IDScan admits break-in after 153 million driver's license scans surface on dark web

The identity verification firm says an unauthorised party may have copied customer records from its cloud, days after a criminal marketplace advertised access to a huge trove of scanned IDs traced back to the company.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style 16:9 photograph of rows of server racks inside a large data centre, bathed in cool blue and white light, with a single rack door
Share

Key points

  • IDScan confirmed on September 4 that an unauthorised party may have accessed customer data held in its cloud platform.
  • The company detected the intrusion on or around September 1, the same day journalist Brian Krebs linked a dark-web service called Nexus to more than 153 million scanned driver's licenses.
  • Exposed information can include full names and driver's license or other government ID numbers, with reports that actual license scans were also taken.
  • The Nexus marketplace also allegedly offered 10 million ID cards, 3 million travel documents and 579,000 medical cards.
  • IDScan is offering free credit monitoring and says it is working with the FBI, which has confirmed an active investigation.

IDScan, a company that helps businesses check the authenticity of driver's licenses and other government IDs, has admitted that hackers got into its cloud systems and may have copied customer data.

The admission came in a September 4 security notice that was quietly published with instructions telling search engines not to list it. First reported by BleepingComputer, the notice arrived only after a separate story tied the company to a huge cache of stolen IDs on the dark web.

What was taken?

IDScan says an unauthorised third party may have accessed or copied information stored in accounts on its IDScan.net cloud. That can include customers' full names and driver's license or other government-issued ID numbers.

The company's notice does not mention the scans themselves. But reporting on the underlying breach says the criminals also walked away with images of actual driver's licenses, the kind of high-quality scan a bar or car rental desk would take from a real customer.

Where did the 153 million figure come from?

On September 1, security journalist Brian Krebs reported on a dark-web marketplace calling itself Nexus. The site was advertising a searchable database of more than 153 million U.S. and Canadian driver's license scans.

Alongside the licenses, the operators claimed to hold 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified sample records, including one for himself, and traced the data back to IDScan.

The Nexus site has since gone offline. That does not mean the data is gone. Several sellers have popped up claiming to offer the full database, though none of those sales have been independently confirmed.

Who uses IDScan, and why does that matter?

IDScan's technology sits at the checkout counter of a lot of everyday businesses. Car rental firms, retailers, banks, cannabis dispensaries, gun shops and hotels all use its software to scan the ID a customer hands over, pull out the details, and confirm the document is real.

That means the pool of potentially affected people is wide and hard to pin down. If you rented a car, opened an account, or bought anything age-restricted in the last few years, your license scan may have passed through IDScan's platform.

Timeline of the incident

Date Event
September 1 Brian Krebs reports on the Nexus marketplace and its 153 million license database
Around September 1 IDScan says it discovered the unauthorised access
September 4 Lawsuits filed against IDScan; company publishes a hidden breach notice
Ongoing FBI investigating; multiple sellers claim to offer the stolen database

Should ordinary people be worried?

Yes, but there are practical steps. A stolen license scan is more dangerous than a leaked password because you cannot change your date of birth or license number. Criminals use these images to open bank accounts, apply for loans, or bypass identity checks on other services.

IDScan is offering free credit monitoring to people it believes were affected. If you receive a notice, take it. Beyond that, place a free credit freeze with the major bureaus, treat any unexpected call about a loan or account as suspicious, and be wary of emails that reference details from your license, since scammers often use real data to make phishing messages, fake emails designed to trick you into handing over more information, look convincing.

The FBI has confirmed it is investigating. IDScan says it has tightened its systems and is cooperating with federal law enforcement.

© 2026 Threat Vectr