
IDScan.net has confirmed that hackers accessed customer data stored in its cloud, including names and driver’s license or other government-issued identification numbers.
The disclosure follows reports linking the identity verification provider to a massive cache of over 153 million driver’s license scans offered through a dark web service.
IDScan published a data security notice dated September 4, but search engines didn’t index it, and it wasn’t added to its press releases section. The notice explains IDScan received information around September 1 indicating that data may have been accessed without authorization. The company said it secured its systems, hired third-party specialists to investigate, and is cooperating with federal law enforcement.
The Louisiana-based company provides identity verification and document scanning technology used by businesses including rental car agencies, retailers, entertainment venues, and cannabis dispensaries. IDScan says its technology processes more than 21 million identity verifications per month across over 20,000 locations worldwide.
According to the notice, an unauthorized third party may have accessed or copied information stored in customer accounts on the IDScan.net cloud. The exposed data may include full names, driver’s license numbers, and numbers from other government-issued identification documents.
IDScan has not disclosed how many people were affected.
CyberInsider previously reported on September 2 that the FBI was investigating an apparent breach after cybersecurity journalist Brian Krebs traced a dark web identity-document marketplace called Nexus back to IDScan.
Nexus claimed to provide access to more than 153 million US and Canadian driver’s licenses, alongside millions of other identity documents. Krebs verified records belonging to himself and others by matching document scans and timestamps to occasions when the IDs had been presented to businesses using IDScan technology.
CyberInsider contacted IDScan at the time seeking confirmation and additional information about the suspected breach but did not receive a response.
TechCrunch first spotted and reported IDScan’s breach notification on September 10, bringing the company’s acknowledgment of the incident to wider attention.
The notification page contained a noindex directive, which instructs search engines not to include the page in their search results and which apparently delayed its discovery.
IDScan said “full access” to the affected information required payment, suggesting that the dark web service's paid-access model limited the spread of the stolen data.
The company is offering potentially affected individuals free credit monitoring and identity protection services.
People who believe their identification data may have been exposed should consider freezing their credit with the major credit bureaus, monitoring financial accounts and credit reports for suspicious activity, using strong multi-factor authentication, and staying alert for phishing or identity-verification scams using stolen personal information.







Leave a Reply