IDScan.net Breach Exposes 170 Million Identity Documents
The FBI is investigating the theft of 153 million North American driver's licenses from a major verification provider.
Identity verification provider IDScan.net has confirmed a massive data breach that exposed over 170 million scanned identity documents. The incident provides cybercriminals with a trove of verified government IDs, creating a systemic risk for identity theft across North America.
Based in New Orleans, IDScan.net confirmed the breach after a dark web service known as "Nexus" began selling access to the stolen data. According to confirmed reports, the exposed dataset includes 153 million driver's licenses from the United States and Canada. Beyond licenses, the breach encompasses 10 million ID cards, 3 million travel documents and international IDs, and 579,000 medical cards. The FBI's New Orleans field office has launched a formal investigation into the theft.
The Path to Discovery
The breach surfaced around September 1, 2026, when a user on the Russian cybercrime forum "Exploit" began advertising the Nexus service. Security researcher Brian Krebs reported that the service offered digital scans of identity documents to buyers. To prove the authenticity of the data, the operator of the service provided a free sample consisting of Krebs' own Virginia driver's license.
Industry Implications
This breach is particularly severe because IDScan.net serves as a primary identity verification layer for several major corporations. The company's client list includes high-profile entities such as Target, FedEx, Hertz, Motorola Solutions, Caesars Entertainment, and Jack Henry.
Because these scanned documents are often regarded as the "gold standard" for verifying identity in legal and financial transactions, their availability on the dark web significantly lowers the barrier for sophisticated fraud. Hackers can now use high-quality, verified scans to bypass security checks that typically rely on the visual authenticity of a government-issued ID.
What's Next
As the FBI continues its investigation, the focus shifts to how the data was exfiltrated and whether the breach resulted from a direct attack on IDScan.net's infrastructure or a third-party vulnerability. Affected individuals and corporate clients are likely to face a surge in targeted phishing and synthetic identity fraud attempts using the stolen scans. It remains to be seen if IDScan.net will provide direct notification to the millions of individuals whose documents were compromised.