IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500 clients, has confirmed a data breach after a criminal marketplace began advertising more than 153 million driver’s licenses from the United States and Canada.

The company disclosed that it detected unauthorized access to its systems on or around September 1, 2026, and immediately began securing its environment while bringing in third-party forensic specialists to determine the scope of the intrusion.

IDScan.net Data Breach

The breach came to light not through IDScan.net’s own disclosure timeline alone, but through investigative reporting from security journalist Brian Krebs, who was alerted on August 31 to a new identity theft service called “Nexus” being advertised on the Russian-language cybercrime forum Exploit .

The seller offered Krebs his own Virginia driver’s license as a free sample to prove the data was genuine, a tactic that ultimately helped researchers trace the leak back to a widely used identity verification vendor.

The Federal Bureau of Investigation’s New Orleans field office has since opened a formal inquiry into the source of the leaked images, and IDScan.net says it is cooperating with federal law enforcement.

Nexus claims to hold identity documents on more than 170 million people across North America, including upwards of 153 million driver’s licenses, over 10 million identification cards, more than 3 million travel and international documents, and at least 579,000 medical cards .

A blank search on the platform returned roughly 11.5 million results pages, a figure consistent with the advertised totals, and researchers found that Canadian records alone exceeded 1.1 million, with Ontario accounting for nearly 474,000 of them .

Notably, the trove includes commercial driver’s licenses, Common Access Cards used for government facility entry, and even marijuana dispensary identification cards, suggesting the stolen dataset spans a far broader swath of government-issued and regulated IDs than a typical retail breach.

Perhaps most alarming is the claim from the operators behind Nexus that they have been “continuously exfiltrating new data for over a year” into a private database, with customers able to preview redacted records and photos before purchasing full access.

Krebs observed the platform’s driver’s license count climb by nearly 400,000 records within a single 24-hour window, suggesting the breach may still be active rather than a one-time historical dump.

High-profile individuals have reportedly been swept up in the exposure as well, including a record for U.S. Defense Secretary Pete Hegseth, underscoring the national security implications of a leak touching government officials alongside ordinary consumers .

Incident Parameter Disclosed Technical Details & Scope Operational & Risk Implications
Affected Entity IDScan.net (Louisiana-based identity verification provider) Outsources ID validation for retail, hospitality, and Fortune 500 clients
Exposed Database Size 170M+ total records; 153M+ driver’s licenses, 10M+ ID cards Spans US and Canadian documents (1.1M+ Canadian, ~474K in Ontario)
Document Types Driver’s licenses, CAC government cards, medical & dispensary IDs Extends beyond consumer retail IDs to military and regulated credentials
Illicit Marketplace “Nexus” service advertised on Exploit forum Offers searchable previews with front/back, infrared, and UV scans
Breach Activity Window Continuous exfiltration claimed over 1+ year; ~400K added in 24h Active intrusion rather than a static legacy repository leak
Law Enforcement & Triage FBI New Orleans field office formal inquiry; external forensics Mandatory credit monitoring offered; cloud account access investigated

In its official notice, IDScan.net stated that an unauthorized third party may have accessed or copied customer information stored in accounts on its cloud platform, primarily full names and driver’s license or other government-issued identification numbers.

The company noted that while full access to the stolen data on dark web marketplaces required payment, it is notifying potentially impacted individuals out of caution and offering free credit monitoring and identity protection services.

Affected individuals can enroll or ask questions by calling 1-833-516-2980 between 8 a.m. and 8 p.m. ET on weekdays, or by writing to the company’s Metairie, Louisiana address.

IDScan.net urges anyone notified of exposure to stay vigilant against identity theft and fraud by closely reviewing credit reports and account statements for unfamiliar activity or billing errors.

Because driver’s license numbers are often used to verify identity for financial accounts, government benefits, and even notarized transactions, security researchers recommend freezing credit files with major bureaus and monitoring for new account applications in one’s name.

The incident illustrates a growing risk in the identity verification industry itself: as more businesses outsource “know your customer” checks to third-party scanning vendors, a single compromised provider can expose sensitive identity documents belonging to millions of people who never directly interacted with the breached company.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web appeared first on Cyber Security News.