153 Million Driver's Licenses Exposed in IDScan.net Data Breach
The FBI is investigating a systemic failure at an identity verification platform used by major brands including Hertz.
A massive security failure has exposed the driver's licenses of approximately 153 million individuals, creating a systemic identity theft risk on a global scale. The stolen data is currently being sold in real-time on a new dark web marketplace known as Nexus.
According to reports from Ars Technica and Cybernews, the breach is linked to IDScan.net, an identity verification platform utilized by a wide array of businesses to process customer documentation. While the breach impacts various sectors, the platform is heavily used by car rental agencies, including Hertz, to verify driver identities and insurance eligibility. The FBI's New Orleans field office has launched an official investigation into the breach to identify the perpetrators and determine the exact point of failure within the IDScan.net infrastructure.
The Vulnerability of Digital Identity
Car rental agencies and other high-traffic businesses frequently require high-resolution scans or digital copies of government-issued IDs for identity verification. These repositories are prime targets for cybercriminals because they contain concentrated amounts of Personally Identifiable Information (PII). Unlike a credit card number or a login password, a driver's license is a static identifier; once the image and associated data are stolen, the victim cannot simply "reset" their identity to secure their accounts.
Industry-Wide Implications
The scale of this breach—affecting 153 million records—suggests a critical vulnerability in the vendor-level software that many companies trust to secure their most sensitive customer data. Because IDScan.net serves as a third-party bridge for multiple industries, the fallout extends beyond car rentals to other major corporations, including FedEx and Target. This incident highlights a growing risk in the "supply chain" of security, where a single point of failure at a verification vendor can compromise the data of millions of customers across unrelated brands.
Long-Term Risks and Next Steps
Victims of this breach face prolonged risks of financial fraud and identity theft. Because the data is being sold on the Nexus marketplace, security experts warn that the information will likely be integrated into larger "fullz" packages used by criminals to open fraudulent lines of credit or bypass KYC (Know Your Customer) checks at financial institutions.
Investigators are currently working to determine how the attackers gained access to the IDScan.net servers and whether the data was exfiltrated over a long period or via a single catastrophic exploit. It remains unconfirmed exactly how many of the 153 million records were sourced specifically from car rental transactions versus other business clients.