IDScan confirms breach tied to 153 million stolen driver’s licenses
IDScan, an identity verification company, confirmed a data breach involving unauthorized access to customer data stored on its cloud platform. The breach exposed sensitive information including full names and driver's license or other government-issued ID numbers, with reports indicating that scans of over 153 million U.S. and Canadian driver's licenses were compromised. The incident was discovered around September 1, 2026, and IDScan has engaged third-party specialists and law enforcement to investigate. The company is notifying affected individuals and offering free credit monitoring and identity protection services. Multiple lawsuits have been filed against IDScan following the breach. The stolen data was initially advertised on a dark-web platform called Nexus, which has since been taken offline, though the database may still be accessible to threat actors.
AI Analysis
Technical Summary
IDScan experienced a security breach where an unauthorized third party accessed or copied customer information stored within its cloud platform. The compromised data includes customers' full names and government-issued identification numbers, including scans of driver's licenses. The breach was linked to a dark-web marketplace advertising a database containing over 153 million U.S. and Canadian driver's license scans, along with millions of other ID documents. IDScan discovered the breach around September 1, 2026, and has taken steps to secure its systems and is cooperating with federal law enforcement. The company is providing notifications and credit monitoring services to potentially impacted individuals. The investigation is ongoing, and multiple threat actors have claimed to sell the stolen database.
Potential Impact
The breach exposed highly sensitive personally identifiable information (PII), including full names and government-issued ID numbers, as well as scans of driver's licenses for over 153 million individuals. This level of exposure poses significant risks of identity theft, fraud, and other malicious activities targeting affected individuals. The breach also damages the trust in IDScan's identity verification services and has led to multiple lawsuits. The availability of this data on dark-web marketplaces increases the likelihood of widespread misuse.
Mitigation Recommendations
IDScan has taken immediate steps to secure its systems upon discovery of the breach and engaged third-party specialists to investigate. The company is cooperating with federal law enforcement agencies. Affected individuals are being notified and offered free credit monitoring and identity protection services. No specific patch or fix is applicable as this is a breach incident rather than a software vulnerability. Organizations using IDScan services should monitor communications from the vendor and follow any additional guidance provided. Individuals potentially impacted should utilize the offered credit monitoring and remain vigilant for signs of identity theft.
IDScan confirms breach tied to 153 million stolen driver’s licenses
Description
IDScan, an identity verification company, confirmed a data breach involving unauthorized access to customer data stored on its cloud platform. The breach exposed sensitive information including full names and driver's license or other government-issued ID numbers, with reports indicating that scans of over 153 million U.S. and Canadian driver's licenses were compromised. The incident was discovered around September 1, 2026, and IDScan has engaged third-party specialists and law enforcement to investigate. The company is notifying affected individuals and offering free credit monitoring and identity protection services. Multiple lawsuits have been filed against IDScan following the breach. The stolen data was initially advertised on a dark-web platform called Nexus, which has since been taken offline, though the database may still be accessible to threat actors.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
IDScan experienced a security breach where an unauthorized third party accessed or copied customer information stored within its cloud platform. The compromised data includes customers' full names and government-issued identification numbers, including scans of driver's licenses. The breach was linked to a dark-web marketplace advertising a database containing over 153 million U.S. and Canadian driver's license scans, along with millions of other ID documents. IDScan discovered the breach around September 1, 2026, and has taken steps to secure its systems and is cooperating with federal law enforcement. The company is providing notifications and credit monitoring services to potentially impacted individuals. The investigation is ongoing, and multiple threat actors have claimed to sell the stolen database.
Potential Impact
The breach exposed highly sensitive personally identifiable information (PII), including full names and government-issued ID numbers, as well as scans of driver's licenses for over 153 million individuals. This level of exposure poses significant risks of identity theft, fraud, and other malicious activities targeting affected individuals. The breach also damages the trust in IDScan's identity verification services and has led to multiple lawsuits. The availability of this data on dark-web marketplaces increases the likelihood of widespread misuse.
Defensive Guidance
IDScan has taken immediate steps to secure its systems upon discovery of the breach and engaged third-party specialists to investigate. The company is cooperating with federal law enforcement agencies. Affected individuals are being notified and offered free credit monitoring and identity protection services. No specific patch or fix is applicable as this is a breach incident rather than a software vulnerability. Organizations using IDScan services should monitor communications from the vendor and follow any additional guidance provided. Individuals potentially impacted should utilize the offered credit monitoring and remain vigilant for signs of identity theft.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6aa2c6dc8744ddd5a6d00bbd
Added to database: 09/10/2026, 15:03:56 UTC
Last enriched: 09/10/2026, 15:04:04 UTC
Last updated: 09/10/2026, 17:53:23 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.