Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
IDScan.net Confirms Breach After 153 Million Driver’s Licenses Leaked
September 11, 2026
Critical Ivanti EPMM CVE-2023-35078 Flaw Lets Attackers Access Devices
September 11, 2026
Okta Patches Critical Auth0 and Access Gateway Flaws
September 11, 2026
Home/CyberSecurity News/IDScan.net Confirms Breach After 153 Million Driver’s Licenses Leaked
CyberSecurity News

IDScan.net Confirms Breach After 153 Million Driver’s Licenses Leaked

Key Takeaways IDScan.net, a prominent identity verification provider, has confirmed a data breach affecting over 153 million driver’s licenses and other identification documents. The...

Jennifer sherman
Jennifer sherman
September 11, 2026 4 Min Read
3 0

Key Takeaways

  • IDScan.net, a prominent identity verification provider, has confirmed a data breach affecting over 153 million driver’s licenses and other identification documents.
  • The compromised data, including sensitive government-issued IDs, is being actively sold on a new cybercrime marketplace called “Nexus.”
  • The breach appears to be ongoing, with threat actors claiming continuous data exfiltration for over a year and new records added daily.
  • The FBI has initiated an investigation, and IDScan.net is offering credit monitoring services to affected individuals.

Identity Verification Firm IDScan.net Confirms Massive Data Breach

IDScan.net, a Louisiana-based company specializing in identity verification technology utilized by major retailers, hospitality venues, and Fortune 500 enterprises for age and identity validation, has officially acknowledged a significant data breach. This confirmation follows the emergence of a new illicit marketplace advertising access to over 153 million driver’s licenses from both the United States and Canada.

Table Of Content

  • Key Takeaways
  • Identity Verification Firm IDScan.net Confirms Massive Data Breach
  • Breach Uncovered by Investigative Journalism
  • Nexus Marketplace Details and Scope of Compromised Data
  • IDScan.net’s Response and Recommendations
  • What You Should Do

The company stated it detected unauthorized access to its internal systems around September 1, 2026. Following this discovery, IDScan.net immediately began efforts to secure its digital environment and engaged third-party forensic experts to thoroughly investigate the scope and nature of the intrusion.

Breach Uncovered by Investigative Journalism

The extent of the breach was brought to wider public attention not solely through IDScan.net’s internal timeline, but primarily through the investigative efforts of cybersecurity journalist Brian Krebs. On August 31, Krebs received a tip about “Nexus,” a newly launched identity theft service being promoted on the Russian-language cybercrime forum, Exploit.

To substantiate the data’s authenticity, the seller on Nexus provided Krebs with a sample of his own Virginia driver’s license. This critical piece of evidence ultimately enabled researchers to trace the origin of the leaked data back to a widely utilized identity verification vendor.

In response to the incident, the New Orleans field office of the Federal Bureau of Investigation has initiated a formal inquiry into the source of the compromised images. IDScan.net has affirmed its full cooperation with federal law enforcement agencies.

Nexus Marketplace Details and Scope of Compromised Data

The Nexus platform claims to possess identity documents for more than 170 million individuals across North America. This vast trove reportedly includes upwards of 153 million driver’s licenses, over 10 million identification cards, more than 3 million travel and international documents, and at least 579,000 medical cards.

A basic search performed on the platform reportedly yielded approximately 11.5 million results pages, a figure consistent with the advertised totals. Researchers also discovered that Canadian records alone exceeded 1.1 million, with nearly 474,000 originating from Ontario.

Significantly, the exposed data set contains a diverse range of sensitive credentials, including commercial driver’s licenses, Common Access Cards (CAC) utilized for entry into government facilities, and even marijuana dispensary identification cards. This breadth suggests the breach extends far beyond typical consumer retail IDs, encompassing a broader spectrum of government-issued and regulated identification documents.

Adding to the concern, operators behind Nexus assert that they have been “continuously exfiltrating new data for over a year” into a private database. The marketplace allows potential customers to preview redacted records and photos before committing to a purchase for full access.

Krebs observed a rapid increase in the platform’s driver’s license count, which climbed by nearly 400,000 records within a single 24-hour period. This observation indicates the breach may still be an active intrusion rather than a static, historical data dump.

Reports also suggest that high-profile individuals have been impacted by the exposure, including a record for U.S. Defense Secretary Pete Hegseth. This detail highlights the potential national security implications of a leak that affects not only ordinary citizens but also government officials.

IDScan.net’s Response and Recommendations

In its official notification, IDScan.net stated that an unauthorized third party may have gained access to or copied customer information stored in accounts on its cloud platform. This data primarily includes full names and driver’s license numbers or other government-issued identification numbers.

Although full access to the stolen data on dark web marketplaces requires payment, the company is proactively notifying potentially impacted individuals and offering complimentary credit monitoring and identity protection services as a precautionary measure.

Individuals who believe they may be affected can enroll in these services or seek further information by calling 1-833-516-2980 between 8 a.m. and 8 p.m. ET on weekdays, or by contacting the company directly at its Metairie, Louisiana address.

IDScan.net advises anyone notified of exposure to remain vigilant against identity theft and fraud. This includes regularly reviewing credit reports and account statements for any unfamiliar activity or billing discrepancies.

Given that driver’s license numbers are frequently used for identity verification across financial accounts, government benefits, and even notarized transactions, security researchers strongly recommend freezing credit files with major bureaus and actively monitoring for any new account applications opened in one’s name.

This incident underscores a significant and escalating risk within the identity verification industry. As more businesses increasingly outsource “know your customer” processes to third-party scanning vendors, the compromise of a single provider can lead to the exposure of sensitive identity documents belonging to millions of individuals who may have never directly interacted with the breached company.

What You Should Do

  • Enroll in Credit Monitoring: If you receive a notification from IDScan.net, immediately enroll in the free credit monitoring and identity protection services offered.
  • Freeze Your Credit: Contact the three major credit bureaus (Equifax, Experian, and TransUnion) to freeze your credit files. This prevents new credit accounts from being opened in your name.
  • Monitor Financial Statements: Regularly review all bank statements, credit card statements, and other financial accounts for any suspicious or unauthorized activity.
  • Be Wary of Phishing: Exercise extreme caution with emails, calls, or texts requesting personal information, even if they appear to be from legitimate sources.
  • Update Passwords: Change passwords for critical online accounts, especially those related to financial services, government benefits, and healthcare. Consider using a password manager and enabling multi-factor authentication (MFA) wherever possible.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachExploitSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Ivanti EPMM CVE-2023-35078 Flaw Lets Attackers Access Devices

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New attack vector: Adversarial machine learning hides AI commands in plain text
September 11, 2026
Best Enterprise Browsers for 2026
September 11, 2026
Top Cloud Security Posture Management (CSPM) Tools for 2026
September 11, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us