IDScan Faces Lawsuits Over Alleged Data Breach Exposing 153 Million Driver's Licenses
Identity verification firm **IDScan** is confronting multiple lawsuits and an **FBI** investigation following allegations that a breach exposed over 153 million driver's licenses and other sensitive identity documents. The incident, first reported by **Brian Krebs**, has prompted concerns among IT security professionals and privacy-conscious users about the security of personal data handled by such services.
Multiple lawsuits have been filed against identity verification company **IDScan** after hackers allegedly breached its service, offering to sell more than 153 million driverβs licenses on the dark web.
Law firms, including **Markovits, Stock & DeMarco** and **Hall Attorneys**, have initiated investigations into potential class-action litigation related to the reported security incident.
## The Nexus Dark Web Service
On September 1, cybersecurity journalist **Brian Krebs** initially reported that a dark-web identity-theft service named β**Nexus**β advertised access to a vast trove of personal documents. This included over 153 million U.S. and Canadian driverβs license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
Krebs verified the samples by successfully searching the database for his own records and those of other consenting individuals, ultimately tracing the leak back to **IDScan**.
## What is IDScan?
**IDScan** is a technology company specializing in identity verification. It provides hardware and software solutions that allow businesses to scan, authenticate, and extract information from government-issued identity documents. Its systems are widely used across the U.S. in various sectors, including car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments.
## Official Response and Investigations
**IDScan** has not yet issued any public statements regarding these allegations and did not respond to requests for comment. The extent of the compromise on **IDScan's** systems and the precise number of impacted individuals remain unclear.
**Krebs** also reported that the **FBIβs** New Orleans office has launched an investigation into the incident, a detail independently confirmed by **Reuters**. The **FBI** has confirmed to BleepingComputer that it is looking into the incident but declined further comment due to the ongoing nature of the investigation.
While the illegal service **Nexus** is no longer online, cybercriminals are believed to still possess the database. Reports indicate that the service included documents belonging to **U.S. Secretary of Defense Pete Hegseth** and an assistant director of the **FBI**, although this information could not be independently verified.
## Legal Ramifications and Future Outlook
The lawsuits, filed in Louisiana where **IDScan** is based, allege that the company failed to adequately protect client information, including that of major global car rental company **Hertz**.
**Markovits, Stock & DeMarco** stated that **IDScan** began notifying some business customers around September 1st. The law firm is actively seeking potential claimants for a possible class-action case, noting that individuals whose IDs were scanned through businesses using **IDScan's** systems may be affected.
Given the potential scale of this incident, additional lawsuits and class actions are anticipated. These cases could eventually be consolidated into multidistrict litigation. Furthermore, state attorneys general and federal regulators may launch separate investigations or enforcement actions, mirroring responses to similar large-scale data exposures involving entities like **23andMe**, **Marriott**, and **Equifax**.