153 million driver's licenses for sale: IDScan faces lawsuits
A dark web service offered more than 153 million driver's license scans for sale, a database traced back to identity verification vendor IDScan. Several lawsuits have been filed, and the FBI is investigating.

On 1 September 2026, security journalist Brian Krebs reported that a dark web identity theft service called Nexus was offering access to more than 153 million American and Canadian driver’s license scans. Alongside them were 10 million identity cards, 3 million travel documents and 579,000 health insurance cards. Krebs says he verified the samples by searching the database for his own data, and for the data of people who had given their consent, then traced the trail back to the company IDScan. Three days later, on 4 September, BleepingComputer reported that several lawsuits had been filed against the firm.
The middleman nobody chose
IDScan sells identity verification hardware and software: reading official documents, authenticating them, extracting the information they contain. Its systems are used in the United States by car rental companies, retailers, gun stores, financial institutions, cannabis dispensaries and the hospitality sector.
That is what gives this case its particular weight. Nobody becomes an IDScan customer: you hand your license across a counter, and the data travels to a vendor whose name you never learn. The contract binds the company to its business clients; the people whose documents were scanned are party to nothing.
The complaints begin in Louisiana
The suits were filed in Louisiana, where IDScan is headquartered. They accuse the company of failing to protect information passed to it by its clients, among them the car rental firm Hertz. Several law firms, including Markovits, Stock & DeMarco and Hall Attorneys, have opened investigations with a view to a possible class action and are seeking plaintiffs. According to the first of those firms, IDScan began notifying some of its business clients around 1 September, and anyone whose document was scanned by a business using its equipment may be affected.
Given the potential scale of the matter, further suits could follow and the proceedings could be consolidated into multidistrict litigation. State attorneys general and federal regulators may also open investigations or actions of their own, as happened with data exposures of comparable size at 23andMe, Marriott and Equifax.
The FBI investigates, the company says nothing
The FBI’s New Orleans field office has opened an investigation. First reported by Brian Krebs, the information was independently confirmed by Reuters, then by the agency itself to BleepingComputer, which obtained no further comment because proceedings are ongoing. IDScan, for its part, has issued no statement on the allegations and did not respond to the outlet’s requests.
What remains undetermined
As of 4 September, it has been established neither that IDScan’s systems were in fact compromised, nor how many people are genuinely affected. The figure of 153 million comes from the listing published by the sellers, not from a count confirmed by the company or by investigators.
One point, however, is settled: the Nexus service is no longer reachable online, but the database itself remains in the hands of those who held it.
A compromised password takes seconds to change. A driver’s license scanned at a rental counter does not.
Sources (1)
- IDScan sued over alleged data breach affecting 153 million driversbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


