More than 153 million driver’s license scans were advertised for sale on a dark‑web forum, and the company whose cloud platform investigators traced those records to has confirmed unauthorized access.
IDScan confirms cloud breach, outlines timeline
Identity verification firm IDScan disclosed on September 4 that it had learned on or around September 1 that certain data stored in its IDScan.net cloud platform "may" have been accessed without authorization. The company said it "took immediate steps to secure our systems and engaged a team of third‑party specialists to help determine the full nature and scope of the incident," and that its investigation remains ongoing.
IDScan’s notice said an unauthorized third party may have accessed or copied customer information held within accounts on the IDScan.net cloud. The company added that, although full access to the exposed information required payment, it is notifying potentially impacted individuals "in an abundance of caution" and is providing free credit monitoring and identity protection services.
The Nexus database: scale, contents, and verification
The incident surfaced when a dark‑web service called "Nexus" was advertised as providing access to more than 153 million U.S. and Canadian driver’s license scans, Brian Krebs reported on September 1. The same advertisement purportedly included 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
Krebs verified samples from the database by searching for records belonging to himself and others who consented to searches, and he traced the exposed information back to IDScan. After the Nexus advertisement spread, the platform was taken offline, although security reporting said the cybercriminals likely still have access to the dataset. Since that time, multiple threat actors have claimed to be selling the full database; BleepingComputer reported it has not been able to confirm whether those sales are legitimate.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWho used IDScan’s technology and how that broadens the exposure
IDScan provides identity verification technology that businesses use to scan, authenticate, and extract information from government‑issued identification documents. According to reporting, the platform is used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses.
Because those sectors rely on scanned government IDs to transact business or check age and identity, the reported exposure of full names and driver’s license or other government‑issued identification numbers — and, according to other reporting, the scans themselves — expands the potential impact beyond a narrow technical breach to any customer whose ID was captured by those services.
Legal action and law‑enforcement response
BleepingComputer reported on September 4 that multiple lawsuits had been filed against IDScan after the allegations surfaced. The company said it is cooperating with federal law enforcement on their investigation; the FBI previously confirmed to BleepingComputer that it was investigating the incident. Separately, TechCrunch noted that IDScan’s breach notification page was configured with a noindex directive when it was published on September 4.
BleepingComputer also reported that it contacted IDScan multiple times with questions about the incident but had not received a response as of that reporting.
What this means for car rental companies, retailers, and affected individuals
- Car rental companies and hospitality businesses that rely on IDScan for on‑site identity checks will need to determine whether records scanned at their locations are part of the exposed dataset and coordinate notifications with IDScan and counsel.
- Retailers, cannabis dispensaries, gun shops, and financial institutions should watch for evidence of fraud tied to exposed driver’s license numbers or names and consider whether additional customer‑facing authentication measures are warranted while investigations continue.
- Affected individuals should expect notifications from the company and have been offered free credit monitoring and identity protection services by IDScan; they may also need to monitor accounts tied to the exposed identity information if they receive direct notice.
The core facts remain stark: a dark‑web service advertised a dataset traced to IDScan that allegedly contains more than 153 million driver’s license scans, IDScan has acknowledged potential unauthorized access to customer data in its cloud, federal authorities are investigating, and multiple parties have claimed to sell the dataset. IDScan says it has taken immediate remediation steps and engaged third‑party specialists, but its investigation is ongoing and public reporting has not verified the scope of any final disclosure or the legitimacy of subsequent sales offers.
Source: BleepingComputer — IDScan confirms breach tied to 153 million stolen driver’s licenses




