TechNewsReel
Live

IDScan.net Breach Exposes 153 Million North American Driver's Licenses

A massive leak of high-resolution identity documents, including infrared and ultraviolet scans, creates a critical national security risk.

TechNewsReel Newsroom · September 14, 2026

Identity verification provider IDScan.net has confirmed a massive data breach that exposed the personal records of over 153 million people across the United States and Canada. The leak provides bad actors with high-fidelity identity documents that could be used to bypass sophisticated security systems.

According to company notices and security reports, an unauthorized third party accessed customer data stored on IDScan.net's cloud platform around September 1, 2026. In addition to the 153 million driver's licenses, the breach included 10 million ID cards, 3 million travel documents, and 579,000 medical cards. The stolen data was subsequently sold via a dark web service known as "Nexus."

Technical analysis of the leaked records reveals a level of detail rarely seen in typical data breaches. Each license record contained six separate image files: three pairs of front-and-back photos, a basic scan, and specialized infrared and ultraviolet versions. These high-resolution scans are designed to verify the authenticity of a physical document, meaning the stolen files contain the very security markers used to prevent forgery.

The Infrastructure of the Leak

IDScan.net, based in Louisiana, provides identity verification services for a wide range of clients, including retailers, car rental companies, and cannabis dispensaries. The breach first surfaced on the Russian cybercrime forum "Exploit" before the Nexus service was launched to commercialize the data. The scale of the exposure was brought to light by security journalist Brian Krebs, whose reporting helped link the data to the IDScan.net platform.

National Security Implications

Security experts warn that this breach is a national security disaster. Because the leak includes UV and IR scans, the documents are not merely images but verified blueprints of identity. This allows criminals to create near-perfect fraudulent documents that can deceive automated identity verification systems. The potential for large-scale identity theft, the creation of fraudulent financial accounts, and the impersonation of government officials poses a systemic risk to secure infrastructure.

Current Status and Investigation

Following the public disclosure of the breach, the FBI's New Orleans field office opened an investigation into the incident. Shortly after the investigation became public, the Nexus dark web site disappeared. While the site is offline, the data remains a permanent risk, as the high-fidelity scans are likely mirrored across other criminal repositories. Authorities continue to monitor the dark web for further distribution of the exposed records.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.