IDScan Faces Four Lawsuits Over Alleged Driver’s License Breach

IDScan faces four proposed class actions after a dark-web service claimed to hold more than 153 million U.S. and Canadian driver’s license records.

Sep 7, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

At least four proposed class-action lawsuits have been filed against New Orleans-based IDScan.net in the U.S. District Court for the Eastern District of Louisiana.

The plaintiffs, from California, Florida, Georgia and Louisiana, allege that businesses they patronized used IDScan’s identity-verification technology and failed to protect their personal information.

The lawsuits followed a Sept. 1 report by cybersecurity journalist Brian Krebs about a dark-web service called Nexus. Its operators claimed to possess more than 153 million U.S. and Canadian driver’s license records, along with more than 10 million identification cards, more than 3 million travel documents or international IDs and at least 579,000 medical cards. Neither IDScan nor a government agency has verified those totals.

Krebs found his own license and searched for records belonging to more than a dozen consenting friends and relatives. Timestamps and transaction histories from nine matches pointed to businesses associated with IDScan, although the company has not confirmed that its systems were the source.

IDScan provides tools that businesses use to scan, authenticate and extract information from government-issued identification documents. Its technology is used in sectors including car rentals, retail, financial services, hospitality and cannabis.

The incident highlights the risks created when businesses send identity documents to third-party verification providers: consumers may not know who processes or retains their information, while one vendor incident could expose records collected across numerous unrelated businesses.

FBI Investigates as Scope Remains Unclear

The FBI’s New Orleans field office opened an investigation into an apparent breach involving IDScan, according to Krebs, who said bureau officials confirmed the inquiry. The FBI has not publicly disclosed its findings.

IDScan has not publicly confirmed that its systems were breached or established how many people may have been affected. Law firm Markovits, Stock & DeMarco said public reporting indicated that IDScan began notifying at least some business customers around Sept. 1. IDScan has not publicly detailed the scope or recipients of any notices.

The Nexus marketplace has since disappeared, but that does not necessarily mean the data itself is gone. Cybercriminals could retain copies or distribute the information privately. Some Nexus records reportedly included front-and-back scans in conventional, infrared and ultraviolet formats, although Krebs noted that not every record contained images. That matters because such files can contain far more identifying information than a simple license number.

What Consumers Can Do While the Investigation Continues

Advertisement

Because no official lookup tool or verified breach directory exists, consumers cannot yet confirm whether Nexus held their records. However, people who have had an identification document scanned can take several precautions:

  • Audit past transactions: Identify rental car check-ins, parcel pickups, retail age checks, or dispensary visits where your physical card was scanned or uploaded alongside a selfie.
  • Contact the merchant directly: Inquire in writing whether the business relied on IDScan.net, VeriScan, or DIVE, and ask if full document images or parsed fields were retained.
  • Guard sensitive details: Do not send unredacted identity scans or Social Security numbers over regular email when inquiring about vendor practices.
  • Monitor and document suspicious activity: Review credit reports and financial accounts, and keep records of unauthorized inquiries, accounts or messages. This documentation may help when disputing fraud or filing an identity-theft report.
  • Freeze your credit: Consider placing free credit freezes with Equifax, Experian and TransUnion to help prevent criminals from opening new accounts in your name.

Until IDScan or investigators release a verified victim count and notification process, consumers may have no definitive way to determine whether their documents were involved. For businesses, the incident is a reminder that identity-security blind spots can extend to third-party providers. Organizations should examine what identity-verification vendors retain, how long they retain it and what happens when sensitive data leaves their direct control.

Read more: Learn how the FBI investigation began after a dark-web service advertised more than 153 million driver’s license records and what researchers uncovered about their possible source.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.