← Terug naar overzicht

Multiple lawsuits have been filed against IDScan, an identity verification company, following an alleged data breach by hackers. The breach reportedly exposed data from over 153 million driver's licenses. The hackers allegedly offered to sell the stolen data. The scale of the breach makes it one of the largest identity-related incidents involving driver's license data. IDScan provides identity verification services, making this breach particularly sensitive given the nature of the personal data involved. The lawsuits signal significant legal and financial consequences for the company. The incident raises concerns about the security practices of identity verification service providers.

Technical details

A dark-web identity-theft service called 'Nexus' advertised access to a database allegedly stolen from IDScan, an identity verification technology company. The database reportedly contained over 153 million U.S. and Canadian driver's license scans, 10 million ID card records, 3 million travel documents, and 579,000 medical cards. Brian Krebs verified the breach by searching the database for his own records and those of consenting individuals, tracing the leak back to IDScan. IDScan's systems are used by car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments across the U.S. The Nexus dark-web service has since been taken offline, but cybercriminals reportedly still retain access to the stolen database. IDScan began notifying some business customers around September 1, 2026. The FBI's New Orleans office launched an investigation into the incident.

Mitigation steps

1. Individuals who have had their IDs scanned at businesses using IDScan systems (e.g., car rental, retail, gun shops, cannabis dispensaries, hospitality) should monitor their credit reports and financial accounts for signs of identity theft. 2. Consider placing a credit freeze or fraud alert with major credit bureaus. 3. Businesses using IDScan should review their vendor contracts and assess exposure under applicable data protection regulations. 4. Potential class-action claimants can contact law firms such as Markovits, Stock & DeMarco or Hall Attorneys. 5. Organizations should monitor for regulatory inquiries from state attorneys general and federal regulators such as the FTC. 6. Security teams should review identity verification vendors for data handling and breach notification practices. 7. Await official statements from IDScan and the FBI's New Orleans office for further guidance.

Affected products

  • IDScan identity verification hardware and software solutions
  • IDScan systems used by Hertz (car rental)
  • IDScan systems used by retailers
  • and hospitality establishments
  • cannabis dispensaries
  • financial institutions
  • gun shops

Related threat actors

  • Nexus (dark-web identity-theft service operator)

IOC's

Dark-web service name: Nexus, Data types exposed: driver's license scans (153M+), ID cards (10M+), travel documents (3M+), medical cards (579,000+)

Categories

  • Data Breach & Exfiltration
  • Identity & Access