IDScan.net Breach Linked to 153 Million Driver’s Licences Sold on the Dark Web
The Verification Layer Became the Leak
IDScan.net sells a simple promise: scan the ID, and confirm the person is who they say they are and old enough to buy what they’re buying. Its software handles identity checks at car rental firms, retailers, bars, cannabis dispensaries and Fortune 500 clients across the United States and Canada. It exists to reduce fraud.
This month the New Orleans-based firm confirmed a data breach. It says it received information on or around 1 September 2026 indicating that data may have been accessed without authorisation. It says an unauthorised party may have accessed or copied customer information stored in accounts on its cloud platform, primarily full names and driver’s licence or other government ID numbers.
Investigative reporting links IDScan to a dark-web service that listed more than 153 million driver’s licences. IDScan has confirmed the breach. It has not publicly confirmed that it is the source of that dataset. The FBI’s New Orleans field office has opened an inquiry, and at least four class-action lawsuits have been filed against the company in the Eastern District of Louisiana. IDScan says it is notifying affected individuals and offering free credit monitoring.
How It Surfaced
The company didn’t bring the breach to light. On 31 August, security journalist Brian Krebs was alerted to a new identity-theft service calling itself “Nexus,” advertised on Exploit, a Russian-language cybercrime forum. Nexus claimed to hold identity documents on more than 170 million people across North America. That included more than 153 million driver’s licences, more than 10 million ID cards, more than 3 million travel and international documents, and at least 579,000 medical cards.
The trail to IDScan came from the data itself. Krebs matched scan timestamps to car rentals at Hertz and to ID checks at Planet13 dispensaries, which had publicly partnered with IDScan.net in 2022. The stolen images also showed infrared and ultraviolet scanning features that match IDScan’s own product documentation.
Two further details matter. Before the story broke, the number of licences listed on Nexus rose by nearly 400,000 in a single 24-hour window. That suggested fresh data was still being uploaded, and its operators claimed they had been exfiltrating continuously for more than a year. Then, within hours of Krebs publishing on 1 September, Nexus vanished. Its login page was replaced with a line of text: the service was no longer available.
Taking the storefront down doesn’t delete the data. A dataset this size, sampled and previewed by customers, can be relisted elsewhere or sold privately.
Why a Licence Is Worse Than a Password
Most large breaches involve credentials that can, at least in principle, be rotated. You change a password. The bank reissues a card. It’s painful, but it has an end.
A driver’s licence can’t be rotated. It carries a legal name, date of birth, home address, physical description, a photograph and a government identifier. Most of that never changes, or changes only when the holder moves. There’s no reset. A licence number exposed in September 2026 is still that person’s licence number in 2030.
That makes the data unusually durable for criminals. It’s exactly what you need to open accounts, pass the document checks meant to stop fraud, and build synthetic identities that mix real and invented details. The same scan that proves a customer is 21 can be replayed to prove a stranger is that customer.
The Structural Irony
This part matters beyond one company.
ID verification is being required in more and more of ordinary life. Age-verification rules for online services, alcohol, cannabis, vaping and gambling push businesses to check government IDs rather than take a customer’s word. Most of those businesses don’t build scanning systems themselves. They buy them from a handful of specialist vendors.
So a policy meant to spread the risk of underage or fraudulent sales ends up concentrating the most sensitive data a person carries in a few third-party systems. Each checkout counter handles one licence. The vendor behind all of them handles every one. The push to verify more has helped build a single point of failure.
None of this means verification is wrong. It means a check that stores what it inspects is a different and far riskier thing than a check that inspects and forgets.
What to Watch
- Whether IDScan confirms or disputes the Nexus link. The company has admitted a breach. Whether it accepts that the breach produced the 153 million-record dataset determines the scale of its liability and of the notifications it owes.
- Whether the data resurfaces. Nexus went offline on 1 September, but the records weren’t destroyed. Watch for relistings under a new name.
- What the forensic report says was retained, and for how long. A check that needs the data for seconds was apparently keeping it. Whether full licence images were stored is the central question.
- State responses. Several states are expanding age-verification mandates. Whether any add data-minimisation rules (scan, confirm, discard) is the policy lever this breach puts on the table.
If your business scans IDs, there’s something concrete you can do this week. Ask your vendor, in writing, whether licence data is stored after verification, for how long, and where. If the answer is “yes”, “indefinitely” or “we’d have to check”, you’re holding a liability you didn’t know you had. The best protection is data that was never kept.
Get the weekly briefing
One email a week on AI, infrastructure, policy and the supply chains underneath them. Free, and you can unsubscribe any time.