IDScan.net Breach Exposes 153 Million Driver's License Records
A massive leak of identity verification data from the US and Canada has triggered an FBI investigation.
Identity verification firm IDScan.net has suffered a massive data breach exposing the records of approximately 153 million people across the United States and Canada. The leak, which involves the theft of driver's license scans and associated metadata, represents one of the largest compromises of government-issued identification data to date.
According to reports from USA Today and PCMag, the stolen data appeared on Nexus, a marketplace on the dark web. The exposed records include full names, driver's license numbers, other government-issued ID numbers, and high-resolution photos of the licenses. IDScan confirmed via USA Today that an unauthorized third party may have accessed or copied customer information stored within its cloud infrastructure.
The Invisible Middleman
IDScan.net operates as a third-party identity verification provider, serving as a behind-the-scenes layer for businesses in the banking, retail, hospitality, and transportation sectors. This includes major car rental companies such as Hertz, which use the service to scan and verify customer IDs. Because IDScan.net functions as a vendor rather than a consumer-facing brand, millions of individuals are likely unaware that their sensitive identification data was being processed and stored by the company.
Implications for Identity Security
This breach is particularly severe because government ID numbers, unlike passwords or credit card digits, are static and extremely difficult for individuals to change. The theft of actual license scans provides attackers with a comprehensive toolkit for identity fraud. While some reports suggest the inclusion of infrared and ultraviolet captures could potentially be used to create fraudulent IDs that pass professional security checks, the primary danger remains the sheer volume of verified personal data now available to cybercriminals.
Federal Response and Next Steps
The scale of the exposure has drawn the attention of federal law enforcement, with the FBI's New Orleans field office opening an official investigation into the breach. As the investigation continues, the focus remains on determining the full extent of the cloud infrastructure compromise and identifying the actors behind the Nexus marketplace listing. Affected individuals are encouraged to monitor their credit reports and be vigilant against sophisticated phishing attempts that may leverage the stolen ID data.