Breaking
Cyber CrimeDeveloping Story

IDScan Lawsuits Grow Over ID Data Leak

Multiple lawsuits target IDScan after alleged breach exposed 153M driver's licenses for sale on dark web.

··1 hour ago·2 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash

Identity verification provider IDScan is facing multiple lawsuits after a dark-web service allegedly advertised access to more than 153 million driver's license scans, according to reports. The legal action comes as the FBI investigates the incident, and as law firms seek potential class-action claimants.

Leak Traced to IDScan

On September 1, cybersecurity journalist Brian Krebs reported that a dark-web identity-theft service called “Nexus” advertised access to more than 153 million U.S. and Canadian driver's license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified samples by searching for his own records and those of others who consented to checks, and tracked the leak to IDScan.

IDScan provides hardware and software for businesses to scan and authenticate government-issued IDs. Its systems are used across the U.S. in car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments.

Lawsuits Target Data Protection

Several law firms, including Markovits, Stock & DeMarco and Hall Attorneys, have launched investigations into potential class-action litigation. Lawsuits were filed in Louisiana, where IDScan is based, alleging the company failed to protect client information, such as that belonging to global car rental company Hertz.

Markovits, Stock & DeMarco says IDScan began notifying some business customers around September 1. The firm says people whose IDs were scanned through businesses using IDScan may be affected and is seeking potential claimants.

FBI Investigation Confirmed

Krebs reported that the FBI's New Orleans office opened an investigation into the incident, and Reuters independently confirmed it. The FBI also confirmed to BleepingComputer that it is looking into the incident, but declined further comment due to the ongoing investigation.

The illegal Nexus service is no longer online, but criminals may still have access to the database. BleepingComputer reports that the database included documents belonging to U.S. Secretary of Defense Pete Hegseth and an assistant director of the FBI, though it could not verify that information.

Company Silent on Allegations

IDScan has not published any statements about the allegations and did not respond to BleepingComputer's requests for comment. As of now, it is unclear whether IDScan's systems were compromised or the number of impacted individuals.

Potential Legal Fallout

The incident's scale could lead to further lawsuits, consolidation into multidistrict litigation, or separate actions by state attorneys general and federal regulators, similar to prior large-scale exposures at 23andMe, Marriott, and Equifax. However, these remain possibilities rather than confirmed developments.

For consumers, the exposure of driver's license images and other identity documents increases the risk of identity theft and fraud. For businesses using IDScan, the case highlights the need to vet third-party vendors and ensure robust data protection measures are in place.

#idscan#data breach#driver's license#identity theft#class action

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories