IDScan Confirms Cloud Breach Amid Claims of 153 Million Stolen Driver’s-License Scans
Data Breaches

Illustrative image generated with AI

IDScan Confirms Cloud Breach Amid Claims of 153 Million Stolen Driver’s-License Scans

IDScan confirmed unauthorized access to IDScan.net amid claims 153M driver's licenses were listed on Nexus dark-web market. Investigation ongoing.

Text generated by artificial intelligence, published without human review. AI transparency

Listen to this articleAudio edition · 10 min

Identity-verification provider IDScan has confirmed potential unauthorized access to customer information stored on IDScan.net, its cloud platform. The disclosure follows the appearance of a vast identity-document database on the dark-web marketplace Nexus.

The advertised collection reportedly contained more than 153 million scans of United States and Canadian driver’s licenses, alongside millions of other identification documents. However, IDScan has not established that every record offered through Nexus came from its systems.

The company also has not disclosed how many customers or individuals were affected. Its investigation remains in progress.

IDScan discovered potential cloud access on September 1

IDScan became aware on September 1, 2026, that an unauthorized third party may have accessed or copied information held in customer accounts on IDScan.net. On the same date, cybersecurity journalist Brian Krebs reported that Nexus was selling access to more than 153 million driver’s-license scans.

IDScan published a security notice on September 4, 2026. The company identified potentially exposed information as including:

  • Full names.
  • Driver’s-license numbers.
  • Other government-issued identification numbers.

The notification did not provide a complete inventory of compromised data. In particular, it did not expressly confirm that the intruder obtained document images, although reporting about the Nexus marketplace connects the incident to driver’s-license scans.

The notice was also configured with a noindex directive, instructing search engines not to include the page in search results. That configuration did not prevent direct access to the notice but may have made it harder to discover through ordinary searches.

By September 10, 2026, IDScan’s breach confirmation and the continuing investigation had been publicly reported in greater detail. Multiple lawsuits had reportedly already been filed against the company, although an exact number has not been disclosed.

The Nexus dataset may extend far beyond driver’s licenses

The database advertised through Nexus was reportedly much broader than its headline figure suggested. Its claimed contents included:

  • More than 153 million U.S. and Canadian driver’s-license scans.
  • Approximately 10 million identification-card scans.
  • More than 3 million travel documents or international IDs.
  • At least 579,000 medical cards.

Krebs reportedly checked the collection for his own information and for records belonging to other people who consented to the searches. Those results helped connect the data to IDScan.

Earlier reporting described indications that Nexus possessed a large and possibly fast-moving identity-document collection. Even so, several key claims remain unverified.

IDScan has not said how many of the records advertised by Nexus originated from its platform. It has not confirmed that the marketplace’s stated totals are accurate, nor that all advertised documents are authentic. A collection of 153 million scans also does not necessarily represent 153 million different people because individuals can have multiple images, renewed licenses, or duplicate records.

Nexus reportedly sold access to the database rather than making it freely downloadable. The marketplace was later taken offline after attracting public attention, but that does not invalidate copies already obtained by paying users or marketplace operators.

Other actors subsequently claimed to possess and sell the complete database. Those offers have not been authenticated.

The intrusion method remains unknown

The affected product is IDScan.net, IDScan’s cloud-based identity-verification service. Organizations use the platform to scan government documents, assess their authenticity, and extract identity information for business or compliance workflows.

No affected software versions have been disclosed. Because IDScan.net is a cloud service, the incident has not been tied to a customer-installable release that organizations can patch independently.

There is also no identified CVE or publicly documented product vulnerability. The available information does not establish whether the attacker:

  • Breached IDScan’s central infrastructure.
  • Took over one or more customer accounts.
  • Used stolen administrative or API credentials.
  • Exploited a cloud configuration error.
  • Abused a legitimate integration.
  • Exploited an undisclosed software flaw.

Consequently, this is not a CISA Known Exploited Vulnerabilities catalog event with a published remediation deadline. It is a cloud data-breach investigation without a disclosed technical root cause.

The identity of the unauthorized party is also unknown. The Record described Nexus as Russia-linked, but that characterization does not establish who initially accessed IDScan.net or who supplied the marketplace database.

The FBI is investigating. No suspected actor, intrusion technique, malware family, ransom demand, or destructive activity has been publicly identified.

Exposure could affect identity-dependent businesses and their customers

IDScan technology is used by organizations that need to verify identity, age, eligibility, or regulatory status. Reported customer sectors include car-rental companies, retailers, financial institutions, cannabis businesses, gun shops, and hospitality providers.

The immediate victims are potentially the people whose documents were processed and retained. Full names paired with genuine identification numbers can support impersonation, fraudulent onboarding, targeted phishing, and attempts to defeat know-your-customer controls.

Document images would create additional risk if their exposure is confirmed. A scan can contain structured identity fields and visual elements useful in social-engineering campaigns or fraudulent verification attempts. The exact fields available vary by document, and IDScan has not released a full data schema for the compromised records.

Organizations using the platform face a separate operational problem. They may need to determine whether data submitted to IDScan was also copied into internal databases, support systems, compliance archives, or third-party integrations. Those downstream copies could expand the incident’s scope even if the original cloud access has been contained.

The reported industries also rely heavily on identity checks for high-consequence transactions. Fraudulent account creation, vehicle rental, financial activity, regulated purchases, and hotel bookings may all be attempted using authentic personal attributes.

The scale remains uncertain. The Nexus figures suggest potentially systemic exposure, but they should not be treated as IDScan’s confirmed breach count.

IDScan is notifying individuals while the investigation continues

IDScan said it took steps to secure its systems after discovering the activity and brought in third-party specialists to investigate the incident’s nature and scope. The company is also reviewing its security policies and cooperating with federal law enforcement.

Potentially affected individuals are being notified and offered free credit-monitoring and identity-protection services. IDScan has not published a final customer count or a complete list of compromised data types.

Customers should not assume that the absence of a notification means their environments are unaffected while the investigation remains open. Organizations using IDScan.net should identify which business units, applications, and API integrations submitted identity documents to the service.

Defensive measures should include:

  1. Review IDScan.net account activity. Look for unexpected logins, administrative changes, bulk queries, exports, or document-verification activity.
  2. Validate administrative access. Remove dormant accounts and confirm that current privileges match operational requirements.
  3. Rotate relevant secrets. Replace potentially exposed passwords, API keys, access tokens, and integration credentials.
  4. Enforce strong multifactor authentication. Prioritize administrator and service-management accounts.
  5. Examine connected systems. Determine whether document images or extracted fields were replicated to customer databases, logs, backups, or analytics platforms.
  6. Reduce retained identity data. Review whether government-ID scans are stored longer than legal or operational requirements demand.
  7. Prepare fraud teams and help desks. Attackers may use accurate personal details to make phishing, impersonation, and account-recovery attempts appear credible.

Affected individuals should be particularly cautious of messages that reference real license details or claim to concern document replacement, account verification, legal action, or credit protection. Possession of accurate identity data does not make a message legitimate.

The central questions remain unanswered: how the intruder gained access, how long access persisted, and what portion of the Nexus collection came from IDScan. Until those findings are released, both customers and individuals must plan around a potentially broader exposure than the company has so far confirmed.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsIDScan breachdriver's license data breachIDScan.netidentity theftNexus dark webcloud security breach
Back to home