Introduction
IDScan.net, a Louisiana-based identity verification vendor, has confirmed that hackers stole driver's licenses and other government-issued identification data from its cloud environment, following weeks of reporting that pointed to one of the largest identity document breaches on record. The company's confirmation, posted as a website notice and reported by TechCrunch on September 10, 2026, comes more than a week after independent security journalist Brian Krebs first reported the existence of a dark web marketplace selling access to more than 150 million driver's licenses.
How the Breach Came to Light
The breach first surfaced publicly on September 1, 2026, when Krebs reported that a new identity theft service called Nexus had launched on the dark web, claiming to let users search through more than 150 million driver's licenses and passports belonging to people in the United States and Canada. A post advertising the site on a Russian cybercrime forum claimed the database was being updated with roughly half a million new documents daily, suggesting the attackers had near real-time access to the identity verification company's systems for an extended period before discovery.
Key Facts
- IDScan.net confirmed the breach in a website notice reported on September 10, 2026.
- The Nexus dark web marketplace claimed over 150 million driver's licenses were searchable.
- Separately reported figures put the total at more than 153 million driver's licenses, 10 million ID cards, 3 million travel documents and 579,000 medical cards.
- The FBI's New Orleans field office has opened an investigation into the breach.
- Krebs confirmed his own driver's license appeared in the searchable database, verifying the data's authenticity.
Whose Data Was Exposed
IDScan.net's corporate customers span industries from entertainment venues to cannabis dispensaries, using the company's technology to verify customers' identity documents, including checking age for regulated purchases. Legal filings tracking the incident have named companies including Hertz, FedEx and Target among IDScan.net's client base, businesses that rely on identity verification for rental transactions, shipping pickups and retail purposes respectively. Notably, US Secretary of Defense Pete Hegseth was reportedly among the individuals whose identification photos appeared in the leaked database.
Table: What Was Reportedly Stolen
| Document Type | Approximate Count |
|---|---|
| Driver's Licenses | 153 million-plus |
| ID Cards | 10 million |
| Travel Documents (Passports) | 3 million |
| Medical Cards (Including Dispensary Cards) | 579,000 |
What Made This Data Especially Sensitive
Unlike many data breaches that expose only names or account numbers, this incident reportedly involved more than basic photos of identification documents, including infrared and ultraviolet scans of the type used specifically to verify a document's authenticity. Security researchers have noted the uncomfortable irony that the very features designed to prove an ID is genuine, detailed scans capturing security features invisible to the naked eye, become powerful tools for identity fraud once stolen, since they can potentially be used to create convincing forged documents.
Company Response
IDScan.net's official notice confirmed that an unauthorized third party accessed and copied certain customer information stored within accounts on its cloud environment, including full names and driver's license or other government-issued identification numbers. The company has not published its own total count of affected records, meaning the widely cited 150 million-plus figure originates from the Nexus dark web listing itself rather than an official company disclosure, and has not been independently verified as a confirmed count by law enforcement.
Expert Insight
Cybersecurity researchers reviewing the incident emphasise that identity verification services occupy an unusually sensitive position in the data ecosystem, since they exist specifically to aggregate and validate the exact documents people rely on to prove who they are. A breach at this scale, they note, carries risks well beyond typical account-based breaches, since stolen government ID data cannot simply be reset the way a compromised password can, leaving affected individuals exposed to identity fraud risks for years rather than until their next password change.
Key Takeaways
- IDScan.net has confirmed a breach after a dark web marketplace claimed over 150 million driver's licenses were stolen.
- Additional stolen documents reportedly include ID cards, passports and medical cards.
- The FBI has opened an investigation into the breach.
- IDScan.net's corporate clients reportedly include Hertz, FedEx and Target.
- The stolen data reportedly included detailed security scans, not just basic photos, raising forgery risks.
FAQ
How many driver's licenses were affected?
A dark web marketplace called Nexus claimed to hold more than 150 million driver's licenses, with related reporting putting the figure at over 153 million; IDScan.net has not published its own official count.
Who is investigating the breach?
The FBI's New Orleans field office has opened an investigation into the incident.
What companies used IDScan.net's services?
Reported clients include Hertz, FedEx and Target, among other companies relying on identity verification for rentals, shipping and retail transactions.
Conclusion
The IDScan.net breach underscores a growing risk in the identity verification industry itself: the very companies built to confirm people's identities have become high-value targets whose compromise can expose far more sensitive, harder-to-replace data than a typical breach. With the FBI investigation ongoing and the company yet to disclose a confirmed total, the full scope of affected individuals may not be clear for some time.