Identity verification company IDScan is facing multiple lawsuits after hackers allegedly infiltrated its services and offered to sell more than 153 million driver’s license records online.
Law firms including Markovitz, Stock & DeMarco and Hall Attorneys have also launched investigations into potential class action litigation related to the reported IDScan security incident.
As first reported by Brian Krebs on September 1, a dark web identity theft service known as “Nexus” advertised access to more than 153 million U.S. and Canadian driver’s license scans, 10 million identity cards, 3 million travel documents, and 579,000 medical cards.
Krebs searched the database for his own records, as well as the records of individuals who consented to testing. The investigation reportedly verified the samples and traced the exposed information to IDScan.
IDScan is an identity verification technology company that provides hardware and software used to scan, authenticate, and extract information from government-issued identification documents.
The company’s systems are used by businesses including rental car companies, retailers, gun stores, financial institutions, cannabis dispensaries, and hospitality providers across the United States.
IDScan has not issued a public statement addressing the allegations and did not respond to BleepingComputer’s request for comment.
It remains unclear whether IDScan’s systems were directly compromised or how many individuals may have been affected by the alleged data exposure.
Krebs also reported that the FBI’s New Orleans office opened an investigation into the incident. Reuters independently confirmed that the FBI is investigating reports that millions of driver’s licenses may have been exposed.
At the time of publication, authorities had not released an official statement providing additional details or confirmed the full scope of the incident.
The Nexus service is no longer online. However, the reported data may have been copied or distributed by other cybercriminals before the service was taken down.
A lawsuit filed in Louisiana, where IDScan is based, alleges that the company failed to adequately protect information collected from customers, including global car rental company Hertz.
According to Markovitz, Stock & DeMarco, IDScan began notifying some business customers about the incident around September 1.
The law firm said individuals whose identification documents were scanned by companies using IDScan’s technology may be affected. It is seeking potential claimants for a possible class action lawsuit.
Given the potential size of the alleged breach, additional lawsuits could be filed. Related cases may ultimately be consolidated into multidistrict litigation.
Large data breaches involving companies such as 23andMe, Marriott, and Equifax have previously prompted investigations by state attorneys general and federal regulators. Similar action could follow if authorities confirm that IDScan systems exposed sensitive identity documents.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



