A Verification Vendor's Own Data Gets Verified — By a Journalist
Identity-verification company IDScan is facing multiple lawsuits after hackers allegedly breached the company and put a database of more than 153 million driver's licenses up for sale on a dark web service called "Nexus." The leak came to light on September 1, 2026, when security researcher Brian Krebs confirmed the breach was genuine by locating his own driver's license record inside the exposed dataset.
What Was Exposed
| Field | Details |
|---|---|
| Company | IDScan |
| Alleged Records | 153 million+ U.S. and Canadian driver's license scans |
| Also Included | 10 million ID cards, 3 million travel documents, 579,000 medical cards |
| Disclosure Date | September 1, 2026 |
| Disclosed By | Brian Krebs (Krebs on Security) |
| Sale Venue | Dark web marketplace/service "Nexus" |
| Legal Response | Multiple class-action lawsuits filed in Louisiana |
IDScan's technology scans, authenticates, and extracts data from government-issued identity documents, and is deployed across a wide range of industries — car rental companies, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality businesses — anywhere a business needs to verify a customer's government ID. That breadth of deployment is exactly what makes a breach of IDScan's own systems so consequential: the exposed data isn't limited to IDScan's direct customers, but potentially reaches the customers of every business that relied on IDScan to process an ID scan.
The Legal Fallout
Multiple lawsuits have already been filed in Louisiana, where IDScan is headquartered, with law firms including Markovits, Stock & DeMarco and Hall Attorneys opening class-action investigations. The core allegation across the filings is straightforward: that IDScan failed to protect information entrusted to it by its business clients and, by extension, those clients' customers.
IDScan has begun notifying its business customers of the incident but has not issued a public statement addressing the allegations, and did not respond to media requests for comment as of publication.
Why This Matters
A breach of an identity-verification vendor carries outsized risk compared to a typical retailer breach, because the stolen data is the exact material needed to defeat identity checks elsewhere:
- Driver's license scans contain full name, address, date of birth, license number, and photo — everything needed for identity theft or to pass a manual ID check
- Downstream exposure extends to every customer of every business that ran an ID through IDScan's systems, not just IDScan's direct clients
- Medical cards and travel documents in the same trove broaden the potential for targeted fraud beyond simple identity theft
Recommended Actions
- If you've had your ID scanned at a car rental counter, gun shop, dispensary, or hotel in recent years, treat your identity data as potentially exposed and monitor for suspicious account activity or credit inquiries
- Businesses using IDScan should seek direct confirmation from the vendor on whether their specific customer data was included in the exposed dataset
- Enable identity-theft monitoring and consider a credit freeze if you suspect your driver's license data may have been compromised
- Watch for follow-on phishing — leaked government ID data is frequently paired with social engineering attempts that reference accurate personal details to appear legitimate