Skip to main content
Emerging ThreatsData Breaches

IDScan Faces Lawsuits Over Alleged Breach Exposing 153 Million Driver's Licenses

Law enforcement office with blurred computer screen in background.

More than 153 million U.S. and Canadian driver’s license scans — along with 10 million ID cards, 3 million travel documents and 579,000 medical cards — were advertised for sale on a dark‑web identity‑theft service called “Nexus,” according to reporting that has set off multiple lawsuits and a federal probe.

What the Nexus advertisement says

Security reporter Brian Krebs published the initial account on September 1, documenting that the dark‑web service Nexus advertised access to the large trove of identity documents. Krebs’s writeup included samples and described the advertised dataset as comprising more than 153 million driver’s license scans from the United States and Canada, along with the other categories of documents.

How the leak was traced to IDScan

Krebs said he verified the samples by searching the database for his own records and those of other individuals who consented to checks, and from that work “tracked the leak to IDScan.” IDScan is described in reporting as an identity verification technology company that supplies hardware and software allowing businesses to scan, authenticate and extract information from government‑issued identity documents. The company’s systems are used across the U.S. in car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries and hospitality establishments.

Legal fallout in Louisiana and the plaintiffs’ claims

Multiple lawsuits have been filed against IDScan in Louisiana, where the company is based. The complaints allege that IDScan failed to protect information from its clients — the filings name global car rental company Hertz as a business customer whose records may have been exposed. Several law firms, including Markovits, Stock & DeMarco and Hall Attorneys, have launched investigations into potential class‑action litigation related to the reported incident.

Markovits, Stock & DeMarco told reporters that IDScan began notifying some business customers around September 1. Given the scale that has been reported, the firms suggest additional lawsuits, including potential class actions, could follow; related cases may eventually be consolidated into multidistrict litigation.

FBI New Orleans probe and criminal access

Reporting states the FBI’s New Orleans office has launched an investigation into the incident; Reuters independently confirmed the FBI’s involvement. As of publication, the agency had not issued an official statement on the incident and had not responded to requests for confirmation.

Investigators also noted that the Nexus service is no longer online, but that cybercriminals still have access to the underlying database, meaning the material advertised has not necessarily been contained simply because the storefront disappeared.

What this means for Hertz, business customers, and affected individuals

  • Hertz and other named business customers: Plaintiffs’ filings center on business customers whose patrons’ documents were scanned through IDScan systems; those businesses may face notification obligations and exposure to litigation if courts find the vendor failed to secure client data.
  • Other businesses using IDScan technology: Retailers, gun shops, financial institutions, cannabis dispensaries, hospitality firms and car rental companies that used IDScan’s scanning and verification products are the putative source of records in the advertised dataset; those organizations will be watching notifications from IDScan and consulting counsel about breach response and regulatory obligations.
  • Affected individuals whose IDs were scanned: The law firms seeking potential claimants say people whose IDs were scanned through businesses using IDScan’s systems may be impacted; plaintiffs’ counsel are actively recruiting claimants for possible class litigation.

Legal observers and regulators are likely to watch this case closely. The reporting notes that state attorneys general and federal regulators could launch separate investigations or enforcement actions, “as it has happened with similar‑scale data exposures in the recent past, including for 23andMe, Marriott, and Equifax.”

Finally, the incident highlights a recurring operational point about intrusion and post‑access activity: “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply,” the Blue Report 2026 is quoted as saying. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

IDScan has not published any statements about these allegations and did not respond to BleepingComputer’s requests for comment, according to the reporting. It remains unclear from the available public record whether IDScan’s systems were directly compromised or exactly how many individuals have been affected; federal and private investigations are ongoing.

Original reporting at BleepingComputer