IDScan data breach leaks 153M driver's license records

Published September 3, 2026

A dark-web criminal service called Nexus advertised more than 153 million U.S. and Canadian driver's license scans for sale, along with 10 million ID cards and other documents. Security researcher Brian Krebs traced the leaked data back to IDScan, a company whose ID-scanning systems are used by car rental firms, retailers, gun shops, banks, and hotels.

Report priority
Medium
Victim
IDScan

What is known

It is not yet confirmed whether attackers broke into IDScan's own systems or obtained the data another way, but Krebs verified real license scans in the Nexus database and traced them back to IDScan, and the company has since begun notifying some of its business customers.

What to do

Watch for a breach notice if you have rented a car, bought a gun, checked into a hotel, or shopped somewhere that scanned your driver's license or ID.

IDScan has not confirmed the breach or published a fix, so there is no personal patch. If you receive a notice from a business that used IDScan, treat it as your license and ID data being exposed and consider a credit freeze or fraud alert, since law firms are already gathering affected individuals for a possible class action.

Reported details

IDScan's scanners sit at the counter of car rental desks, retail stores, and gun shops, capturing a photo and the printed details of every driver's license a customer hands over. Those scanned records ended up in a database sold through the dark-web service Nexus for more than 153 million licenses. Krebs verified the leak was real by searching the database for his own driver's license record and finding it there.

A dark-web identity-theft storefront named Nexus offered a database of over 153 million U.S. and Canadian driver's license scans, 10 million other ID cards, 3 million travel documents, and 579,000 medical cards. Krebs on Security verified sample records, including the reporter's own, and traced the source to IDScan, an identity-verification vendor whose scanning hardware and software is deployed across car rental, retail, gun, financial, cannabis, and hospitality businesses in the U.S. IDScan has not confirmed whether its own infrastructure was breached, but began notifying some business customers around September 1, 2026. The FBI's New Orleans field office has opened an investigation, and multiple law firms have filed or are investigating class-action lawsuits.