Several lawsuits have been filed against identity-verification company IDScan after its service was allegedly breached and data from more than 153 million driver’s licenses was offered for sale on the dark web. Available information indicates that the U.S. Federal Bureau of Investigation has begun investigating the incident, while the company has not yet publicly stated its position on it.
What Is Alleged to Have Been Leaked?
A dark-web criminal service called “Nexus” announced on September 1, 2026, that it possessed or provided access to more than 153 million copies of U.S. and Canadian driver’s licenses, along with 10 million identity cards, 3 million travel documents, and 579,000 medical cards.
Brian Krebs reported that samples from the database could be verified by searching for his records and those of people who agreed to undergo the checks. According to the tracking he conducted, the data led to IDScan, a company that provides hardware and software for scanning, authenticating, and extracting data from government-issued identity documents.
IDScan systems are used by organizations operating in car rentals, retail, gun stores, financial institutions, cannabis dispensaries, and the U.S. hospitality sector. This means that potentially affected individuals may not be direct customers of the company, but rather people whose documents were scanned by businesses using its systems.
Official Investigation and Lawsuits in Louisiana
The Federal Bureau of Investigation, through its New Orleans office, confirmed that it was looking into the incident but declined to provide additional details because the investigation is ongoing. Reuters had independently confirmed that the investigation had begun, according to the source article.
The lawsuits were also filed in Louisiana, where IDScan is headquartered, and accuse the company of failing to protect information obtained from its customers, including global car-rental company Hertz. The firms Markovits, Stock & DeMarco and Hall Attorneys launched investigations into the possibility of filing a class-action lawsuit, and Markovits, Stock & DeMarco said that IDScan began notifying some of its business customers around September 1.
What Changes in Practice?
The shutdown of the Nexus service does not mean the data has disappeared; the article states that criminals still possess the database. If its claimed size is accurate, the risk is not limited to the exposure of identity-document numbers but extends to using document copies in identity-theft attempts or to bypass verification processes at other institutions. However, the source has not yet established how many people were affected, nor determined whether IDScan’s own systems were breached.
The article states that data attributed to U.S. Defense Secretary Pete Hegseth and an FBI assistant director appeared on the service, but it was unable to verify this information. Additional lawsuits or class actions may also emerge and could later be consolidated into multidistrict litigation. Regulatory agencies and state attorneys general may open separate investigations, but this remains a possibility rather than a confirmed action at present.
IDScan has not published a statement regarding the allegations and did not respond to BleepingComputer’s requests for comment. Therefore, as of the article’s update on September 4, 2026, the incident remains an alleged leak under investigation, not a definitively confirmed breach.