IDScan Data Breach May Expose 153 Million Driver’s Licenses
An alleged IDScan data breach may have just exposed more than 153 million driver’s license records belonging to people in the United States and Canada. The records are being sold through Nexus, a dark web identity service that lets buyers search for individual people and purchase copies of their government-issued identification. Many of the records include an actual image of the driver’s license, and some include multiple high-resolution scans of the same document.

This is not a normal breach involving email addresses, passwords, or a spreadsheet filled with personal information. The records being sold can include the driver’s license itself, the photograph printed on the license, the person’s home address, date of birth, signature, physical description, license number, expiration date, barcode information, and other data printed or encoded on the card.
Nexus claims to have more than 153 million driver’s license records, more than 10 million other identification cards, more than 3 million travel documents and international IDs, and at least 579,000 medical cards. The service also contains records identified as cannabis cards, commercial driver’s licenses, and other government identification. Some records are marked CAC, which may refer to Common Access Cards issued to U.S. military personnel and other government employees.
The 153 million number should not be treated as 153 million confirmed individual victims yet. Nexus supplied the count, some people appear more than once, and the total includes records from both the United States and Canada. Searches limited to Canadian driver’s licenses reportedly returned about 1.1 million records, including more than 470,000 from Ontario.
Even with those limits, the size of the database is massive. The records were searchable while Nexus was online, and people whose licenses appeared in the service were able to confirm that the documents were real. In several cases, timestamps attached to the images also matched dates when those people had recently handed their license to a business for identification.
Evidence increasingly points to IDScan.net, a Louisiana company that provides ID scanning and identity verification technology to businesses across the United States. IDScan has not publicly confirmed that all of the Nexus records came from its systems, and the FBI has not released a technical report identifying the source. The connection is based on several pieces of evidence that continue to point in the same direction.
One of the strongest clues is the way some licenses were stored. Several Nexus records contain six separate images of the same driver’s license. There is a normal image of the front and back, an ultraviolet image of the front and back, and an infrared image of the front and back.
IDScan documents a six-image authentication process that uses those same views. Its document authentication technology examines both sides of an ID under visible, ultraviolet, and infrared light to check security markings, document templates, barcodes, printed information, UV features, infrared features, and other characteristics used to determine whether the ID is authentic.
The six-image format does not prove how the data was stolen. It does, however, closely match the format used by IDScan’s authentication technology. There is currently no confirmed CVE, exposed storage bucket, stolen API key, compromised employee account, ransomware infection, or other public explanation for how Nexus obtained the records.
The timestamps provide another connection. Several people whose licenses were found in Nexus were able to match the date on the images to a recent car rental. Another record matched a visit to a cannabis dispensary that had publicly partnered with IDScan for ID verification. In some cases, the license appears to have been scanned during the same trip or transaction reflected in the Nexus timestamp.
IDScan is not a small ID scanner company serving a handful of stores. Its technology is used across car rental, hospitality, cannabis, banking, gaming, retail, nightlife, logistics, visitor management, and physical security. The company says its systems are used at more than 20,000 locations and process millions of identity verifications.
Its software supports driver’s licenses, passports, passport cards, permanent resident cards, employment authorization documents, Canadian health and service cards, medical marijuana cards, transportation worker identification credentials, military IDs, and other government documents.
That helps explain how one identity verification provider could end up handling information belonging to people who have never heard of the company. Someone may hand a license to a rental employee, hotel clerk, dispensary worker, security guard, or cashier without knowing which company actually processes the scan behind the scenes.
IDScan also offers products that can keep more than a simple yes or no verification result. Its VeriScan platform can create visitor profiles from scanned IDs. Depending on the customer and configuration, those profiles can contain names, dates of birth, addresses, phone numbers, email addresses, ID information, photographs, scan history, visit history, comments, tags, and other information connected to the person.
There is no evidence that all of that information was taken. The Nexus records confirmed so far are centered around identity documents, document images, and timestamps. Investigators still need to determine whether the attackers only reached stored ID images or had access to larger visitor profiles and customer records.
IDScan’s own documentation also shows that some of its products can retain scanned identity information for long periods. VeriScan can be configured to collect and store identity records in the cloud, while other IDScan products use different retention periods. Some can delete submitted information quickly, while others support much longer retention.
That distinction matters because nobody has publicly identified the system that was breached. If Nexus reached a shared IDScan repository, records from many unrelated businesses could have been exposed through one compromised system. If the data came from individual customer environments, the scope would be very different.
Nexus claimed that it had been collecting new information for more than a year. That statement came from the people operating the criminal service and has not been confirmed by forensic investigators. What is confirmed is that the number of driver’s license records available through Nexus continued to increase while the service was being examined.
The driver’s license count increased by almost 400,000 records in about 24 hours. Other recently scanned licenses reportedly appeared in Nexus close to the time they had been used during real-world transactions. That makes this look different from a database stolen years ago and dumped online once. It raises the possibility that whoever operated Nexus still had access to a source that was receiving new ID scans.
Nexus disappeared from the dark web shortly after the breach became public. Its login page was replaced with a message saying the service was no longer available. There is no evidence that the people behind Nexus deleted the database, surrendered it to law enforcement, or lost access to the records.
Taking the website offline does not make the stolen data disappear. A database can be copied, sold privately, broken into smaller collections, shared with other criminal groups, or relaunched through another service. Driver’s license data is particularly difficult to protect once it has been copied because most of the information on the document cannot simply be changed.
The photograph is one of the biggest problems. A driver’s license connects a person’s face to their legal name and other personal information. Criminals can use that information while trying to impersonate the victim, open an account, recover an existing account, convince a support employee that they are the account owner, or provide identity documents during a fraudulent transaction.
Driver’s license images are already used as part of identity verification at banks, payment services, cryptocurrency companies, mobile carriers, online marketplaces, rental companies, and other businesses. Many of those services ask customers to upload a photograph of the front and back of their license.
Having a real license image does not automatically defeat a good identity verification system. Better systems can require a live selfie, liveness detection, facial matching, device checks, authoritative database verification, or additional identity information before approving someone. The problem is that criminals now appear to have genuine source material that can be used against systems with weaker verification or combined with other stolen information.
The ultraviolet and infrared images make some of the Nexus records even more unusual. Those images contain information used by specialized ID authentication equipment to inspect a real document. There is no public evidence that criminals have already used the Nexus records to bypass a bank or government authentication system, but the additional scans give them much more information than a photograph taken with a phone.
The consequences can also be very different depending on whose license is exposed. A stolen license belonging to a politician, law enforcement officer, military member, judge, executive, investor, celebrity, musician, YouTuber, streamer, adult entertainer, or other public figure can expose information that creates a physical security or privacy problem in addition to financial fraud.
Government-issued identification belonging to senior U.S. officials has reportedly appeared in Nexus. A driver’s license can connect a public identity to a residential address, date of birth, signature, physical description, and current photograph. That information can be useful for doxxing, impersonation, stalking, phishing, social engineering, or attempts to locate someone who does not want their location publicly known.
The same problem applies to people dealing with stalking, domestic violence, harassment, or other threats. Someone may spend years keeping a residential address private only to have a copy of a government document containing that address sold to strangers online.
Records identified as Common Access Cards could create another issue if the CAC designation is accurate. A picture or scan of a CAC would not copy the cryptographic credentials stored on the physical smart card and would not provide automatic access to Department of Defense systems. It could still give someone useful information for impersonation, phishing, social engineering, or attempts to appear legitimate when dealing with government or military personnel.
IDScan technology is also used for physical access control. The company has published a case study describing VeriScan as the primary visitor identification system used at the U.S. Coast Guard Academy. There is no evidence that Coast Guard Academy visitor records were exposed. The deployment simply shows that IDScan is used in environments where identity verification can have security consequences beyond checking someone’s age or completing a rental transaction.
IDScan also connects with software used by banks, hotels, cannabis businesses, casinos, equipment rental companies, and security operations. Those companies should not automatically be described as victims. Using an IDScan product does not prove that a company’s records were present in Nexus.
Caesars Entertainment has already provided an example of why that distinction matters. Caesars said it stopped using VeriScan in February 2025, had no active VeriScan accounts when the incident became public, and did not authorize IDScan to retain data from its accounts. IDScan had previously displayed Caesars among companies associated with its services. There is currently no evidence that Caesars customer data was included in Nexus.
The FBI’s New Orleans field office is investigating the breach. The bureau has confirmed that it is looking into the incident but has not publicly identified the source of the records or explained how they were obtained.
IDScan.net has also told customers that it is investigating whether unauthorized access occurred. The company has reportedly secured potentially affected systems, preserved logs, contacted law enforcement, involved outside counsel, and brought in forensic specialists. IDScan has not publicly confirmed that 153 million people were affected.
Lawsuits began almost immediately after the incident became public. Four civil cases were filed against IDScan.net in federal court in Louisiana. They include Bunch v. IDScan.net, Greenbaum v. IDScan.net, Sealy v. IDScan.net, and Rioux v. IDScan.net. Secondary reporting describes the cases as proposed class actions involving residents of several states, including people who say their IDs were processed during car rentals.
The legal questions will depend heavily on what the forensic investigation finds. Investigators still need to determine when the unauthorized access began, what systems were compromised, what information was taken, when IDScan learned about it, and when customers and affected individuals were notified.
Louisiana law specifically covers driver’s license information under its breach notification requirements. Businesses that maintain covered personal information are also expected to use security procedures appropriate for the type of information they hold. If people across the United States and Canada were affected, IDScan and its customers could face additional notification requirements in other jurisdictions.
The Federal Trade Commission may also take an interest if investigators find that poor security or unnecessary data retention contributed to the breach. The FTC has previously taken action against companies after data breaches involving allegations of weak security, excessive retention, and failure to delete personal information that was no longer needed.
More than one million Canadian driver’s license records were reportedly searchable through Nexus. That could also bring Canadian privacy regulators into the response if organizations covered by Canadian privacy law determine that personal information was exposed and created a serious risk of harm.
Businesses that scan IDs should take a close look at what they actually keep. Checking whether someone is 21 years old does not necessarily require storing a permanent high-resolution copy of their driver’s license. The same applies to many hotels, rental companies, venues, and other businesses that only need to verify identity during a transaction.
Companies using IDScan products should determine where ID images are stored, how long they are kept, who can access them, and whether copies are sent to other systems. Administrative accounts, API credentials, integration permissions, export history, and access logs should also be reviewed while the investigation continues.
- Identify every IDScan product, scanner, and integration currently in use.
- Determine whether driver’s license images are stored locally, in IDScan’s cloud, or in another connected system.
- Review retention settings and remove records that no longer have a legitimate business or legal reason to be stored.
- Review administrator accounts, API keys, service accounts, and integration credentials.
- Preserve scan histories, authentication logs, exports, and other records that may be needed during the investigation.
- Request written confirmation from IDScan about whether company records were affected.
- Review contracts and data processing agreements for breach notification and retention requirements.
People who believe their driver’s license may have been exposed should assume that information copied from the document could remain useful to criminals even if Nexus never comes back online. Replacing a license may change the license number in some states, but it does not change a person’s name, face, date of birth, signature, or information that has already been copied from an older document.
A credit freeze is one of the most effective ways to make it harder for someone to open a new credit account using stolen identity information. Consumers can freeze their credit separately with Equifax, Experian, and TransUnion at no cost and temporarily lift the freeze when they need to apply for legitimate credit.
Existing bank and credit card accounts should also be monitored. Calls, emails, text messages, or account recovery requests should not be trusted simply because the person contacting you knows your address, date of birth, license information, or other personal details. Someone with a copy of your driver’s license may know enough to make a fraudulent request sound legitimate.
- Freeze credit reports with Equifax, Experian, and TransUnion.
- Review credit reports for accounts or inquiries you do not recognize.
- Enable multifactor authentication on email, financial, mobile carrier, and other important accounts.
- Replace reused passwords and use a different password for each important account.
- Be suspicious of support calls or account recovery requests that use accurate personal information.
- Contact your state motor vehicle agency if there is evidence that someone is fraudulently using your license.
- Report confirmed identity theft through the appropriate federal identity theft reporting service.
- Scan devices involved in suspicious downloads, phishing, or account activity with a trusted security product such as Malwarebytes.
The biggest unanswered question is still how Nexus got the records. The FBI has not identified the initial access point, IDScan has not published a forensic report, and the 153 million figure has not been confirmed as the number of individual people affected. What is already clear is that real driver’s license records were being sold, some included full authentication scans, and the database contained documents belonging to people in both the United States and Canada.
For verified coverage of major data breaches and the latest cybersecurity threats, visit Botcrawl for ongoing updates and expert analysis.