IDScan confirms breach involving 153 million stolen driver’s licenses

IDScan

Identity verification company IDScan confirmed that hackers accessed customer data stored on its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver’s license scans.

IDScan disclosed the incident in a Sept. 4 security announcement, saying it learned on or around Sept. 1 that some data may have been accessed without authorization.

“Following this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident.” IDScan said.

The company says its investigation is ongoing but has determined that an unauthorized third party “may” have accessed or copied customer information stored in IDScan.net cloud accounts.

Disclosed information may include customers’ full names and driver’s license or other government-issued identification numbers. Although not mentioned in the notification, the breach also allows threats to steal scans of driver’s licenses.

TechCrunch IDScan Violation Notice noticedwhich was published on September 4, but configured with a noindex directive that instructs search engines not to index the page.

BleepingComputer previously reported on September 4 that multiple lawsuits had been filed against IDScan after hackers allegedly infiltrated the company and offered access to a database containing more than 153 million driver’s licenses.

IDScan has not publicly acknowledged the incident or responded to BleepingComputer’s requests for comment at the time.

The company said that while full access to exposed information requires payment, it notifies potentially affected individuals “with great care” and provides free credit monitoring and identity protection services.

Massive ID database linked to IDScan

The incident became known for the first time after Brian Krebs reported on September 1, a dark web platform called “Nexus” advertised access to more than 153 million driver’s license scans in the US and Canada.

The service is also said to have contained 10 million ID cards, 3 million travel documents and 579,000 medical records.

Krebs checked samples of the database, looking for records belonging to himself and others who agreed to the searches, and traced the exposed information back to IDScan.

IDScan provides identity verification technology that businesses use to scan, authenticate, and retrieve information from government-issued identification documents. Its platform is used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops and hospitality businesses.

After news of the Nexus service spread, the platform was shut down, although cybercriminals likely still have access to the database.

Multiple threats have since claimed to sell the entire database, but BleepingComputer has been unable to confirm whether these sales are legitimate.

IDScan said it is cooperating with federal law enforcement, with the FBI previously confirming to BleepingComputer that it is investigating the incident.

“In response to this incident, we immediately launched an investigation and reviewed our data security policies and procedures,” IDScan said.

“We are also cooperating with federal law enforcement in their investigation.”

BleepingComputer contacted IDScan several times with questions about the incident, but did not receive a response.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *