LmCast :: Stay tuned in

IDScan confirms breach tied to 153 million stolen driver’s licenses

Recorded: Sept. 10, 2026, 3:10 p.m.

Original Summarized

IDScan confirms breach tied to 153 million stolen driver’s licenses

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

IDScan confirms breach tied to 153 million stolen driver’s licenses

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Microsoft says September updates fix mouse settings reset issues

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityIDScan confirms breach tied to 153 million stolen driver’s licenses

IDScan confirms breach tied to 153 million stolen driver’s licenses

By Lawrence Abrams

September 10, 2026
10:55 AM
0

Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans.
IDScan disclosed the incident in a September 4 security notice, saying it learned on or around September 1 that certain data may have been accessed without authorization.
"Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident," IDScan said.
The company says its investigation remains ongoing but has determined that an unauthorized third party "may" have accessed or copied customer information stored within accounts on the IDScan.net cloud.
The exposed information can include customers' full names, and driver's license or other government-issued identification numbers. While not mentioned in the notification, the breach reportedly also allowed threat actors to steal scans of driver's licenses.
TechCrunch spotted IDScan's breach notification, which was published on September 4 but configured with a noindex directive that instructed search engines not to index the page.
BleepingComputer previously reported on September 4 that multiple lawsuits had been filed against IDScan after hackers allegedly breached the company and offered access to a database containing more than 153 million driver's licenses.
At the time, IDScan had not publicly acknowledged the incident or responded to BleepingComputer's requests for comment.
The company said that although full access to the exposed information required payment, it is notifying potentially impacted individuals "in an abundance of caution" and providing free credit monitoring and identity protection services.
Massive ID database linked to IDScan
The incident first came to light after Brian Krebs reported on September 1 that a dark-web platform called "Nexus" was advertising access to more than 153 million U.S. and Canadian driver's license scans.
The service also allegedly contained 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
Krebs verified samples from the database by searching for records belonging to himself and others who consented to the searches and traced the exposed information back to IDScan.
IDScan provides identity verification technology that businesses use to scan, authenticate, and extract information from government-issued identification documents. Its platform is used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses.
After news of the Nexus service spread, the platform was taken offline, though the cybercriminals likely still have access to the database.
Since then, multiple threat actors have claimed to be selling the entire database, but BleepingComputer has not been able to confirm if these sales are legitimate.
IDScan said it is cooperating with federal law enforcement, with the FBI previously confirming to BleepingComputer that it was investigating the incident.
"In response to this incident, we immediately began an investigation and reviewed our policies and procedures related to data security," IDScan said.
"We are also cooperating with federal law enforcement on their investigation."
BleepingComputer has contacted IDScan multiple times with questions about the incident but has not received a response.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
IDScan sued over alleged data breach affecting 153 million drivers220 million traveler records exposed in Vietnam-linked APIS leakFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataExfilSquad hackers leak info of over 100,000 UK police officers, staffCoca-Cola confirms data theft in Fairlife ransomware attack

Data Breach
Data Leak
Driver License
FBI
IDScan

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Identity verification company IDScan confirmed a data breach involving the exposure of customer information linked to more than 153 million driver's license scans. This incident was disclosed by IDScan in a security notice on September 4, stating that unauthorized third parties may have accessed or copied customer data stored on its cloud platform on or around September 1. The exposed information reportedly includes customers' full names, driver's license numbers, and scans of driver's licenses.

The breach originated from activity on a dark-web platform named Nexus, which was advertising access to a massive database containing over 153 million U.S. and Canadian driver's license scans. This source allegedly contained additional sensitive materials, including ten million ID cards, three million travel documents, and 579,000 medical cards. Investigation by Brian Krebs verified samples from this database, tracing the exposed information back to IDScan's platform. IDScan utilizes identity verification technology for businesses such as car rental companies, financial institutions, and retail establishments to scan and authenticate government-issued documents.

Following the emergence of reports regarding the Nexus service, IDScan took immediate action to secure its systems, engaged external specialists to assess the incident, and began an internal investigation. The company affirmed its cooperation with federal law enforcement agencies, including the FBI, regarding the ongoing investigation. Although some threat actors have claimed ownership or intent to sell the entire database, IDScan has stated that full access to the exposed information requires payment, and they are providing free credit monitoring and identity protection services to potentially affected individuals as a precautionary measure. The incident underscores significant concerns regarding data security protocols within identity verification systems.

Beyond the specific breach, the text touches upon broader cybersecurity context, noting that once attackers possess valid credentials, the effectiveness of prevention measures diminishes significantly, as only thirty-seven percent of their actions are blocked. This is contextualized by defenses measured across simulations, such as the Blue Report 2026, which assesses security techniques in customer production environments.