IDScan.net Data Breach Exposes Drivers Licenses and ID Scans

Published: 1 September 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

A dark web service called Nexus began selling scans of more than 153 million drivers licenses, apparently sourced from a breach at identity verification company IDScan.net, which serves businesses like Hertz, Target, and Caesars Entertainment. The FBI has opened a formal investigation. Affected individuals should place a credit freeze or fraud alert immediately and monitor their credit reports for suspicious activity.

CompanyIDScan.net
IndustryOther Commercial
Data Types ExposedDrivers License Images, State Identification Cards, Travel Documents, Medical Marijuana Dispensary Cards, Infrared and Ultraviolet ID Scans, Photo Identification, Commercial Drivers License Records, Common Access Card Records
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Data Exfiltration
Regulators NotifiedNot Publicly Disclosed

What Happened in the IDScan.net Data Breach?

A dark web marketplace called Nexus began selling scans of more than 153 million drivers licenses this week. The listings also include over 10 million identification cards, three million travel documents, and nearly 579,000 medical cards. Most of the records belong to people in the United States, with a smaller share tied to Canadian residents.

Evidence points to IDScan.net, a Louisiana-based identity verification company, as the likely source. IDScan.net provides ID scanning services for businesses like Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. The company also verifies IDs at more than 1,000 marijuana dispensaries across 19 states. As a result, the exposure may reach far beyond any single retailer or industry.

The seller behind Nexus claims to have pulled data from an ongoing breach for over a year. This means new scans may still be added to the marketplace regularly. In fact, researchers observed the number of listed drivers license records grow by nearly 400,000 within just 24 hours. This suggests the data theft has not stopped.

Researchers confirmed the connection by matching timestamps on leaked license images to actual travel and car rental dates. Several volunteers found their own licenses in the Nexus database. Notably, the timestamps aligned closely with moments when they had shown identification to rental car companies or dispensaries, not airports.

Because of this, investigators believe the breach traces to identity verification systems used at the point of service, not TSA checkpoints. IDScan.net told researchers it is investigating the matter but has not issued a full public statement. Meanwhile, the FBI’s New Orleans field office has opened a formal investigation into the apparent breach.

Who was affected?

The IDScan.net data breach may affect a massive number of consumers across North America. The exposed records cover people in the United States and Canada whose drivers licenses, ID cards, or other documents were scanned through IDScan.net’s verification systems. This includes customers of companies like Hertz, Target, and Caesars Entertainment, among others.

The exact number of individuals affected by this breach has not been publicly disclosed. However, the scale suggested by the Nexus marketplace, more than 153 million license records, indicates the population impacted could be extremely large. This likely includes ordinary consumers, as well as several high-ranking government officials whose licenses reportedly turned up in the same database.

Because IDScan.net serves industries ranging from car rental to retail to legal cannabis sales, the affected population spans many walks of life. Anyone who has shown a physical ID for age verification, rental agreements, or account setup at a business using IDScan.net could potentially be included. This breadth makes it difficult for any one person to assume they are safe.

What Information Was Potentially Exposed?

The data available through the Nexus marketplace goes well beyond basic contact details. It includes detailed scans of government-issued identification, along with the personal information printed on those documents. This is sensitive material that can be used to impersonate someone convincingly.

  • Drivers license images (front and back)
  • State identification card scans
  • Travel documents and international IDs
  • Medical marijuana dispensary cards
  • Infrared and ultraviolet scan images of IDs
  • Photos associated with identity documents
  • Commercial drivers license (CDL) records
  • Common Access Card (CAC) related records

This type of exposure creates serious identity theft risk. A clear scan of a drivers license, including the photo, often contains enough detail for a criminal to open new credit accounts. In addition, some victims may face fraudulent loan applications or unauthorized account changes using their stolen identity documents.

Beyond financial fraud, this breach raises unusual safety concerns. Security researchers noted that clear license photos could help someone locate individuals who do not want to be found. This includes domestic violence survivors and people in witness protection programs. As a result, the risk here extends past typical financial harm into personal safety.

What is the company doing?

IDScan.net has acknowledged it is looking into the reported breach. However, the company has not yet issued a full public statement or answered detailed questions about how the exposure occurred. A company representative said updates from outside researchers have been helpful to the internal investigation.

Because the FBI has now opened a formal inquiry through its New Orleans field office, the investigation is no longer limited to IDScan.net’s internal review. This federal involvement suggests officials view the exposure as significant. Consumers should expect updates as both the company and law enforcement continue examining how the data was taken and how far it has spread.

What Should Affected Individuals Do?

Check for Signs Your License Was Exposed

If you have rented a car, visited a dispensary, or completed age verification at a business in recent years, your license could be part of this breach. Businesses tied to IDScan.net include major national brands. Therefore, even routine transactions could have put your ID scan at risk.

Because the Nexus service reportedly allows previews before purchase, some victims have been able to confirm their own exposure. However, most people will not have this option. Instead, affected individuals should assume exposure is possible and take protective steps right away, rather than waiting for direct confirmation.

Place a Fraud Alert or Credit Freeze

Given that drivers license images can be used to open new credit lines, a credit freeze is a strong first step. This prevents new creditors from accessing your credit file without your explicit approval. You can request a freeze for free with each of the three major credit bureaus.

Alternatively, a fraud alert requires lenders to take extra steps before approving credit in your name. This option is faster to set up and still offers meaningful protection. Either way, acting quickly reduces the window criminals have to misuse your stolen identity documents.

Monitor Your Credit Reports Closely

Regularly reviewing your credit reports helps you catch fraud early. Look for unfamiliar accounts, hard inquiries you don’t recognize, or sudden changes to your credit limit. You can request free reports from each major bureau through the official government-authorized site.

In addition, consider setting up transaction alerts on your bank and credit card accounts. This way, you receive immediate notice of unusual activity. Because stolen license images can support convincing fraud, early detection is one of your best defenses.

Stay Alert for Phishing and Impersonation Attempts

Criminals often pair stolen identity documents with phishing emails or phone calls designed to extract even more personal information. Be cautious of unexpected messages asking you to verify your identity or confirm account details. When in doubt, contact the company directly using a number from its official website.

Furthermore, be wary of any unfamiliar accounts, loan offers, or government benefit notices that arrive unexpectedly. These can be early warning signs of identity misuse. If something feels off, it is worth investigating immediately rather than dismissing it.

Consider Consulting a Data Breach Attorney

Because this breach may involve a company’s failure to secure highly sensitive identity documents, affected individuals may have legal options worth exploring. A data breach attorney can help evaluate whether you qualify for compensation. Many offer free consultations to review your specific situation.

Since the scope of this breach is still unfolding, staying informed about developments is important. As more details emerge about how IDScan.net secured its systems, legal options for affected consumers may become clearer. Consulting an attorney early can help you understand your rights without any upfront cost.



Related Data Breaches

View the full list of tracked data breaches →