IDScan.net Data Breach: Was Your Driver’s License Exposed?

The ID-scanning firm behind countless counter checks says names and license numbers were taken. A seller claimed 153 million records. Here is what to do.

A worker at a desk beside a desktop ID scanner holding a driver's license, with a monitor showing an Authentication Failed message
A desktop ID scanner in IDScan.net's product imagery. Image: IDScan.net.

IDScan.net, a Louisiana company whose scanners and apps check driver’s licenses at stores, car rental counters, dispensaries and casinos, has confirmed a data breach. In a notice dated September 4, 2026, the company said an unauthorized third party “may have accessed and/or copied” customer information stored in its cloud, including full names and driver’s license or other government ID numbers. Reporting by security journalist Brian Krebs ties the incident to a dark-web service that claimed to sell scans of more than 153 million US and Canadian driver’s licenses — a figure IDScan.net has not confirmed.

Key facts

  • Company: IDScan.net, an ID-scanning and identity verification provider based in the New Orleans area
  • Discovered: on or around September 1, 2026; public notice dated September 4, 2026
  • Data involved (per IDScan.net): full names and driver’s license or other government-issued ID numbers
  • Scale: not disclosed by the company; a dark-web seller advertised 153 million+ license records, according to KrebsOnSecurity
  • Help line: 1-833-516-2980, Monday to Friday, 8 a.m. to 8 p.m. ET, for questions and free credit monitoring enrollment
  • Law enforcement: IDScan.net says it is cooperating with a federal investigation

Because IDScan.net sells to businesses, most people whose licenses may be in the data have never heard of the company. They simply handed over an ID at a counter. Below is what the company has officially said, what has been reported beyond that, how to tell whether you might be affected, and the concrete steps worth taking this week.

What happened at IDScan.net?

According to the company’s official Notification of Data Security Incident, IDScan.net “received information indicating that certain data may have been accessed without authorization” on or around September 1, 2026. The company says it took immediate steps to secure its systems and hired third-party specialists to investigate, and that the investigation “is currently ongoing.”

The notice says that an unauthorized third party may have accessed or copied “certain customer information stored within their accounts on the IDScan.net cloud.” In other words, the data belonged to IDScan.net’s business customers — the stores and services that scan IDs — and consisted of records about the people whose IDs were scanned.

One line in the notice stands out: “Though full access to the information required payment, in an abundance of caution, we are notifying potentially impacted individuals.” That wording suggests the data was being offered behind a paywall, which fits reporting that the seller offered redacted preview searches and charged for full records.

What information was exposed?

IDScan.net’s notice lists only two categories: full names and driver’s license or other government-issued identification numbers. The company has not said whether dates of birth, home addresses, photos or images of the cards themselves were involved.

Independent reporting paints a broader picture. KrebsOnSecurity, which first exposed the sale, reported that a service called “Nexus” advertised on a Russian-language cybercrime forum on August 31 that it had been pulling data “for over a year” from a major identity verification company. According to that reporting, each record contained six image files: the front and back of the ID, a basic scan, and infrared and ultraviolet versions. A physical driver’s license carries your photo, date of birth, home address and physical description, so an image of the card exposes far more than the license number alone. Those details come from the seller’s listings as described by the reporter and have not been confirmed by IDScan.net.

ClaimSourceStatus
Names and driver’s license / government ID numbers accessed or copiedIDScan.net notice, September 4Confirmed by the company
153 million+ US and Canadian driver’s licenses offered for saleKrebsOnSecurity, citing the Nexus listingSeller’s claim; not confirmed by IDScan.net
10 million+ ID cards, 3 million+ travel documents, 579,000+ medical cards also listedKrebsOnSecurity, citing the Nexus listingSeller’s claim; not confirmed
Front, back, infrared and UV images of each cardKrebsOnSecurityReported; not addressed in the company notice
FBI New Orleans field office investigatingKrebsOnSecurity; IDScan.net says it is cooperating with federal law enforcementInvestigation confirmed in general terms

How many people are affected?

IDScan.net has not published a number. Its notice does not say how many customer accounts or individuals were involved, and it says the investigation is still under way.

The 153 million figure comes from the criminal seller’s own advertising, as reported by KrebsOnSecurity. Sellers on criminal markets have every reason to inflate their numbers, and the count may include duplicates — the same person scanned at several businesses — so treat it as an upper-bound claim rather than a verified total. Even so, the reporter was able to match specific records to real people, including his own license, which suggests that at least a large portion of the data is genuine.

Was I affected? How to tell

There is no public lookup tool for this breach, and IDScan.net has not said how it will identify and reach the people whose IDs its customers scanned. That makes it hard to be certain. These are the realistic ways to judge your exposure:

  • You receive a notice letter. IDScan.net says it is “notifying potentially impacted individuals.” A genuine letter should reference the same incident and the same help line number, 1-833-516-2980.
  • You had your ID scanned by a business that used IDScan.net. KrebsOnSecurity traced records to ID scans at Hertz car rental counters and at a Planet13 cannabis dispensary in Las Vegas, and reported that other clients have included retailers, a casino operator and financial services firms. Caesars Entertainment told the reporter it stopped using the service in February 2025. None of those companies’ inclusion means every one of their customers is affected.
  • You were scanned in the past year or so. The seller claimed to have been collecting data “for over a year,” and the reporter’s own record came from a June 2025 rental.

If any of these apply to you, or if you regularly have your license scanned rather than just glanced at, assume your details could be in the data and take the steps below. They are free and useful regardless.

What to do now: 7 steps

Step 1: Call the IDScan.net help line and enroll in the free monitoring

IDScan.net is offering free credit monitoring and identity protection services. Call 1-833-516-2980 (Monday to Friday, 8 a.m. to 8 p.m. ET, excluding holidays) to ask whether you are on the notification list and to enroll. Only use the number printed in the official notice or on IDScan.net’s own website — not one from an email, text or social media post.

Step 2: Freeze your credit at all three bureaus

A driver’s license number plus a name, address and date of birth can be enough to attempt new-account fraud. The Federal Trade Commission’s guide to credit freezes and fraud alerts explains that while a freeze is in place, “nobody can open a new credit account in your name,” that placing or lifting one costs nothing, and that it does not affect your credit score. You must contact all three bureaus separately — Equifax, Experian and TransUnion. The Equifax credit freeze page and the Experian freeze center let you do it online; IDScan.net’s notice lists TransUnion’s number as 1-800-680-7289.

Step 3: Or place a fraud alert

If a freeze is too inconvenient because you are about to apply for a loan or a job, the FTC notes you can place an initial fraud alert instead. It tells lenders to verify your identity before opening credit, lasts one year, is free, and you only need to contact one bureau, which must notify the other two.

Step 4: Check your credit reports

Review your reports for accounts or inquiries you do not recognise. You can get your reports free from all three bureaus through AnnualCreditReport.com, the official site for free credit reports. Keep checking over the coming months, not just once.

Step 5: Watch your existing accounts

IDScan.net’s notice urges people to review “account statements for suspicious activity.” A leaked license alone will not let someone into your bank account, but it can help a criminal pass identity checks when calling a bank or mobile carrier, or answer knowledge-based questions. Turn on transaction alerts in your banking apps and add a PIN or passcode to your mobile phone account if your carrier supports one.

Step 6: Treat unexpected contact as a scam until proven otherwise

Big breaches attract follow-on scams. Expect fake “breach settlement” messages, phony credit monitoring offers and callers claiming to be from IDScan.net, the FBI or a bank. Do not give personal details to anyone who contacts you first, and do not click links in messages about this breach. Call the official number yourself instead.

Step 7: Report identity theft if it happens

If someone does misuse your information, report it at IdentityTheft.gov, the FTC’s official identity theft site, which IDScan.net’s notice also points to. An FTC identity theft report lets you place an extended fraud alert, which the FTC says lasts seven years. You may also want to contact your state’s motor vehicle agency to ask what options exist if your license number is being used fraudulently.

Why a driver’s license breach is harder to fix

When a password leaks, you change it. When a credit card leaks, the bank sends a new one. A driver’s license number, date of birth and face are much harder to replace, and they are used as proof of identity in dozens of places, from rental counters to phone stores to online account recovery. That is why the steps above focus on locking down credit and watching for impersonation rather than on “changing” anything.

It also shows the risk of ID scanning itself. Many businesses scan a license only to check a customer’s age or confirm a name, but a scan can create a stored digital copy of the card that sits in a vendor’s cloud long after the transaction. Where you have the choice, it is reasonable to ask whether a business needs to scan your ID rather than simply look at it, and how long it keeps the data.

Protect your online accounts too

Stolen identity documents are sometimes used to talk support staff into resetting account access. The best defence is to make your important accounts rely on something a thief cannot get from a picture of your license. Use a unique password for every account — our comparison of Bitwarden, 1Password and Proton Pass can help you pick a manager — and switch your email, bank and phone carrier accounts to passkeys or an authenticator app wherever possible. Our step-by-step guide to setting up passkeys on iPhone, Android and Windows covers the most important accounts.

What happens next

IDScan.net says its investigation is ongoing and that it has reviewed its data security policies and procedures. Expect the company to send notification letters, and watch for filings with state attorneys general, which often reveal how many residents of each state were affected. According to KrebsOnSecurity, the Nexus website was taken offline on September 2, though the data could already have been copied by buyers, so the takedown does not undo the exposure.

The bottom line: if you have had your driver’s license scanned at a business in the past year or two, freeze your credit at all three bureaus today — it is free and stops anyone from opening new credit in your name while it is in place. Then call 1-833-516-2980 to claim the free monitoring IDScan.net is offering, and stay sceptical of anyone who contacts you about this breach.

Frequently asked questions

Was I affected by the IDScan.net data breach?

There is no public lookup tool. IDScan.net says it is notifying potentially impacted individuals, and you can call its help line at 1-833-516-2980 to ask. If a business scanned your driver's license in the past year or two, it is sensible to assume you could be affected.

What information was stolen in the IDScan.net breach?

IDScan.net says the affected data may include full names and driver's license or other government-issued ID numbers. Reporting by KrebsOnSecurity says the seller also offered front, back, infrared and ultraviolet images of the cards, which the company has not confirmed.

Were 153 million driver's licenses leaked?

That number comes from a dark-web seller's advertising, as reported by KrebsOnSecurity. IDScan.net has not said how many people were affected, and the seller's figure may include duplicates.

Is IDScan.net offering free credit monitoring?

Yes. The company's September 4 notice says it is providing access to free credit monitoring and identity protection services. Call 1-833-516-2980, Monday to Friday, 8 a.m. to 8 p.m. ET, to enroll.

Should I freeze my credit after the IDScan breach?

It is a good precaution. The FTC says a credit freeze is free, does not affect your credit score and stops anyone from opening new credit in your name while it is in place. You need to contact Equifax, Experian and TransUnion separately.

Sources

More on IDScan.net data breach →IDScan.netData breachDriver's licenseIdentity theftCredit freeze
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all