IDScan Breach Deep Dive: 150M+ Driver's Licenses Stolen
IDScan confirmed a cloud breach after Krebs reported a dark-web search site covering 150M+ US and Canadian licenses with photos. What was stolen, who uses the checker, and what to do next — with primary sources.
150 million licenses — including photos
Louisiana identity-verification vendor IDScan (idscan.net) has confirmed that hackers stole driver's licenses from its cloud. The disclosure follows reporting that a dark-web search service was offering scans covering more than 150 million US and Canadian licenses — with photos. If you ever showed a license at a venue, dispensary, or ticket gate that used this checker, your name, number, and photo may already be searchable.
This deep dive pulls together what TechCrunch confirmed, what Brian Krebs verified first, and what the company still will not say — with primary sources linked throughout.
What happened
On or around September 1, 2026, IDScan said it "received information" about a claimed hack. The same day, independent journalist Brian Krebs reported a dark-web service (Nexus) that let anyone search over 150 million US and Canadian driver's licenses, including photos. About a week later, IDScan posted a website notice acknowledging that an unauthorized party may have accessed or copied customer data from its cloud — its first public acknowledgement after initially saying it was only investigating.
- Vendor: IDScan / idscan.net (Louisiana)
- Vector described by the company: cloud account data access / copy
- Public confirmation: website notice reported by TechCrunch (Sep 10, 2026)
- Earlier reporting: KrebsOnSecurity — FBI probes service selling 153M+ licenses
What was stolen
According to IDScan's notice and subsequent coverage, affected data may include:
- Full names
- Driver's license numbers
- Other government-issued ID numbers (including passports)
- License photos tied to a cache covering 150M+ US & Canadian licenses
Krebs's reporting also described Nexus claiming millions of additional ID cards, travel documents, and medical cards alongside the license corpus. Treat those secondary counts as claims from the marketplace until independently confirmed by the company.
Krebs verified the dark-web search site against his own record. High-profile entries reported in coverage included Defense Secretary Pete Hegseth.
Who uses IDScan — and why that matters
IDScan is used by corporate customers verifying IDs at the door: entertainment venues, cannabis dispensaries, ticket gates, and other regulated check-ins. Krebs traced real-world encounters (including dispensary check-ins) back to the vendor. When a single ID-check SaaS sits in front of many brands, one cloud compromise can quietly aggregate identity data across industries.
Additional coverage from Biometric Update and CSO Online underscores the same pattern: document retention after verification is the risk, not just the scan moment itself.
What Krebs verified
KrebsOnSecurity reported that the Nexus service offered searchable scans and that the New Orleans FBI field office opened an inquiry into the source of the images. Krebs verified authenticity against his own license record and interviewed others whose licenses appeared in the cache. That verification — not a press release — is what forced the story into the open before IDScan's later notice.
Read the primary account: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
What they still will not say
IDScan notes it holds over 150 million license records, but has not stated how many people are affected. Its notice said "full access to the information required payment" — language that likely refers to a ransom or gated dump rather than a free public dump of the entire corpus. Forensic details (root cause, dwell time, whether the compromise was ongoing) remain thin in public statements.
- No clear headcount of affected individuals
- Investigation described as ongoing
- Limited technical disclosure so far
What to do next
Practical steps if you may have been scanned by an IDScan customer:
- Watch for identity-theft patterns: new credit inquiries, SIM-swap attempts, synthetic-ID fraud using your photo + license number.
- Consider a credit freeze / fraud alert with major bureaus if you are in the US or Canada.
- Treat unsolicited "your license was leaked — click here" messages as phishing; use official company notices and reputable reporting instead.
- If you operate venues or dispensaries: ask your ID vendor for retention policy, encryption at rest, access logging, and breach notification SLAs — and delete scans you do not legally need to keep.
Primary sources
- TechCrunch — IDScan confirms 150M+ licenses stolen
- KrebsOnSecurity — FBI probes service selling 153M+ licenses
- Biometric Update — IDScan confirms breach
- CSO Online — FBI investigates 153M license records
How BSH can help
At BSH Technologies we help teams harden identity and document workflows on cloud — least-privilege access, retention that matches the law (not convenience), encryption, monitoring, and breach-ready logging. If your product verifies IDs or stores scans, our Thrissur engineers can review the threat model before the next vendor breach becomes your incident.
Frequently asked questions
Was my driver's license stolen?
IDScan has not published a full list of affected individuals. If a venue, dispensary, or ticket gate that uses IDScan scanned your license, treat exposure as possible and monitor for identity fraud.
Where can I read the original reporting?
Start with TechCrunch's confirmation and Brian Krebs's KrebsOnSecurity investigation linked in the Primary sources section of this article.
What should businesses that use ID checkers do?
Ask vendors for retention limits, encryption, access logs, and breach SLAs. Delete scans you are not required to keep, and segment identity data from general cloud workloads.
Related Topics
From the blog
View all posts
How to Build an AI Agent for Free in 2026
You can build a working AI agent for free in 2026 using n8n, open-source frameworks, and a free LLM tier. Here is the exact stack and the steps.

Best Free AI Agent Frameworks in 2026
The best free AI agent frameworks in 2026 are LangChain, CrewAI, Microsoft AutoGen, LangGraph, and n8n. Here is how to choose between them.