Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
▣ Breach IDSCAN-150-MILLION 2026-09-18

IDScan.net: Year Long Cloud Intrusion Exposes Driver's License Data for 150M+ People

"Identity verification vendor IDScan.net has confirmed that an unauthorized third party accessed and copied customer data stored in its cloud platform, after a dark web marketplace began advertising searchable access to…"

Identity verification vendor IDScan.net has confirmed that an unauthorized third party accessed and copied customer data stored in its cloud platform, after a dark web marketplace began advertising searchable access to scanned government ID documents belonging to people across the United States and Canada. The company says it learned of the claim on or around September 1, 2026, the same day independent journalist Brian Krebs published his report on the listing, and posted a breach notice to its website on September 4. Figures for the scale of the exposure differ by source: the dark web listing and most outlets covering it (BleepingComputer, Help Net Security, The Record) cite more than 153 million driver's license scans, TechCrunch and The Paypers frame it as "more than 150 million," and IDScan itself has declined to state how many individuals are affected, with The Paypers noting only that the company's own marketing materials claim records for over 150 million licenses. Reuters, reporting a day after Krebs, described the exposure more conservatively as "tens of millions" of licenses. The FBI's New Orleans field office has opened an investigation.

What Happened

The incident surfaced publicly on September 1, 2026, when Krebs reported that a Russia-linked dark web identity theft service called Nexus was offering searchable access to a very large corpus of scanned identity documents. According to BleepingComputer and The Record, Krebs was alerted to the listing by a source on August 31 and authenticated the data by querying it for his own record and for records of other individuals who had consented to the check. He then traced the dataset back to IDScan.net. TechCrunch reports that the database also contained records for high-profile individuals, naming U.S. Secretary of Defense Pete Hegseth, and that a security researcher independently verified his own record for Krebs' story.

IDScan, a Louisiana-based firm whose hardware and software are used by car rental companies, retailers, gun shops, financial institutions, hospitality venues, and cannabis dispensaries to scan and authenticate government ID, did not acknowledge an intrusion for several days. On September 4, BleepingComputer reported that multiple lawsuits had already been filed and that the company had not responded to requests for comment. That same day, IDScan quietly published a security notice on its own site. TechCrunch, which was first to spot the notice, and The Record both report that the page carried a noindex directive telling search engines not to list it, which made the disclosure difficult to find.

The company's own language is carefully hedged. Per the notice quoted by BleepingComputer, Help Net Security, and The Record: "While the investigation is ongoing, IDScan.net has determined that an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud." IDScan says it moved immediately to secure its systems, engaged third-party specialists, reviewed its data security policies and procedures, and is cooperating with federal law enforcement.

One point where accounts diverge in emphasis: TechCrunch and The Paypers describe the underlying compromise as a year-long intrusion, based on the earlier reporting that preceded the confirmation. IDScan's own notice does not state a dwell time, an initial access date, or an attack vector. Treat the year-long characterization as reported rather than company-confirmed.

What Was Taken

IDScan's notice describes the affected data as potentially including full names and driver's license or other government-issued identification numbers. TechCrunch adds that identity numbers from other government documents such as passports are in scope. Notably, the company notice as quoted does not mention document images, but BleepingComputer states that the breach also allowed threat actors to steal scans of the licenses themselves, and Krebs reported that the Nexus service exposed photos alongside the record data.

The composition of the dataset advertised on Nexus, as reported by Krebs and relayed by BleepingComputer, Help Net Security, and The Record, breaks down as:

That is a materially richer package than the "names and ID numbers" framing in IDScan's notice. The gap between what the company disclosed and what the marketplace was selling is the single most important detail in this incident for anyone assessing their own exposure.

The sensitivity here is close to worst case. Driver's license images are a primary breeder document for account opening, KYC onboarding, and identity proofing. Unlike a password or a payment card, a license number and its associated photo cannot be rotated. Help Net Security notes IDScan is offering free credit monitoring and identity protection to those it notifies, which is standard practice but addresses only a fraction of the downstream risk from stolen document images.

Why It Matters

This is a supply chain failure at the identity layer. IDScan does not hold a customer relationship with the 150 million plus people whose documents it processed; it holds those documents because a rental counter, a dispensary, a gun shop, or a hotel front desk scanned them. The individuals affected almost certainly do not know the company exists, and the businesses that fed it data may not have understood the retention profile of what they were sending to a third-party cloud.

BleepingComputer reports that the lawsuits filed in Louisiana allege IDScan failed to protect information belonging to its clients, naming Hertz among them. That framing matters for defenders: if your organization routes ID scans through a verification vendor, your customers' documents may now be in a criminal marketplace regardless of the state of your own security program, and you may inherit the notification and litigation exposure.

The marketplace dimension compounds it. According to BleepingComputer, Nexus itself is no longer online, but criminals retain access to the database. Takedown of a storefront does not retract a dataset. The Paypers notes that IDScan's notice referred to full access requiring payment, wording the outlet reads as an apparent reference to a ransom demand, though whether IDScan received or responded to such a demand is not confirmed by any source here. Read against Krebs' account, the "payment" language is at least as consistent with the Nexus service's paywalled search function as it is with extortion.

The Attack Technique

Root cause has not been disclosed. IDScan's notice states only that an unauthorized third party may have accessed or copied customer information stored within accounts on the IDScan.net cloud platform. TechCrunch, The Paypers, and Help Net Security consistently describe the target as the company's cloud infrastructure rather than on-premise scanning hardware deployed at customer sites.

No source in this set identifies an initial access vector, a named threat actor, malware, or an exploited vulnerability. There is no indication of credential stuffing versus exposed storage versus compromised API keys. The "year-long hack" characterization in TechCrunch and The Paypers implies extended undetected access consistent with either stolen valid credentials or a misconfigured or over-permissioned cloud data store, but that is inference, not reporting. The distribution channel is the only well-attested part of the chain: the data surfaced on Nexus, a Russia-linked dark web identity theft service offering per-record search rather than bulk dumps.

Anyone building detection content off this incident should work from the shape of it rather than from indicators, because no usable indicators have been published.

What Organizations Should Do

  1. Inventory your ID verification vendors and what they retain. Determine whether IDScan.net, or any comparable provider, is in your stack directly or through a reseller or POS integration. Then establish specifically whether the vendor retains document images post-verification or only a pass/fail result. Image retention is the risk multiplier in this incident.

  2. Force a retention and deletion conversation with those vendors, in writing. Ask for retention periods, storage location, encryption at rest, and a deletion attestation for records you no longer need verified. Where the business case allows, move to verify-and-discard rather than verify-and-store.

  3. Audit cloud access paths for third-party identity data. Enumerate service accounts, API keys, and tenant-level credentials that can read ID document stores. Enforce MFA on every human and machine path, scope keys to least privilege, rotate long-lived credentials, and alert on anomalous bulk read or export volume. Long-dwell cloud data theft is typically caught by egress volume anomalies, not by endpoint tooling.

  4. Reassess any workflow that treats a driver's license image as proof of identity. With document scans circulating at this scale, image-based verification should be paired with liveness checks, issuer-side validation, or out-of-band confirmation before it gates account opening, credential recovery, or high-value transactions. Assume attackers can produce a genuine-looking scan for a large share of the North American adult population.

  5. Prepare for downstream notification and legal exposure now. If you fed customer documents to an affected vendor, determine your obligations under applicable state and provincial breach statutes before regulators or plaintiffs' firms determine them for you. Litigation is already active in Louisiana, per BleepingComputer, with multiple firms soliciting class-action claims.

  6. Train fraud and help desk teams on the specific abuse pattern. Expect a rise in social engineering that pairs a stolen license number, photo, and address to defeat knowledge-based authentication. Update KBA policies accordingly, and monitor for synthetic identity applications using real license numbers attached to mismatched biographic data.

Sources: IDScan confirms breach of over 150 million driver's licenses | IDScan confirms breach tied to 153 million stolen driver’s licenses | ID verification giant IDScan confirms data breach with more than 15... | FBI Probes Service Selling 153M+ Drivers Licenses | IDScan confirms breach after 153 million driver’s licenses leak on... | IDScan sued over alleged data breach affecting 153 million drivers | IDScan confirms breach after hackers offer 153 million driver's ... | FBI probes report of data breach exposing millions of drivers ...