IDScan has confirmed that an unauthorized party accessed customer information held on its cloud platform. The disclosure follows reports linking the company to a database containing more than 153 million driver’s license scans.
The identity verification provider discovered the incident around September 1, 2026. It then published a security notice on September 4.
According to IDScan, the investigation remains active. However, current findings show that an unauthorized third party may have accessed or copied information from customer accounts on the IDScan.net cloud.
Personal Information May Have Been Exposed
The compromised data may include full names and numbers from driver’s licenses or other government-issued identification documents. Reports also indicate that the attackers obtained scanned copies of driver’s licenses.
IDScan said it quickly secured its systems after discovering the intrusion. Furthermore, the company hired third-party specialists to determine the nature and scale of the incident.
The breach notice did not confirm exactly how many people were affected. It also did not explain how the attackers entered the cloud environment or how long they had access.
Although viewing all the exposed data reportedly required payment, IDScan is notifying potentially affected individuals as a precaution. The company is also offering free credit monitoring and identity protection services.
Breach Notice Was Hidden From Search Engines
IDScan published its security notice on September 4. However, the page included a noindex directive, which instructed search engines not to include it in their results.
As a result, the notice attracted limited attention until TechCrunch identified it several days later. Before then, IDScan had not publicly responded to questions about the alleged breach.
Meanwhile, several lawsuits had already targeted the company. The complaints followed claims that hackers had accessed a database holding more than 153 million driver’s license scans.
Nexus Advertised Millions of Identity Documents
The IDScan data breach first drew public attention after researcher Brian Krebs reported on a dark-web service called Nexus. The platform advertised access to more than 153 million U.S. and Canadian driver’s license scans.
In addition, Nexus allegedly held 10 million identification cards and 3 million travel documents. The collection also reportedly included 579,000 medical cards.
Krebs tested samples by searching for his own information and records belonging to other consenting individuals. He then traced the exposed data back to IDScan.
The company provides technology that scans, verifies and extracts details from government-issued documents. Its customers operate across several industries, including financial services, retail, hospitality and car rental.
Cannabis dispensaries, gun shops and other businesses that must verify customer identities also use the platform. Therefore, the exposed database could contain documents collected across many different sectors.
Criminals May Still Hold the Stolen Database
Nexus disappeared from the internet after reports about the service became public. Nevertheless, taking the platform offline does not mean the stolen information has been deleted.
The people behind the operation may still possess the database. Moreover, several other threat actors have since claimed that they can sell the entire collection.
Those offers remain unverified. Still, identity documents can create long-term risks because victims cannot replace personal details as easily as passwords.
Criminals may use stolen license scans to support identity fraud, bypass verification checks or create convincing fraudulent accounts. The combination of document images and personal information makes the exposure particularly serious.
FBI Investigates the IDScan Data Breach
IDScan says it is cooperating with federal law enforcement. The FBI has also confirmed that it is investigating the incident.
The company added that it has started reviewing its data security policies and procedures. However, it has not publicly answered detailed questions about the breach.
Several important facts consequently remain unclear. These include the number of affected customers, the attack method and the exact dates of unauthorized access.
The company has also not confirmed whether the reported total of 153 million driver’s license scans accurately represents the stolen material. Its investigation is continuing.


0 responses to “IDScan Confirms Data Breach Linked to 153 Million Driver’s License Records”