IDScan, a New Orleans-based identity verification technology company that provides hardware and software for businesses to scan and authenticate government-issued IDs, is facing mounting legal pressure after an alleged data breach exposed personal records on a massive scale.
The incident came to light on September 1 when security journalist Brian Krebs reported that a dark-web identity-theft service called "Nexus" was advertising access to more than 153 million U.S. and Canadian driver's license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified samples by searching the database for his own records and those of consenting individuals, and traced the leak back to IDScan.
Multiple law firms, including Markovits, Stock & DeMarco and Hall Attorneys, have launched investigations into potential class-action litigation. Lawsuits have been filed in Louisiana, where IDScan is based, alleging that the company failed to protect information collected from clients such as global car rental company Hertz. According to Markovits, Stock & DeMarco, IDScan began notifying some business customers around September 1.
The company has not published any statements about the allegations and did not respond to BleepingComputer's requests for comment. Reuters independently confirmed that the FBI's New Orleans office is investigating the incident, though the agency has not issued an official statement.
The illegal service Nexus is no longer online, but cybercriminals still have access to the database. It remains unclear whether IDScan's systems were compromised or how many individuals are affected.
Given the potential scale, additional lawsuits — including class actions — could be filed, and related cases may be consolidated into multidistrict litigation. State attorneys general and federal regulators could launch separate investigations or enforcement actions, as has happened with past large-scale data exposures such as the 23andMe breach and the Marriott data incidents.