IDScan Confirms Data Breach After 153 Million Driver's Licenses Surface on Dark Web
Identity verification company **IDScan** has officially acknowledged a data breach impacting its cloud platform, days after reports linked the firm to a massive database containing over 153 million driver's license scans. The incident potentially exposed full names, driver's license numbers, and other government-issued identification information belonging to its customers.

**IDScan**, a prominent identity verification company, has confirmed that unauthorized parties accessed customer data stored in its cloud platform. This admission follows days of speculation and reports linking the company to a colossal database of over 153 million driver's license scans advertised on the dark web.
### Breach Disclosure and Investigation
**IDScan** disclosed the incident in a security notice dated September 4, stating that it became aware of potential unauthorized data access around September 1. "Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident," **IDScan** stated.
The company's ongoing investigation indicates that an unauthorized third party "may" have accessed or copied customer information from **IDScan.net** cloud accounts. While **IDScan**'s notification explicitly mentions full names and driver's license or other government-issued identification numbers, earlier reports also indicated the theft of actual scans of driver's licenses.
**TechCrunch** noted that **IDScan**'s breach notification, though published on September 4, was initially configured with a 'noindex' directive, preventing search engines from listing it. Prior to **IDScan**'s public acknowledgment, **BleepingComputer** reported on September 4 that multiple lawsuits had already been filed against the company in connection with the alleged breach.
**IDScan** has stated that while full access to the exposed information required payment from the threat actors, it is notifying potentially impacted individuals out of an "abundance of caution" and offering free credit monitoring and identity protection services.
### The Nexus Database and Its Origins
The full scope of the incident first emerged on September 1, when **Brian Krebs** reported on a dark-web platform named "**Nexus**." This service was reportedly advertising access to over 153 million U.S. and Canadian driver's license scans, alongside 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
**Krebs** was able to verify samples from the database, tracing the exposed information back to **IDScan**. **IDScan** provides technology used by various businessesβincluding car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businessesβto scan, authenticate, and extract data from government-issued identification documents.
Following widespread news of the **Nexus** service, the platform was taken offline. However, it is widely believed that the cybercriminals still retain access to the database. Since then, multiple threat actors have claimed to be selling the entire database, though the legitimacy of these subsequent sales remains unconfirmed.
**IDScan** has confirmed its cooperation with federal law enforcement, with the **FBI** previously acknowledging its investigation into the incident. "In response to this incident, we immediately began an investigation and reviewed our policies and procedures related to data security," **IDScan** reiterated, emphasizing its collaboration with authorities.