IDScan sued over alleged data breach affecting 153 million drivers

A Massive Data Breach Affects 153 Million Drivers, Raising Concerns About Identity Verification Company IDScan

A staggering 153 million driver’s licenses have been compromised in a massive data breach involving identity verification company IDScan. The incident has sparked multiple lawsuits and investigations, with several law firms launching potential class-action litigation against the firm. The breach is believed to have occurred through IDScan’s systems, which are used by various businesses across the US, including car rental companies, retailers, and financial institutions.

The breach was first reported by cybersecurity journalist Brian Krebs on September 1st, who discovered that a dark-web identity-theft service called “Nexus” had advertised access to the compromised driver’s license scans. Krebs verified the samples by searching his own records and those of other individuals who had consented to the checks, and tracked the leak to IDScan. The FBI’s New Orleans office has launched an investigation into the incident, which is still ongoing.

IDScan provides hardware and software solutions for businesses to scan, authenticate, and extract information from government-issued identity documents. Its systems are used by a wide range of industries, including hospitality, finance, and retail. However, it appears that IDScan’s security measures may have been compromised, allowing hackers to access sensitive data belonging to millions of individuals.

The lawsuits filed against IDScan allege that the company failed to protect information from its clients, such as global car rental company Hertz. The law firm Markovits, Stock & DeMarco is seeking potential claimants for a possible class-action case and has reported that IDScan has started notifying some business customers about the breach. Given the incident’s potential scale, additional lawsuits could be filed, and related cases may eventually be consolidated into multidistrict litigation.

The breach also raises concerns about the security of identity verification processes in various industries. With hackers having access to a massive database containing sensitive information, individuals who have had their driver’s licenses scanned through businesses using IDScan’s systems may be at risk of identity theft or other malicious activities.

As this incident unfolds, it serves as a reminder that even robust security measures can be breached by determined attackers. In this case, the hackers appear to have obtained valid credentials, which significantly reduced the effectiveness of prevention measures. According to The Blue Report 2026, once attackers have valid credentials, only 37% of their actions are blocked.

For individuals whose driver’s licenses may have been compromised in this breach, it is essential to take steps to protect themselves from potential identity theft. This can include monitoring credit reports, being cautious with personal data online, and keeping software and systems up-to-date with the latest security patches. Businesses that use IDScan’s services should also review their security measures to ensure they are robust enough to prevent similar breaches in the future.


Source: Bleeping Computer — 2026-09-04