TechNewsReel
Live

IDScan Breach Exposes 153 Million Driver's Licenses and Security Scans

The theft of high-resolution ID images, including UV and IR scans, creates a catastrophic risk for global identity verification systems.

TechNewsReel Newsroom · September 10, 2026

Identity verification firm IDScan has confirmed a massive data breach involving the theft of approximately 153 million driver's licenses and other government-issued identity documents from its cloud systems. The breach represents a critical failure in the security of high-fidelity identity data, exposing millions of individuals to sophisticated fraud.

The breach first came to light after journalist Brian Krebs reported that a dark web marketplace known as 'Nexus' had begun selling the stolen records. Confirmed reports from TechCrunch and BleepingComputer indicate the leaked data includes full names, driver's license numbers, and identity numbers from passports and other government documents. Most alarmingly, the theft includes high-resolution images of these IDs, featuring infrared (IR) and ultraviolet (UV) scans used to verify authenticity.

The Scale of IDScan's Operations

Based in Louisiana, IDScan operates as a backbone for identity authentication across a diverse range of industries. The company's services are utilized by corporate clients including logistics giants FedEx and Hertz, as well as cannabis dispensaries and entertainment venues. The sheer scale of the company's footprint amplifies the impact of the leak; IDScan currently performs over 21 million verifications every month across 20,000 different locations worldwide.

Why High-Fidelity Data Matters

This breach is considered catastrophic because it does not merely expose text-based data, but the actual security markers used to prevent forgery. By stealing UV and IR scans, attackers possess the exact blueprints required to bypass modern identity verification systems that rely on these invisible spectrums to detect fake IDs.

The security risk extends to the highest levels of government. Confirmed reports indicate that the stolen data included the records of U.S. Secretary of Defense Pete Hegseth, highlighting that no user—regardless of profile—was shielded from the exposure. Threat analyst group vx-underground described the event as "a catastrophic data breach, probably one of the worst I've ever seen."

The Path Forward

As the industry grapples with the fallout, the primary concern remains the long-term utility of the stolen images for identity theft and synthetic identity fraud. While the core volume of 153 million licenses is confirmed, the full extent of other leaked document types remains under scrutiny. Organizations relying on IDScan for authentication must now assume that the visual security markers of millions of documents have been compromised, potentially rendering current verification protocols obsolete for the affected population.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.