Identity verification giant IDScan has admitted to a cloud platform breach that exposed over 153 million driver's license scans and other government IDs, fueling widespread identity theft concerns.

  • Over 153 million US and Canadian driver's license scans compromised.
  • Data includes full names, ID numbers, and high-resolution document images.
  • Breach first detected via the 'Nexus' dark-web marketplace.
  • FBI is currently investigating the scope of the unauthorized access.

Identity verification firm IDScan has officially confirmed that unauthorized third parties gained access to customer data stored within its cloud infrastructure. The admission comes after weeks of speculation and reports linking the company to a gargantuan database containing more than 153 million driver's license scans, which were being peddled on the dark web.

In a security notice published on September 4, IDScan stated that it discovered the breach around September 1. The company claims to have immediately engaged third-party specialists to secure its systems. However, critics have pointed out that the company initially attempted to hide the notification from search engines using a 'noindex' directive, raising questions about its transparency during the crisis.

Why This Matters

BozokMedia analysis shows that this breach represents a catastrophic failure in the 'chain of trust.' IDScan's clients include car rentals, financial institutions, and gun shops—sectors where identity verification is a legal mandate. By losing these scans, IDScan hasn't just lost data; it has provided criminals with the exact blueprints needed to create flawless fake IDs, potentially undermining the security of thousands of businesses globally.

"The exposure of actual image scans is far more dangerous than text-based leaks, as it allows threat actors to bypass biometric and visual verification checks."

The crisis first surfaced when renowned cybersecurity journalist Brian Krebs reported that a dark-web platform called 'Nexus' was advertising a massive trove of identity documents. The database allegedly contained not only 153 million driver's licenses but also 10 million ID cards, 3 million travel documents, and over half a million medical cards. Krebs verified the leak by searching for his own records, tracing the source directly back to IDScan.

Following the leak, multiple lawsuits have been filed against the company. While IDScan is now offering free credit monitoring and identity protection to affected individuals, the damage may already be irreversible. The FBI has confirmed its involvement in the investigation, as the scale of the breach suggests a sophisticated state-sponsored or high-level criminal operation.

Document Type Estimated Volume
Driver's License Scans 153 Million+
General ID Cards 10 Million
Travel Documents 3 Million
Medical Cards 579,000
Did You Know?: Many identity verification companies store images in 'buckets' (cloud storage) that, if misconfigured, can be accessed by anyone with the correct URL, even without a password.

Frequently Asked Questions

Q1: What specific data was stolen?
The breach included full names, government-issued ID numbers, and actual image scans of the documents.

Q2: How can I protect myself if I'm affected?
Enable multi-factor authentication (MFA) on all accounts and consider placing a fraud alert on your credit report.