IDScan data breach leaks 153M identities

Published September 1, 2026

An attacker is selling a database of 153 million scanned driver's licenses, ID cards, and passports allegedly stolen from identity verification company IDScan. The listing also includes medical cards, and researchers say the theft looks like it ran for years before anyone noticed.

Report priority
Medium
Victim
IDScan

What is known

An attacker known as NEXUS says they pulled data out of IDScan's systems slowly over several years, which let the theft stay under the radar instead of triggering an alert from a sudden burst of network traffic.

What to do

IDScan has not published a fixed version or patch since this is a data theft, not a software bug, so watch for a breach notification from IDScan or the FBI, and consider placing a fraud alert or credit freeze with the major credit bureaus given how usable scanned IDs are for identity theft.

Reported details

IDScan's software scans a customer's driver's license during a car rental to confirm their identity. An attacker who reached IDScan's systems copies that scan along with millions of others, a little at a time over years so no single transfer looks unusual. KrebsOnSecurity tested the claim using a friend's real rental scan and found it in the leaked database with a timestamp matching the actual rental.

The leak reportedly comprises 153 million driver's license scans, over 10 million ID card scans, more than 3 million passport scans, and 579,000 medical card scans, both front and back images, offered for sale on the EXPLOIT cybercrime forum by an actor using the alias NEXUS. Estimated raw volume ranges from roughly 30TB to over 140TB depending on image compression. KrebsOnSecurity corroborated authenticity by matching a known individual's rental-verification timestamp to a record in the sample data. IDScan says it has secured affected systems, preserved logs, engaged legal counsel and cyber insurers, and is investigating alongside law enforcement.