TechNewsReel
Live

IDScan.net Breach Exposes 153 Million Driver's License Scans in Real-Time Leak

A year-long data siphon from a major identity verification provider has left millions of North Americans vulnerable to identity theft.

TechNewsReel Newsroom · September 4, 2026

A massive security failure at IDScan.net has exposed more than 153 million digital scans of driver's licenses from the United States and Canada. The breach represents a systemic collapse of identity security, as hackers maintained a live feed of sensitive documents for over a year.

The data was exfiltrated in real-time from the Louisiana-based identity verification provider and sold on the dark web through a service known as "Nexus." The scale of the theft remained staggering even as the breach became public; nearly 400,000 new records were added to the stolen database in a single 24-hour window just before the leak was publicized. The Nexus service explicitly claimed it had been "continuously exfiltrating new data for over a year" into its private database.

The Trust Gap

IDScan.net operates as a critical infrastructure piece for thousands of businesses, providing verification services for cannabis dispensaries and Fortune 500 giants including Target, FedEx, and Hertz. The company has positioned itself as a champion of security and regulatory compliance, maintaining a "Trust Center" that claims adherence to the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Furthermore, the company has been a vocal advocate for stricter age verification mandates, such as the Kids Online Safety Act (KOSA).

Systemic Risks

The breach highlights the inherent danger of centralized identity databases. Because driver's licenses serve as primary credentials for opening credit lines and verifying legal identity, the leak provides a turnkey toolkit for large-scale identity theft. Beyond financial fraud, the exposure poses severe physical security risks. For individuals in witness protection or those fleeing domestic violence, the availability of these images allows bad actors to use AI-based image matching to track and locate victims.

Security experts note the irony of the timing: just as the industry attempts to improve authentication controls through license verification, the very systems those improvements depend on are being compromised. This vulnerability transforms a tool meant for security into a liability for millions of citizens.

Ongoing Investigation

The FBI's New Orleans field office has launched an official inquiry to determine the exact source of the images and the method of exfiltration. While the volume of leaked data is confirmed, the full extent of how the real-time siphon was established—and why it remained undetected for over twelve months—remains under investigation. The incident serves as a stark reminder that compliance claims often mask deep-seated technical vulnerabilities in the identity verification pipeline.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.