Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2735+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. IDScan Confirms Breach After Hackers Offer 153 Million Driver's License Scans for Sale
IDScan Confirms Breach After Hackers Offer 153 Million Driver's License Scans for Sale
NEWS

IDScan Confirms Breach After Hackers Offer 153 Million Driver's License Scans for Sale

IDScan disclosed a breach of its cloud platform after stolen scans of driver's licenses, ID cards and travel documents surfaced on a dark web market.

Dylan H.

Security Engineer

September 10, 2026
3 min read

IDScan Confirms Data Breach Exposing Government ID Scans

IDScan, an identity-verification vendor whose scanning technology is used by cannabis retailers, gun stores, banks, and other age- and identity-restricted businesses, has confirmed a data breach after a large cache of stolen identity document scans appeared for sale on a dark web marketplace.

What Happened

According to a breach notice dated September 4 but not widely publicized, IDScan acknowledged that an unauthorized third party accessed its cloud platform and copied customer identity-verification data. The company did not disclose the specific attack method used to gain access, and its notice did not specify how many individuals were affected — leaving that count to be pieced together from the stolen data itself.

Scale of the Exposure

The data offered for sale, first identified and reported by security journalist Brian Krebs, includes:

  • 153 million driver's license scans (U.S. and Canadian citizens)
  • 10 million identification card scans
  • 3+ million travel documents and international IDs
  • 579,000+ medical cards
  • Full names and government-issued ID numbers tied to the scanned documents

Discovery

The breach came to light after Krebs identified the stolen dataset being marketed on Nexus, a Russia-linked dark web marketplace. Krebs authenticated the offering by locating his own scanned records among the samples provided by the seller — a strong indicator that the dataset is genuine rather than a recycled or fabricated listing.

IDScan's Response

IDScan's public response has drawn criticism for its limited visibility. The company:

  • Acknowledged the incident but downplayed its severity, noting the data was not "freely distributed"
  • Applied search-engine indexing blocks to its breach notice, reducing its public discoverability
  • Offered affected individuals free credit monitoring and identity-protection services

The FBI has opened an inquiry into the incident, and multiple lawsuits have reportedly already been filed against the company.

Why This Matters

Identity-verification platforms like IDScan sit at a uniquely sensitive point in the data supply chain: they exist specifically to collect and retain scans of government-issued identity documents on behalf of downstream businesses that never intended to store that data themselves. A breach at this layer doesn't just expose one company's customers — it exposes the customers of every business that relied on IDScan's scanning kiosks and verification services, likely without those individuals ever knowing IDScan held their data at all.

With full names, government ID numbers, and document images now circulating on a criminal marketplace, affected individuals face elevated risk of identity theft, synthetic identity fraud, and document forgery using their real personal details as a template.

Recommendations

For Individuals Who May Be Affected

  1. Request your free credit monitoring if offered by IDScan or a business that used its verification services
  2. Place a credit freeze with major credit bureaus to prevent new accounts being opened in your name
  3. Watch for account-opening or loan notifications that you didn't initiate
  4. Be alert to targeted phishing that references accurate personal details pulled from the leaked scans

For Businesses Using Third-Party Identity Verification

  1. Audit data retention practices with identity-verification vendors — confirm whether scanned documents are retained or purged after verification
  2. Review vendor breach-notification contracts to ensure timely, complete disclosure obligations
  3. Minimize the identity data collected to only what is legally required
  4. Evaluate vendors' security posture before entrusting them with government ID scans

Sources: The Record, Krebs on Security

#Data Breach#IDScan#Identity Verification#Dark Web#Driver's License

Related Articles

IDScan Sued Over Alleged Breach Exposing 153 Million Driver's Licenses

Class actions target ID-verification vendor IDScan after 153M+ driver's licenses and other government IDs surfaced for sale on a dark web 'Nexus' listing.

3 min read

Texas Govt Data Breach Exposes Over 3 Million Driver's Licenses

The Texas Parks and Wildlife Department disclosed a data breach at its license system vendor that exposed personal information for more than three million...

3 min read

FBI Probes Dark Web Service Selling 153M+ Drivers Licenses

A new dark web service called Nexus sells 153M+ US and Canadian drivers licenses, reportedly sourced from ID verification firm idscan.net.

3 min read
Back to all News