ID Verification Firm Confirms 150M License Breach
IDScan.net confirmed hackers stole over 150 million driver's licenses from its cloud, after the data appeared on a dark web marketplace.
Every time someone hands over a driver's license to get into a bar, rent a car, or buy from a cannabis dispensary, that scan usually passes through a company most people have never heard of. On September 10, 2026, one of the largest of those companies, Louisiana-based IDScan.net, confirmed what independent researchers had been reporting for over a week: hackers had stolen more than 150 million driver's licenses, along with other government-issued identification documents, directly from its cloud systems.
The confirmation closed a gap that had been open since early September, when the company's own language shifted from cautious hedging to outright admission. That single change in wording, from information that may have been accessed to a confirmed theft, matters enormously to the businesses whose customers' identity documents pass through IDScan's systems every day.
Nine Days From "May Have" to "Confirmed"
The company's public timeline shows how slowly this admission developed. IDScan first acknowledged internally, on or around September 1, 2026, that certain information may have been exposed. It took nine more days, and mounting outside pressure, before the company's website notice confirmed outright that an unauthorized third party had accessed and copied certain customer information stored within accounts on the IDScan.net cloud. In the interim, the FBI's New Orleans field office opened a formal investigation, and multiple lawsuits were already filed against the company before its own confirmation even arrived.
How the Breach Was Actually Discovered
IDScan didn't disclose this breach on its own initiative. Independent security journalist Brian Krebs broke the story on September 1, after discovering a new dark web marketplace called Nexus offering searchable access to more than 153 million driver's licenses and passports belonging to people in the United States and Canada. According to a post advertising the site on a Russian cybercrime forum, Nexus was adding roughly half a million new documents daily, a detail suggesting whoever ran the marketplace had ongoing, near-real-time access to the identity verification company's systems, not a single historical data dump.
Krebs confirmed the data was genuine by finding his own driver's license among the searchable records. The Nexus marketplace has since been taken offline, though the underlying database may still exist elsewhere, accessible to whoever downloaded copies before the shutdown.
What Was Actually Stolen, and From Whom
The scope of the stolen data goes well beyond driver's licenses alone. According to reporting from Malwarebytes, the compromised collection included more than 153 million driver's license scans, 10 million additional ID cards, 3 million travel documents including passports, and 579,000 medical cards, some tied to marijuana dispensary verification specifically. The stolen information includes full names and government identification numbers, and in many cases, the actual photos attached to those documents.
IDScan's business model is exactly what made a breach at this scale possible. The company provides identity verification services to a wide range of corporate customers, including entertainment venues, cannabis dispensaries, and larger operations like car rental agencies, shipping companies, and retailers who need to verify a customer's government-issued ID at the point of a real-world transaction. Every one of those verification checks routes personal identity data through IDScan's systems, meaning a single breach at the vendor level exposes people who may never have directly interacted with IDScan themselves, only with the businesses that use its service in the background.
The Detail That Made This Impossible to Ignore
One specific fact pushed this breach from a technical security story into genuinely mainstream news: among the records found in the Nexus database was an ID belonging to US Secretary of Defense Pete Hegseth. That detail underscores a point security researchers have been making about this breach specifically, that identity verification data touches people across every level of society, regardless of their profession or security clearance, the moment they hand over an ID at a rental counter or a dispensary.
Why the Real Number Is Still Unknown
There's an important accuracy caveat sitting underneath the widely reported 150 million figure. That number originated entirely from the Nexus dark web listing itself, first reported by Krebs, not from IDScan's own internal audit or from law enforcement's independent count. As of its September 10 confirmation, IDScan had not published its own official total for how many records were actually affected. That gap between a criminal marketplace's marketing claim and a verified, company-confirmed figure is a meaningful distinction, even though it doesn't change the fact that a breach of some real scale genuinely occurred and has been formally acknowledged.
IDScan has said it's cooperating with federal law enforcement and offering affected individuals credit monitoring and identity protection services, standard remediation steps for a breach of this nature, though notably these protections address downstream financial fraud risk rather than the underlying exposure of the identity documents themselves, which can't be recalled once copied and distributed.
What This Breach Says About Identity Verification Itself
The IDScan incident lands amid a broader pattern of serious cybersecurity failures this year involving systems that were specifically built to be trustworthy, from AI agents finding unexpected paths around their own containment, as documented in Anthropic's own Claude Cowork sandbox vulnerability disclosure earlier this summer, to fully autonomous ransomware campaigns like JadePuffer, which exploited an already-patched vulnerability nobody had bothered to fix. The IDScan breach fits a related, if distinct, category: a piece of infrastructure businesses and consumers trusted implicitly, precisely because verifying identity is supposed to prevent fraud, becoming the exact vulnerability that enables fraud at scale instead.
Unlike a stolen password, a compromised driver's license number or passport scan can't simply be reset. That's the uncomfortable structural reality this breach exposes: as more everyday transactions, from renting a car to buying age-restricted products, increasingly route through third-party digital identity verification systems, the security of those third parties becomes a single point of failure capable of exposing sensitive, largely unchangeable personal data at a scale few individual consumers ever chose to accept when they simply handed their ID across a counter.
Written by
Mr. Aayush Bhatt
Software Engineer with in depth understanding of buliding softwares and Tech.




