Our Blog

Blog Index 

IDScan Confirms Data Breach: 153 Million Driver's Licenses Stolen in Year-Long Hack

Posted on 12th Sep 2026 06:03:56 in Artificial Intelligence, Machine Learning

Tagged as: data breach, cybersecurity, identity verification, IDScan, dark web

Identity verification provider IDScan.net has confirmed what cybersecurity reporters had been uncovering for over a week: hackers breached its systems and stole digital scans of more than 153 million driver's licenses belonging to people in the United States and Canada. The Louisiana-based company, whose scanning hardware and software sit at rental car counters, hotel desks, cannabis dispensaries and entertainment venues across North America, said in a website notice that an "unauthorized third party may have accessed and/or copied certain customer information" stored in its cloud. The exposed data includes people's full names and driver's license numbers, along with identity numbers from other government-issued documents such as passports. It is one of the largest exposures of government-issued identity documents ever reported, and it came with an unusual twist: the stolen records were being sold through a fully searchable dark-web storefront.

What Happened: A Dark-Web Storefront Called Nexus

The breach first came to light on August 31, 2026, when independent cybersecurity journalist Brian Krebs was alerted to an advertisement on the Russian cybercrime forum Exploit. The post promoted a new identity-theft service dubbed "Nexus," which claimed to hold more than 153 million driver's licenses from people in the United States and Canada, plus more than 10 million identification cards, over 3 million travel documents and international IDs, and at least 579,000 medical cards. The operators bragged that they had been "continuously exfiltrating new data for over a year" into their private database.

Krebs found the claims were not exaggerated. Running a blank search on Nexus returned approximately 11.5 million pages of results, with about 15 records per page. Canadian licenses alone accounted for roughly 1.1 million records, the largest concentration coming from Ontario with 473,673 entries. Some records carried source notations such as "CDL," presumably for commercial driver's licenses, and "CAC" — a reference to Common Access Cards, the government-issued identity cards that grant physical access to federal buildings and secure rooms. Worryingly, the database kept growing: the number of driver's license records increased by nearly 400,000 in a single 24-hour span, suggesting the service was being fed by a live, ongoing breach rather than a one-time theft.

How the Breach Was Traced to IDScan

Krebs verified the authenticity of the data by examining his own record first. His Virginia driver's license was offered as a free sample in the seller's introductory thread, and the scans attached to it included six image files — front and back photos, a basic scan, and infrared and ultraviolet versions — each stamped with a date and timestamp. The timestamp on his record corresponded to June 2025, when he rented a car from Hertz before a flight. Checking with more than a dozen friends and family members who consented to be searched, Krebs found nine whose licenses appeared in Nexus, each with timestamps matching dates they had travelled or rented vehicles.

Security researcher Zach Edwards found his own license in the database, timestamped to the middle of his trip to the DEFCON conference in Las Vegas. Edwards did not rent a car, but he did hand his ID to a dispensary that scanned it — Planet13, a multi-state cannabis chain that signed an exclusive identity-verification agreement with IDScan.net in 2022. The pattern pointed directly at IDScan, which publicly lists Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment among its customers, and says its systems perform more than 21 million verifications each month across 20,000-plus locations worldwide. The stolen set even included the driver's license of U.S. Secretary of Defense Pete Hegseth and that of an FBI assistant director.

What Was Exposed — and Why the Scan Format Makes It Worse

The contents of the stolen records make this breach more dangerous than a typical database leak of names and numbers. IDScan's verification hardware scans identity documents with infrared and ultraviolet light to detect counterfeits — which means the compromised cache includes the very security features that prove a document is genuine. Krebs' own record contained separate infrared and ultraviolet renderings of his license alongside ordinary front-and-back photos. Armed with those images, fraudsters can produce counterfeits that pass both visual inspection and the machine checks designed to catch fakes.

IDScan's notice confirmed that the affected information "may include full names and driver's license or other government-issued identification numbers." Combined with photos of the holders, that is effectively a complete identity-fraud toolkit for more than 153 million people. Unlike passwords or credit cards, driver's licenses are not something users can simply rotate: the document numbers remain valid for years unless the holder takes deliberate steps to have them replaced.

The Investigation, Confirmation and Legal Fallout

The FBI's New Orleans field office opened an official investigation into the apparent breach on September 1, the same day Krebs published his report. Reuters independently confirmed the bureau was "looking into the incident," and the Pentagon said it was aware of the suspected breach. The Nexus storefront vanished from the dark web shortly after Krebs' story went live, but investigators and security analysts assume the stolen database remains in criminal hands. IDScan initially said only that it was investigating; on September 10, the company published its first formal acknowledgement of the intrusion, stating it had "received information indicating that certain data may have been accessed without authorization" on or around September 1.

The legal machinery has already started moving. Multiple lawsuits have been filed in Louisiana, where IDScan is based, and law firms including Markovits, Stock & DeMarco and Hall Attorneys have opened investigations into potential class-action litigation. Legal observers expect additional filings, possible consolidation into multidistrict litigation, and scrutiny from state attorneys general and federal regulators — the same path followed after large-scale exposures involving 23andMe, Marriott and Equifax. IDScan has not publicly said how many individuals are affected, though its own materials note the company holds more than 150 million driver's license records.

What Individuals and Businesses Should Do Now

For the tens of millions of people whose licenses may be in this dataset, the practical playbook mirrors any major identity exposure, with a few extras:

  • Freeze your credit files at all three major bureaus — Equifax, Experian and TransUnion — and lift them only temporarily when applying for credit.
  • Watch for unusually specific phishing: criminals holding your license photo and number can craft convincing social-engineering attacks.
  • Check whether your state's motor vehicle department offers license-number reissuance; several states allow requesting a new number after a confirmed breach.
  • Monitor account statements and mail for new-account or address-change activity, and consider identity-monitoring services.

For businesses, the incident is a governance wake-up call. Any company that outsourced identity checks should review its vendor's data-retention practices, assess what document images remain stored in third-party clouds, and prepare customer-notification workflows. The deeper lesson from the IDScan breach is about data minimization: a verification vendor does not need to retain infrared and ultraviolet scans of every ID indefinitely — and every long-lived copy of a credential is a future liability waiting for a breach like this one.

Sources

whatsapp me