Sep 11, 2026 · 7 min read
153M Driver's License Scans Stolen From IDScan
A Louisiana company you have never heard of reads your license when you rent a car or check into a hotel. On August 31, a dark web marketplace put 153 million of those scans on sale. By September 4, IDScan.net had confirmed a breach.
Most coverage led with the number. The detail that matters more sits in the file formats: the listings included infrared and ultraviolet captures, the layers a scanner reads to decide whether a license is genuine. A stolen password is a string you rotate in 30 seconds. Your license number does not change until the state reissues it, which for most drivers is four to eight years away. Brian Krebs first reported the marketplace on September 1.
Key Takeaways
- IDScan.net said on September 4, 2026 that "an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud."
- Nexus, a dark web marketplace advertised on the Russian language crime forum Exploit, listed 153 million driver's license scans, 10 million identification cards, more than 3 million travel documents and over 579,000 medical cards.
- The exposed fields include full names and government issued ID numbers belonging to U.S. and Canadian citizens whose IDs were scanned through IDScan's platform.
- Listings carried front, back, infrared and ultraviolet images with date and time metadata, the formats that defeat document authenticity checks rather than merely reveal a name.
- The FBI's New Orleans field office opened an inquiry, Nexus went offline on September 2, and IDScan is offering free credit monitoring without saying how many business customers were affected.
What Exactly Did IDScan Lose?
IDScan lost scanned images of government issued identity documents, plus the full names and ID numbers attached to them, from customer accounts in its cloud. The company authenticates IDs for cannabis retailers, firearms dealers, banks and hospitality operators. The Record reported the confirmation and the FBI inquiry, alongside the detail that IDScan told search engines not to index its own notice page.
Scale explains how one vendor held this much: IDScan processes more than 21 million verifications a month across upwards of 20,000 locations. Timestamps on the leaked records line up with ordinary errands, from rental counters to dispensary doors to hotel check ins. BleepingComputer covered the confirmation and the missing customer count.
Why Are Infrared and UV Scans Worse Than a Photo?
Because a phone photo proves nothing, while an infrared and ultraviolet capture is what a verification system treats as proof the document is physically real. Licenses embed patterns visible only outside the range of normal light, and scanners read those layers specifically to catch forgeries. A dump containing them hands an attacker the answer key, not just the data on the front.
Researcher Corrado Paolini framed the limit of that defence bluntly in Krebs's reporting: "A photo can be copied and reused forever. A person standing there, physically, in the moment, can't be." NIST Special Publication 800-63A sets out the evidence requirements for identity proofing, and a stolen strong document paired with a weak liveness step collapses several assurance levels at once.
Is 153 Million Scans the Same as 153 Million People?
No, and almost every write up skipped past that. The listing counts scan events, not individuals. Someone who bought at a dispensary in March, rented a car in June and checked into a hotel in August appears three times. Krebs noted the database grew by roughly 400,000 license records in a single day, the signature of a live transaction feed rather than a static customer table.
That cuts both ways. The victim count is below 153 million, though not reassuringly so against the 237.7 million licensed drivers the Federal Highway Administration counted in 2023. The harm per victim is larger, because duplicate records are a movement history: which cities, on which dates, and what kind of business you walked into. Credit monitoring does nothing about that.
What Can Someone Do With Your License Number?
They can open accounts as you at any service whose onboarding accepts a document image, which is most of them. TransUnion's analysis of the first half of 2025 found 8.3% of digital account creation attempts were suspected fraud, the highest rate of any stage in the customer lifecycle. The automated side is industrialised too: Group-IB recorded 8,065 attempts between January and August 2025 to bypass one bank's liveness checks during loan applications, using generated faces injected through virtual cameras. Each attempt gets cheaper when the attacker also holds a real, matching document.
Scale it against the precedents. Discord's vendor breach exposed roughly 70,000 government ID photos, disclosed in October 2025, and the UK visa portal leaked 100,000 passports and selfies. IDScan's set is about 2,000 times larger than Discord's, with the infrared layer attached.
Identity document exposure is not confined to licences either. An Advance Passenger Information database left 220 million traveler and crew records reachable online, passport numbers and all.
What This Means for Your Inbox
IDScan's exposure did not include email addresses, and that is worth stating plainly. What follows is a pairing problem: an attacker holds your real name and license number, then matches an email address to it from any commodity dump already circulating. The result is a message quoting a number only a legitimate institution should know. The UK's National Cyber Security Centre publishes guidance on the phishing wave that follows a breach for this reason.
Before the convincing lure arrives, senders want to know the address is alive. That is the mundane job a tracking pixel does in bulk mail: a harmless looking notification confirms who opened it, when, and from roughly where, and the list gets pruned to whoever responded. No evidence suggests the IDScan data was used this way. It is simply the sequencing that makes targeted follow up economical, and why a pattern like the fake cloud storage payment emails flooding inboxes keeps working.
So the rule for the next few months is narrow. Any email asking you to verify your identity or check whether you were affected is hostile by default.
What Security and Compliance Teams Should Take From This
The failure here is retention, not access control. A dispensary needs to know a customer is over 21 at the moment of sale. Nobody needs an infrared scan of that license sitting in a vendor cloud forever. Every scan kept after the decision is pure liability, the same lesson the ShinyHunters claim of 284 million McKesson patient records taught in a different sector.
Two questions belong in your next vendor review. Does the contract permit image retention at all, or only the pass or fail decision. And if the provider is breached, who notifies the individual, because state breach notification laws put that duty on the business that collected the data, not the processor that lost it. The FTC's data breach response guide also recommends telling customers in advance how you will contact them, so follow on phishing has less room to work.
What Should You Do Right Now?
- Freeze your credit at all three bureaus. It is free, it blocks new account opening, and the FTC's IdentityTheft.gov covers recovery if something already opened.
- Ask your DMV about a new license number. Several states reissue with a fresh number on proof of identity theft, the only step that actually invalidates the stolen record.
- Never verify through a link in an email. Navigate to the institution yourself, or call a number you looked up independently.
- Watch for account opening, not card fraud. The realistic abuse is a loan or a phone line in your name, which never shows up on a card statement.
Looking Ahead
Nexus went dark on September 2, two days after launching, which is the least meaningful fact in the story. The copies predate the storefront and will resurface under another name, so the FBI's New Orleans inquiry can change the market, not the data.
Track two things. Whether IDScan publishes a customer count and a retention schedule, since silence on both means nobody knows the scope yet. And whether a regulator treats scanner captured infrared imagery as biometric data rather than an ordinary document copy, which would move this under statutes with far sharper penalties.
The other route to the same data skips the vendor entirely. In September 2026 ShinyHunters pulled Florida driver records straight out of the state's own DAVID database, using credentials a police employee had stored on a personal device.