US Edition
Your source for latest news
TechnologyCybersecurity

ID-verification firm confirms breach exposing 153 million driver's licenses

IDScan.net, whose scanners sit behind rental-car counters, casinos and dispensaries nationwide, has confirmed hackers stole a trove of driver's license and passport scans now circulating on a dark-web marketplace.

PT
By PressTemps Technology DeskPublished Yesterday, 21:55 ET · 6 min read
ID-verification firm confirms breach exposing 153 million driver's licenses
A sample driver's license design from the California DMV, shown for illustration only — not one of the documents involved in the IDScan.net breach.
What to know
IDScan.net, a Louisiana identity-verification vendor, confirmed hackers stole roughly 153 million driver's license scans plus 10 million ID cards, 3 million passports and 579,000 medical cards.
The stolen data was first advertised on a dark-web marketplace called Nexus and traced back to IDScan.net by security researcher Brian Krebs before the company itself confirmed the breach.
Businesses that rely on IDScan.net's ID-scanning technology include Hertz, Target, Caesars Entertainment, FedEx, Motorola Solutions and over a thousand cannabis dispensaries and gun shops.
The FBI has opened an investigation and at least nine class-action lawsuits have been filed against the company in federal court in Louisiana.

A Louisiana identity-verification company used by rental-car counters, retailers, casinos and cannabis dispensaries across the United States has confirmed that hackers stole a cache of driver's license scans and other government identification documents large enough to touch roughly half the adult population of North America. IDScan.net, based in Metairie, near New Orleans, disclosed in a security notice posted to its own website that it learned on or around September 1 that a customer-facing cloud system had been accessed without authorization. The disclosure, quietly filed on September 4 and widely reported only after news organizations found it on September 10, confirmed a breach that security researchers had already traced to the company more than a week earlier.

The company's statement is spare. It says an unauthorized third party "may have accessed and/or copied" information held in customer accounts, that outside forensic specialists were brought in immediately, and that federal law enforcement has been notified. It does not name the intruders, explain how they got in, or say how many people were affected. Those details emerged instead from independent reporting that first surfaced the stolen data on a criminal marketplace.

The scope of the exposure

The breach came to light when the security journalist Brian Krebs reported on a dark-web platform called Nexus that was advertising more than 153 million U.S. and Canadian driver's license scans for sale, along with millions of other identity documents. According to a breakdown tallied from the listings, the trove also included more than 10 million identification cards, upward of 3 million passports and other travel documents, and roughly 579,000 medical identification cards. Each license record reportedly came with several image files — front and back photographs, a standard scan, and infrared and ultraviolet versions used by scanning hardware to detect forgeries — suggesting the data was pulled directly from the machines businesses use to verify identity at the counter, not from a simple database dump.

Krebs verified the leak was genuine by locating his own driver's license, issued in Virginia, offered as a free sample on a Russian-language cybercrime forum tied to the marketplace.

How the breach came to light

IDScan.net has spent more than two decades selling age- and identity-verification hardware and software to businesses that are legally required to check government identification — bars, gun shops, casinos, and, more recently, cannabis dispensaries and retailers enforcing age limits on tobacco and alcohol sales. Its scanners read the machine-readable zones and security features on driver's licenses and passports, and the resulting images are typically retained by the business, the software vendor, or both, for compliance and fraud-prevention purposes. That business model means the company sits on an unusually rich and unusually sensitive archive: unlike a retailer's breached customer list, a stolen ID scan cannot be reset the way a password can.

News organizations, including TechCrunch's initial reporting on the dark-web listing earlier this month, had already pointed to IDScan.net as the likely source days before the company's own confirmation. That gap between independent discovery and corporate disclosure has become a familiar pattern in major breaches, and it drew renewed criticism this week from security researchers who noted that IDScan's notice carried a search-engine "noindex" tag that kept it out of Google results until reporters found it directly.

Who is affected

IDScan.net's client roster reads like a cross-section of American retail and hospitality: rental car company Hertz, retailer Target, casino operator Caesars Entertainment, shipping company FedEx, financial-technology firm Jack Henry, communications equipment maker Motorola Solutions, and more than a thousand cannabis dispensaries and gun shops that use the company's scanners to comply with state age-verification laws. Consumers who handed a license to a clerk at any of those counters in recent years — rather than customers of IDScan.net directly — are the ones whose information may now be circulating. Because IDScan.net's technology often operates behind the scenes of a much larger brand, many affected people are unlikely to have ever heard the company's name before this week.

The scale drew attention beyond the usual pool of security-conscious consumers after Krebs reported that a scan purportedly belonging to Defense Secretary Pete Hegseth was listed for sale on the marketplace for $100, illustrating that the exposure was not confined to ordinary retail transactions. IDScan.net said it is offering free credit monitoring and identity-protection services to people it can identify as affected, and has set up a dedicated phone line for inquiries.

Reaction, lawsuits and what happens next

The Federal Bureau of Investigation's field office in New Orleans has opened an inquiry, though it has offered little detail publicly.

"The FBI can confirm that it is looking into the incident. Due to the ongoing nature of the investigation, we decline to comment further," a spokesperson for the bureau's New Orleans field office told a local television station.

The legal response has moved faster than the regulatory one. At least nine putative class-action complaints were filed against IDscan.net Inc. in the U.S. District Court for the Eastern District of Louisiana in the first days of September, according to court filings reviewed by trade publications, with plaintiffs from California, Florida, Georgia and Louisiana arguing that the company failed to adequately protect data it was entrusted with by the businesses that hired it. The suits, several of which name Hertz transactions specifically as a point of origin for plaintiffs' stolen data, seek damages and changes to IDScan.net's security practices. The company has not responded publicly to the litigation.

IDScan.net says its investigation into the breach's scope is continuing and that it will notify individually affected customers as they are identified, a process that for breaches of this size typically stretches over weeks or months. Security researchers have urged people who have used identity verification at a rental counter, casino, dispensary or retailer in recent years to treat driver's license fraud as a live risk rather than a hypothetical one, since a stolen license image can be used to open financial accounts or pass identity checks elsewhere. The FTC's identity-theft recovery service and the FBI's Internet Crime Complaint Center both offer guidance for reporting suspected misuse of stolen identification.

The episode is also likely to sharpen scrutiny of the identity-verification industry more broadly. A wave of state laws over the past several years has required businesses — from social media platforms to liquor stores to cannabis retailers — to verify customers' ages, often by scanning a government ID through third-party software. Privacy advocates have long warned that concentrating scans of sensitive documents with a small number of verification vendors creates a single point of failure; the IDScan.net breach, if the numbers reported hold up, would be among the largest practical demonstrations of that risk to date. Congress has not moved on federal data-breach notification legislation this year, leaving the current patchwork of state laws, under which IDScan.net is required to notify state attorneys general in jurisdictions where more than a threshold number of residents were affected, as the primary mechanism holding the company publicly accountable.

More on this story

All Technology