IDScan.net Faces Lawsuits and FBI Probe Over 153 Million Driver's License Leak
A massive dark web database containing high-resolution ID scans has triggered federal investigations and class-action suits against the verification provider.
Identity verification provider IDScan.net is facing multiple class-action lawsuits and a federal investigation following the discovery of a massive database of driver's license scans on the dark web. The leak, which involves approximately 153 million records from the U.S. and Canada, represents one of the most significant exposures of government-issued identification data to date.
The data was first identified on a dark web service known as "Nexus," according to reports from cybersecurity journalist Brian Krebs. The leaked database allegedly contains high-resolution front-and-back images of licenses, including specialized infrared (IR) and ultraviolet (UV) scans typically used by businesses to verify the authenticity of a document. While IDScan.net has not officially confirmed the full scope of the breach, the company has stated that it is currently investigating the incident.
The Federal Response
The scale of the exposure has drawn the attention of federal law enforcement. The FBI's New Orleans field office has opened an inquiry into the situation, coinciding with the filing of several class-action lawsuits against the New Orleans-based company in Louisiana courts. The legal actions center on the alleged failure of IDScan.net to protect sensitive personal imagery used by its clients in the retail, hospitality, and travel sectors.
The Risk of Permanent Data
This breach is particularly critical because of the nature of the stolen information. Unlike credit card numbers or passwords, which can be canceled and reset, government-issued ID numbers and biometric images are permanent. Once these high-resolution scans enter the hands of cybercriminals, the affected individuals face a lifelong risk of identity theft.
Security experts warn that the inclusion of IR and UV scans provides attackers with the exact tools needed to create sophisticated forged documents that can bypass standard security checks. Furthermore, the incident underscores the systemic vulnerability of the "supply chain" data model, where third-party verification vendors become centralized, high-value targets for attackers by aggregating the sensitive data of millions of users across different industries.
What Remains Unconfirmed
While the core of the breach is well-documented, some specific details remain under scrutiny. Reports have circulated that the database allegedly included the license of U.S. Secretary of Defense Pete Hegseth, though some primary sources note this specific claim has not been independently verified. As the FBI investigation continues and the class-action lawsuits proceed through the Louisiana court system, the full extent of the security failures at IDScan.net and the exact number of compromised individuals are expected to emerge.