A Louisiana-based company called IDScan.net has confirmed that hackers accessed its cloud platform and stole data including names and driver’s licence numbers from more than 153 million people in the United States and Canada. The breach came to light not through the company’s own disclosure but through investigative reporting by security journalist Brian Krebs, who traced a dark web marketplace called Nexus back to IDScan after being offered his own driver’s licence as a free sample.

Most of the people affected have never heard of IDScan. That’s exactly the problem.

Who Is IDScan and Why Does It Have Your ID?

IDScan provides identity verification technology to businesses that need to check age or confirm identity quickly at point of sale. Car rental agencies, retailers, entertainment venues, casinos, cannabis dispensaries, and bars all use services like IDScan’s to scan a customer’s ID at the counter and confirm it’s genuine.

Clients confirmed to use IDScan technology include Hertz, Target, and Caesars Entertainment. When you handed your driver’s licence to a Hertz employee to rent a car, or showed ID at a casino, that scan likely went into a database you never knew existed — one that, it now turns out, was inadequately secured.

The stolen database reportedly contains more than driver’s licence images. Nexus’s listing included front-and-back images of licences, as well as infrared and ultraviolet scans — the specialised images used to verify security features on physical documents. Also included: more than 10 million identification cards, over 3 million travel documents, and approximately 579,000 medical cards including marijuana dispensary cards. The timestamps on the records appear to align with when holders actually used their ID at a business — meaning the data is verified as real and current.

What IDScan Has Actually Confirmed

IDScan published a data security notice on September 4 — but buried it on its website in a location search engines didn’t index, and didn’t add it to its press releases section. The notice confirmed that on or around September 1, the company received information indicating data may have been accessed without authorisation. It secured its systems, hired third-party forensic specialists, and is cooperating with federal law enforcement.

The FBI’s New Orleans field office has opened a formal investigation. The agency confirmed it is “looking into the incident” but declined further comment given the ongoing nature of the investigation.

Nexus claimed it had been “exfiltrating new data for over a year into our private database” — meaning this may not have been a single breach event but a sustained, ongoing extraction that went undetected for months. IDScan has not confirmed or denied that timeline. Shortly after Krebs published his report, the Nexus marketplace went offline.

Defence Secretary Pete Hegseth’s driver’s licence reportedly appeared in the leaked database — one of several high-profile government officials whose ID data is now in criminal hands, according to reports. That detail underscores how widely IDScan’s technology was deployed.

Why This Breach Is Different From a Password Leak

Most data breaches expose passwords, email addresses, or payment card numbers. Those are serious — but they can be changed. A driver’s licence cannot. Your name, date of birth, address, licence number, and physical appearance are permanently associated with that document, and a high-resolution scan of the front, back, and security features is everything a fraudster needs to impersonate you or create a convincing fake ID.

Licences typically expire and get renewed — but the data doesn’t become useless just because the card does. The combination of personal information, physical appearance, and verified identity is exactly what identity thieves use to open bank accounts, apply for loans, file false tax returns, and commit medical fraud in your name. These crimes can take months or years to surface and longer to resolve.

What to Do Right Now

Given the scale and nature of this breach, taking protective action now is worth the effort even if you’re not certain your data was included.

  • Place a credit freeze at all three major bureaus — Equifax, Experian, and TransUnion. A freeze prevents anyone from opening new credit in your name without your explicit permission. It’s free, takes about 15 minutes online, and is the single most effective protection against new-account fraud.
  • Place a fraud alert alongside the freeze if you want an additional layer. A fraud alert requires lenders to take extra steps to verify identity before opening new accounts.
  • Monitor your credit reports at AnnualCreditReport.com, which now provides free weekly access to reports from all three bureaus. Look for any accounts or inquiries you don’t recognise.
  • Watch for targeted phishing. Fraudsters with your full name, address, and photo can craft highly convincing impersonation attempts — phone calls, emails, or text messages that appear to know specific personal details. Be sceptical of any unexpected contact claiming to be from a financial institution, government agency, or utility provider.
  • IDScan says it will offer free credit monitoring to affected individuals. Watch for a notification letter. If you receive one, use the service — it won’t protect against all fraud, but it adds a detection layer.

For more on protecting your identity and accounts from breaches like this, see our guides on how to protect your digital privacy in 2026 and the worst cyberattacks and data breaches of 2026.

Read more tech related articles here.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *