IDScan.net has confirmed the data breach at its cloud platform, saying an unauthorized third party accessed customer records. The IDScan data breach exposed full names and driver’s license numbers, and the company learned of it on or around 1 September 2026. A dark-web service had listed more than 153 million license scans days earlier.
What IDScan Has Confirmed, and What It Has Not
As of 11 September 2026, IDScan.net has confirmed that customer data was accessed without authorization, but it has not said how many people were affected.
IDScan.net is an identity-verification vendor based in Metairie, Louisiana, that supplies ID-scanning hardware and software to businesses that need to check a customer’s age or identity. In a notice dated 4 September 2026, the company said that “on or around September 1, 2026, IDScan.net received information indicating that certain data may have been accessed without authorization,” and that “an unauthorized third party may have accessed and/or copied certain customer information.”
The company said it secured its systems, engaged outside specialists, and is cooperating with federal law enforcement. It is offering free credit monitoring and identity protection to potentially affected individuals, and has opened a support line on 1-833-516-2980, staffed Monday to Friday, 8am to 8pm Eastern Time. On 10 September, TechCrunch reported that IDScan had gone further and acknowledged that images of driver’s licenses were taken from its cloud, not only the numbers printed on them.
Three things remain unstated by the company:
- The number of people affected: IDScan has given no total, and its notice says it is notifying individuals “in an abundance of caution.”
- How the intruder got in: the notice describes access to customer accounts on the IDScan.net cloud but does not name a cause.
- How long the access lasted: the company says only that potentially affected records are those that entered the system before 1 September 2026, and that there is no evidence of ongoing unauthorized access.
Where the 153 Million Figure Comes From
The 153 million number is not IDScan’s; it is a count of search results on the dark-web market that was selling the documents.
On 1 September 2026, the security journalist Brian Krebs reported that a new service called Nexus was offering scanned identity documents for sale, and that a blank search on the site returned roughly 153 million records. Krebs tied the images to IDScan after noting that they included infrared and ultraviolet captures matching the company’s documented scanning technology, and after researcher Zach Edwards traced his own license scan to a visit to a Planet13 cannabis dispensary, a business IDScan announced as a customer in 2022.
| Document type | Records listed on Nexus |
|---|---|
| US and Canadian driver’s licenses | More than 153 million |
| Identification cards | More than 10 million |
| Travel documents and international IDs | More than 3 million |
| Medical cards | About 579,000 |
Those components add up to roughly 167 million documents; Biometric Update has reported the total as more than 170 million. Neither figure has been verified by IDScan or by any government agency. About 1.1 million of the licenses were Canadian, and Krebs counted 473,673 from Ontario alone. Nexus went offline shortly after his report was published, but the people who assembled the database still hold it.
How to Tell If Your License Was Scanned by IDScan
There is no lookup tool, and the practical test is not whether you have heard of IDScan but whether a business scanned your ID.
Almost nobody in this database signed up with IDScan directly. The company sells scanners, kiosks and mobile apps to businesses that check identity documents at the door or at the counter, so the record was created by a venue you visited, not by you. SecurityWeek, citing IDScan’s own materials, reported that the company handles more than 21 million verifications a month across more than 20,000 locations. Krebs reported that its dispensary business alone covers over 1,000 stores in 19 states.
You are more likely to be in the affected population if, since roughly 2022, a business in one of these categories photographed or barcode-scanned your license rather than glancing at it:
- Cannabis dispensaries: the single largest documented segment of IDScan’s customer base in the United States.
- Bars, nightclubs and casinos: venues using age-verification scanners or ID-activated door systems.
- Car rental counters and auto dealerships: IDScan lists automotive among the sectors it serves.
- Hotels, stadiums and event venues: hospitality and access-management deployments.
- Banks, fintech apps and logistics firms: onboarding and driver-verification checks.
A visual ID check leaves no record. A scan does. If you cannot remember, assume the scan happened and act accordingly, because IDScan is notifying by website notice as well as directly, and a direct notice may never reach you.
Why a Credit Freeze Does Not Cover a Stolen ID Image
A credit freeze blocks new credit accounts opened in your name, and it does nothing about a photograph of your license circulating among criminals.
Most coverage of this breach recommends freezing your files at Equifax, Experian and TransUnion. That advice is sound and worth following, but it was written for card-and-account breaches such as the Weverse data breach reported earlier this month, where the exposed material was transaction records. A card number can be reissued and a freeze stops the main downstream harm. Neither applies cleanly here.
What was taken is a usable image of a government document. That image can be uploaded to any service whose identity check accepts a photograph of an ID, which includes many exchanges, marketplaces, rental applications and mobile carriers. A freeze at the credit bureaus does not sit between an attacker and those checks. A driver’s license number is also not reissued on request in most jurisdictions; replacing it usually means demonstrating actual fraud to a licensing authority first.
No confirmed misuse of the IDScan images has been reported publicly as of 11 September 2026. That is a statement about what is known, not an assurance.
What to Do Now
- Freeze your credit files at Equifax, Experian and TransUnion. It is free, reversible, and still the fastest single step.
- Enrol in the free credit monitoring and identity protection IDScan says it is providing, using the notice on its own site rather than a link from an email.
- Treat any request to “re-verify” your identity with suspicion. Breaches of this kind are routinely followed by phishing that asks the victim to upload a fresh copy of the same document.
- Contact your state DMV or provincial licensing authority if you see signs of misuse, and ask what its process is for flagging or reissuing a compromised license number.
- Watch for account-opening notices, unexpected bills and unfamiliar credit applications, which are the earliest visible signs that a document is being used.
The FBI Inquiry and Four Class Actions
The FBI’s New Orleans field office has opened an investigation, and four proposed class actions have already been filed.
Krebs reported the New Orleans field office inquiry, and an FBI spokesperson separately confirmed to reporters that the bureau is investigating. TechCrunch reported that the Pentagon said it was aware of the suspected breach. The four proposed class actions were filed in the US District Court for the Eastern District of Louisiana by plaintiffs in California, Florida, Georgia and Louisiana, who allege that businesses they patronised used IDScan’s technology and failed to protect their information.
IDScan has said little publicly beyond its notice. Asked by Krebs about the findings, Jillian Kossman, the company’s marketing and operations leader, said: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.”
Frequently Asked Questions
Was My Driver’s License in the IDScan Data Breach?
There is no public tool to check. If a business scanned or photographed your license rather than simply looking at it, you may be in the affected population, and dispensaries, bars, casinos, car rental counters and hotels are the most common IDScan deployments.
Has IDScan Said How Many People Are Affected?
No. As of 11 September 2026 the company has confirmed unauthorized access but has published no victim count. The 153 million figure comes from search results on the dark-web market, not from IDScan.
Does a Credit Freeze Protect Me After an ID Scan Is Stolen?
Only partly. A freeze blocks new credit accounts, but it does not prevent someone from uploading a stolen image of your license to services that verify identity by document photograph. Freeze your files, but do not treat it as complete cover.
Is the Nexus Site Still Selling the Documents?
Nexus went offline shortly after Brian Krebs published his report on 1 September 2026. The operators still hold the data, and taking the storefront down does not remove copies already sold or retained.
Why Did IDScan Have My License If I Never Used It?
IDScan sells scanning equipment and software to other businesses. The record was created when one of those businesses verified your ID, so you would have no direct relationship with IDScan and no reason to recognise the name.




