IDScan sued over alleged data breach affecting 153 million drivers

A staggering 153 million driver’s licenses have been allegedly breached by hackers who offered to sell access to the sensitive information on a dark-web identity-theft service called “Nexus.” The compromised database is believed to belong to IDScan, an identity verification technology company that provides services to businesses across the US. If true, this would be one of the largest data breaches in recent history, with far-reaching implications for individuals and organizations alike.

IDScan’s systems are used by a wide range of industries, including car rental firms, retailers, financial institutions, and hospitality establishments, among others. The company’s hardware and software solutions allow businesses to scan, authenticate, and extract information from government-issued identity documents. However, it appears that IDScan’s security measures may have been inadequate, allowing hackers to gain access to the sensitive data.

According to investigative journalist Brian Krebs, who first broke the story, the breach was linked to a dark-web service called “Nexus,” which offered for sale access to more than 153 million U.S. and Canadian driver’s license scans, as well as other sensitive information such as ID cards, travel documents, and medical records. Krebs verified the samples by searching the database for his own records and those of other individuals who had consented to the checks.

The FBI has launched an investigation into the incident, with the agency confirming that it is looking into the breach. However, at this stage, it remains unclear whether IDScan’s systems were compromised or if the number of impacted individuals is as high as 153 million. The company has not made any public statements about the allegations and did not respond to our requests for comment.

The potential consequences of this breach are significant. Individuals whose driver’s licenses were compromised may be at risk of identity theft, financial fraud, and other forms of cybercrime. Businesses that used IDScan’s services may also face reputational damage and financial losses as a result of the breach.

Lawsuits have been filed against IDScan in Louisiana, where the company is based, alleging that it failed to protect sensitive information from its clients. The law firms behind the lawsuits are seeking potential claimants for a possible class-action case, which could result in significant compensation for those affected by the breach.

As this story unfolds, it serves as a stark reminder of the importance of robust cybersecurity measures and data protection policies. Organizations must take proactive steps to protect sensitive information from hackers, and individuals should be vigilant about monitoring their accounts and credit reports for signs of suspicious activity. By taking these precautions, we can minimize the risk of identity theft and financial fraud, and ensure that our personal data remains secure online.


Source: Bleeping Computer — 2026-09-04