Skip to main content

Morning Overview

A breach at an ID-checking firm put 153 million driver’s licences up for sale

IDScan.net, an identity-verification company whose scanning technology sits behind age and ID checks at bars, retailers and other businesses, confirmed in a September 4 security notice that hackers had accessed data stored on its systems. The company said it first learned of the intrusion on or around September 1, days after a criminal marketplace began advertising more than 153 million driver’s licenses from the United States and Canada for sale. The exposed records can include a person’s full name alongside their driver’s license or other government-issued identification number.

Security journalist Brian Krebs broke the story before IDScan.net’s own disclosure, reporting that a dark web platform called Nexus was offering access to the trove alongside millions of additional identity documents from other sources. The gap between a criminal marketplace listing the data and the company that lost it confirming the breach publicly is a familiar pattern in large identity-document leaks, and it is part of why regulators and plaintiffs’ lawyers moved as quickly as they did once the notice went out.

What the Nexus Marketplace Was Actually Selling

Krebs’s reporting on the marketplace listing describes a bundle that went well beyond the 153 million driver’s licenses: roughly 10 million additional ID cards, 3 million travel documents, and 579,000 medical cards, all advertised for sale on the same platform. That scope suggested the breach, or the data aggregation behind the listing, drew from more than a single point of failure inside IDScan.net’s own systems, since travel documents and medical cards are not typically part of a standard driver’s-license verification check.

IDScan.net’s notice stopped short of explaining exactly how the additional document categories connected to its own breach, saying only that a third-party forensics team was still working to determine the full nature and scope of the incident at the time the notice was published.

TechCrunch’s coverage of the confirmation, published six days after the security notice went out, noted that identity-verification vendors occupy an unusually sensitive position in the wider data ecosystem: businesses hand over scanned copies of a customer’s government ID to check an age or confirm an identity, then trust a company most of those customers have never heard of to store the resulting images and numbers securely on their behalf.

Names and ID Numbers, Not Photos, Confirmed Exposed

The company’s own description of the exposed data centers on two fields: customers’ full names and their driver’s license or other government-issued identification numbers. That combination is enough on its own to support identity theft and fraudulent account opening, even without the scanned photo or barcode image some earlier reports suggested might also be included in the marketplace listing.

IDScan.net said it is notifying individuals whose information may have been affected and offering free credit monitoring and identity-protection services, a standard response for a breach of this kind but one that does little to prevent a license number from being reused once it has already been copied and offered for sale.

The FBI’s New Orleans Field Office Opens a Case

The FBI’s New Orleans field office opened an investigation into the apparent breach, a detail that signals the bureau treated the scale of the exposure as serious enough to warrant a formal federal inquiry rather than leaving it to state regulators alone. Krebs’s coverage of the FBI’s involvement came before IDScan.net’s own confirmation, adding pressure on the company to acknowledge the incident publicly rather than waiting for a slower internal review to conclude first.

Neither the bureau nor IDScan.net has said publicly how the 153 million licenses were pulled from the company’s systems, whether through a compromised employee credential, an exposed database, or a vulnerability in one of the third-party platforms IDScan.net’s verification tools connect to. That gap has left the marketplace listing itself, rather than any official account of the intrusion, as the main public record of what was actually taken.

Law Firms Begin Circling for Class Actions

Multiple law firms have since filed lawsuits against IDScan.net and opened investigations into potential class-action litigation on behalf of affected customers, arguing the company failed to adequately secure identity data it was specifically in the business of verifying. BleepingComputer’s reporting on the breach notes the litigation is still in its early stages, with no settlement or court ruling yet establishing what, if anything, IDScan.net owes the millions of people whose license numbers ended up on a criminal marketplace.

For businesses that used IDScan.net to verify a customer’s age or identity at checkout, the breach raises a separate question the lawsuits have not yet answered: how much of that verification data those businesses themselves retained, and whether their own customers were ever told their license numbers passed through a system that would later be compromised. Until a court forces disclosure of those retention practices, the 153 million people whose licenses turned up on the Nexus marketplace have only IDScan.net’s own account, and a criminal listing, to go on.


More from Morning Overview

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.