, tracing the source to IDScan. The company’s platform is utilized by businesses such as car rental agencies, retailers, financial institutions, and healthcare providers to authenticate and extract information from official identification documents.
Response and Ongoing Concerns
After the Nexus leak was exposed, the platform was taken offline, though cybercriminals likely retain access to the database. Subsequent claims by other threat actors to sell the entire dataset have not been independently verified.
Cooperation with Authorities
IDScan has stated it is cooperating with federal authorities, with the FBI confirming an ongoing investigation. The company emphasized that it is reviewing data security protocols and working with law enforcement.
Unanswered Questions
BleepingComputer has sought further details from IDScan but has not received responses.
Broader Implications and Vulnerabilities
Additional context from a 2026 report highlighted that 37% of malicious activities are blocked when attackers possess valid credentials, underscoring vulnerabilities in authentication systems. The breach underscores broader risks associated with cloud storage and the proliferation of sensitive personal data on underground marketplaces.
According to a 2026 report, 37% of malicious activities are blocked when attackers possess valid credentials, underscoring vulnerabilities in authentication systems.
