IDScan Breach Exposes License Data
IDScan confirmed hackers accessed customer data in its cloud platform after reports linked it to 153 million stolen driver's license scans.
When an identity verification provider confirms that hackers reached the customer records inside its own cloud, the fallout lands on every business that trusted it to check a driver's license at the counter. IDScan has now acknowledged that an unauthorized party may have accessed or copied information belonging to its customers, days after researchers and reporters tied the company to a sprawling database of stolen license images.
The admission, published quietly and buried from search engines, is the first time the company has publicly addressed an incident that had already been circulating in criminal forums and federal investigative channels. What follows is a detailed look at how the disclosure unfolded, what the company says was taken, and where the stolen material appears to have gone.
A Notice Hidden From Search
IDScan disclosed the incident in a security notice dated September 4. In that notice, the company said it learned on or around September 1 that certain data may have been accessed without authorization. The notification was published on the company's site but carried a noindex directive instructing search engines not to surface it. TechCrunch spotted IDScan's breach notification, according to coverage of the filing.
The company's wording is careful, as breach notifications tend to be. It says its investigation "remains ongoing" and that an unauthorized third party "may" have accessed or copied customer information stored within accounts on the IDScan.net cloud. The exposed data, according to the notice, can include customers' full names and driver's license or other government-issued identification numbers.
Notably absent from the notification is any mention that scans of driver's licenses were reportedly stolen as well — a detail that has circulated in reporting around the incident but does not appear in the company's own account.
The Company's First Public Words
IDScan framed its response as immediate. The company said it moved to secure its systems once it understood the scope of the problem and brought in outside help to assess what happened.
"Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident."
— IDScan, in its September 4 security notice
The company also described reviewing its internal safeguards and its posture toward law enforcement.
"In response to this incident, we immediately began an investigation and reviewed our policies and procedures related to data security. We are also cooperating with federal law enforcement on their investigation."
— IDScan, in its September 4 security notice
BleepingComputer has contacted IDScan multiple times with questions about the incident but has not received a response, the outlet reported.
What Was Reportedly Taken
The scale of the material linked to this incident is what drew attention well before IDScan acknowledged anything. Brian Krebs reported on September 1 that a dark-web platform called "Nexus" was advertising access to more than 153 million U.S. and Canadian driver's license scans, according to his account of the service.
That same service allegedly contained 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs reported verifying samples from the database by searching for records belonging to himself and others who consented to the searches, tracing the exposed information back to IDScan.
In its own notice, IDScan said that although full access to the exposed information required payment, it is notifying potentially impacted individuals "in an abundance of caution" and providing free credit monitoring and identity protection services.
- 153 million+ U.S. and Canadian driver's license scans allegedly advertised through the Nexus platform
- 10 million ID cards allegedly included in the same service
- 3 million travel documents allegedly included
- 579,000 medical cards allegedly included
- September 1 — date Krebs reported the Nexus service
- September 4 — date of IDScan's security notice and of prior reporting on lawsuits
Lawsuits Arrive Before the Admission
The legal pressure preceded the public statement. BleepingComputer reported on September 4 that multiple lawsuits had been filed against IDScan after hackers allegedly breached the company and offered access to a database containing more than 153 million driver's licenses.
At that time, IDScan had not publicly acknowledged the incident and had not responded to the outlet's requests for comment. The gap between the lawsuits, the Krebs report, and the company's eventual notice is a familiar sequence in breach disclosures: external researchers and plaintiffs move first, and the affected company speaks once its own investigation has something to say — or once the cost of silence grows.
Nothing in the public record so far indicates that IDScan has confirmed the full 153 million figure as its own tally. The company's notice describes unauthorized access that "may" have occurred, and the larger number traces to the criminal marketplace listing and subsequent reporting, not to IDScan's own count.
Who Relies on IDScan
IDScan provides identity verification technology that businesses use to scan, authenticate, and extract information from government-issued identification documents. Its platform is used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses.
That customer list matters for understanding the blast radius. These are not abstract data processors; they are front-line businesses that check IDs as a condition of doing business — renting a car, selling age-restricted products, opening an account. The records IDScan holds are the same documents those businesses photograph or scan at the point of sale or service.
When a verification vendor's cloud accounts are reached, the downstream exposure is not limited to the vendor's own systems. It includes the identity documents of people who never chose to do business with IDScan directly and may have no idea their license image passed through its platform.
The Marketplace Goes Dark
After news of the Nexus service spread, the platform was taken offline, though the cybercriminals likely still have access to the database. Taking a storefront down does not delete what was already copied or sold.
Since then, multiple threat actors have claimed to be selling the entire database. BleepingComputer has not been able to confirm whether those sales are legitimate, leaving open the question of how many copies of the data exist and who now holds them.
The FBI previously confirmed to BleepingComputer that it was investigating the incident. IDScan says it is cooperating with federal law enforcement on that investigation, a detail the company included in its notice.
What the Notification Leaves Out
Read closely, IDScan's notice is narrower than the reporting around it. The company acknowledges potential unauthorized access to customer information — full names and government-issued identification numbers. It does not confirm the theft of license scans, the 153 million figure, or the existence of the Nexus marketplace.
Those omissions are not unusual in a notification drafted while an investigation is still open, and the company has framed its outreach as precautionary rather than as an admission of confirmed exfiltration. The offer of free credit monitoring and identity protection services is the practical remedy it is extending in the meantime.
For anyone whose license was scanned by a business using IDScan's platform, the notice's language about what "may" have been accessed offers little certainty. The company has not said how many individuals it is notifying, which accounts were affected, or when the unauthorized access began relative to its September 1 discovery.
Why This Matters Beyond One Vendor
The IDScan case sits at an uncomfortable intersection: a company whose product is verifying that people are who they claim to be, now unable to fully account for what happened to the identity documents it processed. If the reported scale holds, the stolen material is not passwords that can be reset but permanent identifiers — names paired with license numbers and, reportedly, images of the documents themselves.
That distinction shapes the risk for the businesses that rely on such vendors. A credential can be rotated; a driver's license number generally cannot. For consumers, this suggests a longer tail of potential fraud, from synthetic identity creation to account opening, that outlasts any single notification cycle.
For the identity verification industry, the episode raises a question its customers will have to weigh: how much identity data should a verification provider retain, and for how long, when the value of that data to attackers is precisely what makes the provider a target. The FBI investigation and the pending lawsuits may eventually clarify the scale. Until then, the company's own notice — cautious, noindexed, and short on specifics — is the only official account available.
Sources
- BleepingComputer Original source
- IDScan said Also reporting
- spotted IDScan's breach notification Also reporting
- multiple lawsuits had been filed against IDScan Also reporting
- Brian Krebs reported Also reporting
Continue Reading
Fake Adobe Reader Pages Hide Rogue RAT
Huntress reports a phishing campaign using browser-in-the-browser tricks to slip rogue ScreenConnect clients past victims.
Cisco confirms exploited Secure FMC flaw
Cisco says attackers are exploiting a maximum-severity Secure FMC bug, but its own July advisory points to earlier activity.
One Exploit Kit, Four Spy Groups, One Week
Proofpoint says China-aligned clusters rapidly adopted BlueMoon, a Chrome and Windows exploit chain that may have cost far less to build than expected.