Over 153 million Driver’s Licenses Exposed in Massive Breach Affecting IDScan Customers
A major cybersecurity incident has left millions of individuals vulnerable to identity theft and financial exploitation. Identity verification company IDScan has confirmed that hackers accessed customer data stored on its cloud platform, exposing sensitive information including driver’s license scans for over 153 million people.
The breach was first discovered by investigative journalist Brian Krebs, who reported on a dark-web platform called “Nexus” advertising access to the massive database of driver’s licenses. IDScan provides identity verification technology used by various businesses, and its platform is vulnerable to unauthorized access. The company has since acknowledged the incident, stating that an investigation remains ongoing.
The exposed information includes customers’ full names and government-issued identification numbers. While not explicitly mentioned in the notification, it appears that threat actors were also able to steal scans of driver’s licenses. This information can be used for identity theft, financial fraud, or other malicious purposes. The fact that hackers may have accessed this sensitive data without payment is particularly concerning.
It’s worth noting that IDScan’s breach notification was published on September 4 but was configured with a noindex directive, which prevented search engines from indexing the page. This has led to speculation about the company’s willingness to disclose the incident openly and transparently. When BleepingComputer reached out for comment, IDScan failed to respond.
The incident highlights the importance of robust cybersecurity measures in protecting sensitive data. While IDScan is providing free credit monitoring and identity protection services to potentially affected individuals, it remains unclear how many people are at risk. The fact that multiple threat actors have claimed to be selling the entire database raises concerns about the potential for further exploitation.
IDScan’s cooperation with federal law enforcement, including the FBI, is a positive step in addressing this incident. However, more transparency and accountability from companies handling sensitive data are needed to prevent such breaches from occurring in the future.
To protect yourself from similar incidents, it’s essential to be cautious when sharing personal information online. Verify the authenticity of any company or service requesting your ID documents, and ensure that you’re using reputable identity verification services. Stay informed about cybersecurity news and updates, and take advantage of free resources offered by companies like IDScan in the wake of a breach.
Ultimately, this incident serves as a reminder that even with robust security measures in place, data breaches can still occur. By staying vigilant and taking proactive steps to protect your sensitive information, you can reduce the risk of falling victim to identity theft or financial exploitation.
Source: Bleeping Computer — 2026-09-10