IDScan Breach Exposes 153 Million Driver's Licenses
ID verification vendor IDScan confirmed a breach exposing 153 million driver's licenses, raising fresh questions for India's own ID-scanning habits.
Hand your driver's license to a rental car counter or a bar bouncer's scanner, and for a second or two, a machine reads everything on it — your photo, your address, the barcode, sometimes even the hidden infrared and ultraviolet security patterns printed into the card. That scan is supposed to disappear into a database and never resurface. For more than 153 million people in the US and Canada, it just did.
How a routine ID check turned into a 153-million-record leak
Security journalist Brian Krebs broke the story on August 31: a newly launched dark-web marketplace called Nexus was advertising bulk access to over 153 million scanned driver's licenses, plus another 10 million ID cards, 3 million travel documents, and nearly 580,000 medical cards. The trail led to IDScan.net, a New Orleans-based identity verification company whose scanners sit behind counters at car rental desks, retail stores, dispensaries, and casinos across North America.
IDScan confirmed the breach in a notice published on September 4, saying it detected unauthorized access to customer accounts on its cloud platform around September 1. What made the disclosure worse: reporters found the notice page had been configured with a "noindex" tag, quietly telling search engines not to list it — the kind of move that makes a breach harder for affected people to stumble across while searching for their own name.
"Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident," IDScan said in its breach notification.
What makes this leak sting more than a typical password dump is the resolution of the data. Krebs' reporting found high-quality scans — including the infrared and UV layers normally invisible to the naked eye — bundled with timestamps showing exactly when and where each ID was scanned: a car rental pickup, a dispensary visit, an airport security line. That's not just a name and number; it's a location-tagged movement record built from documents people had no real choice but to hand over.
Who's caught up in it, and what happens next
IDScan's client roster reportedly includes Hertz, Target, FedEx, Motorola Solutions, casino operator Caesars Entertainment, and financial services firm Jack Henry — though Caesars has pushed back, telling Krebs it stopped using IDScan's VeriScan product back in February 2025 and shouldn't be affected. The FBI's New Orleans field office has opened a formal investigation, and multiple class-action lawsuits were filed within days of the disclosure.
For anyone whose ID may be in the mix, security researchers are recommending the basics that tend to get ignored until it's too late:
- Freeze your credit with all major bureaus, not just monitor it
- Watch for new accounts or loans opened in your name, since a scanned ID is often enough to pass "identity proofing" checks elsewhere
- Ask any business that scanned your ID recently whether it used IDScan.net's systems
- Treat unexpected calls or texts referencing your license number as a targeting attempt, not a coincidence
The India angle: this isn't just an American problem
India doesn't use IDScan, but it runs the same basic model at a much larger scale. Hotels, car rental startups, co-working spaces, and even some retail chains routinely scan Aadhaar cards, PAN cards, or driving licences at the counter and store the images with third-party verification vendors — often with far less scrutiny than what IDScan is now getting. The Digital Personal Data Protection (DPDP) Act, 2023 requires companies to report significant breaches to India's Data Protection Board and notify affected users, but enforcement is still new, and most Indian users have no idea which vendor actually holds their scanned ID after a hotel check-in or a bike rental. This breach is a useful reminder of why DigiLocker — the government's system that lets you share a verified copy of a document without handing over the physical original for someone else's camera — exists in the first place, and why more Indian businesses ought to be using it instead of building their own photo archives of everyone's ID.
A trust problem the industry can't scan its way out of
The uncomfortable part of this story isn't that IDScan got breached — it's that "scan and store" is still the default way identity verification works almost everywhere, despite years of exactly this kind of incident hitting similar vendors. It happened to Discord's age-verification vendor in 2025, and now to a company that sits behind rental car counters — the common thread is always a third party holding a government ID scan that the original user never chose to trust. Every counter that photographs your ID "for verification" is making a promise about how long that image lives and who can see it, and there's rarely any way for the person handing over their license to check whether that promise is being kept. Until verification systems move toward proving a claim (yes, this is a valid license, yes, this person is over 21) instead of hoarding a full copy of the document itself, this exact headline is going to repeat with a different vendor's name in it.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0