IDScan Hit With Lawsuits Over Breach Exposing 153 Million Driver's Licenses

FBI investigates as dark-web service Nexus offered scans of IDs from Hertz and other clients

edit
By LineZotpaper
Published
Read Time2 min
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million U.S. and Canadian driver's licenses, along with millions of other identification documents. The FBI has launched an investigation into the incident, which was first reported by security journalist Brian Krebs.

IDScan, a New Orleans-based identity verification technology company that provides hardware and software for businesses to scan and authenticate government-issued IDs, is facing mounting legal pressure after an alleged data breach exposed personal records on a massive scale.

The incident came to light on September 1 when security journalist Brian Krebs reported that a dark-web identity-theft service called "Nexus" was advertising access to more than 153 million U.S. and Canadian driver's license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified samples by searching the database for his own records and those of consenting individuals, and traced the leak back to IDScan.

Multiple law firms, including Markovits, Stock & DeMarco and Hall Attorneys, have launched investigations into potential class-action litigation. Lawsuits have been filed in Louisiana, where IDScan is based, alleging that the company failed to protect information collected from clients such as global car rental company Hertz. According to Markovits, Stock & DeMarco, IDScan began notifying some business customers around September 1.

The company has not published any statements about the allegations and did not respond to BleepingComputer's requests for comment. Reuters independently confirmed that the FBI's New Orleans office is investigating the incident, though the agency has not issued an official statement.

The illegal service Nexus is no longer online, but cybercriminals still have access to the database. It remains unclear whether IDScan's systems were compromised or how many individuals are affected.

Given the potential scale, additional lawsuits — including class actions — could be filed, and related cases may be consolidated into multidistrict litigation. State attorneys general and federal regulators could launch separate investigations or enforcement actions, as has happened with past large-scale data exposures such as the 23andMe breach and the Marriott data incidents.

§

Analysis

Why This Matters

  • The breach exposes hundreds of millions of individuals to identity theft and fraud: driver's licenses contain name, address, date of birth, and often digitized photos, making them a goldmine for criminals.
  • ID verification companies like IDScan hold highly sensitive data from multiple industries (car rentals, gun shops, financial services, cannabis dispensaries), so a single breach can cascade into widespread harm.
  • The incident raises scrutiny over data retention and security practices of third-party identity verification vendors that consumers may not even know are handling their personal information.

Background

IDScan is an identity verification technology company headquartered in Louisiana that provides hardware and software solutions for businesses to scan, authenticate, and extract information from government-issued identity documents. Its systems are used across the U.S. in car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments. The company has not disclosed its data retention policies or how long it stores scanned ID images.

Key Perspectives

[Affected consumers]: Individuals whose IDs were scanned through businesses using IDScan may have their personal information exposed. Law firms are seeking potential claimants for class-action cases, arguing the company failed to protect sensitive data. [IDScan]: The company has not published any statements about the allegations and did not respond to requests for comment. It began notifying some business customers around September 1, according to the law firm Markovits, Stock & DeMarco. [FBI]: The agency's New Orleans office has launched an investigation into the incident but has not issued an official statement. The investigation may focus on how the data was accessed and whether federal computer fraud statutes were violated. [Critics/Skeptics]: Questions remain about the accuracy of the claimed 153 million figure and whether IDScan was directly breached or whether a client's system was compromised. The company has not confirmed any breach, so the full scope remains unverified.

What to Watch

  • Whether IDScan issues a public statement confirming or denying the breach, and whether it offers credit monitoring or identity protection services to affected individuals.
  • Court filings in the Louisiana lawsuits will reveal more details about the alleged security failures and the number of claimants.
  • The FBI investigation may lead to criminal charges if evidence points to a specific hacker group or insider threat.
  • State attorneys general, particularly in California and New York, could launch separate consumer protection investigations.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.