IDScan.net has confirmed that an unauthorized party may have accessed or copied identity data from customer accounts in its cloud, including full names and driver’s-license or other government-issued identification numbers.
The company’s September 4 notice does not say how many people are affected, how the intruder gained access, which customers’ accounts were involved, or how long the access lasted. It says the investigation is continuing, federal law enforcement is involved, and potentially affected people can enroll in free credit monitoring and identity-protection services.
A separate dark-web service called Nexus claimed to offer more than 153 million U.S. and Canadian driver’s-license records, along with millions of other identity documents. Security journalist Brian Krebs found evidence connecting the cache to IDScan and verified records belonging to himself, relatives, researchers, and government officials. IDScan has not publicly confirmed that 153 million figure, so it should be treated as the operator’s claim supported by outside sampling, not a final breach count.
What the stolen ID records reportedly contained
This was not described as a list of names and license numbers alone. KrebsOnSecurity reported that some records included images of the front and back of a license plus infrared and ultraviolet scans used to test whether a physical document is genuine. Customer photos were also available in some entries.
Nexus advertised more than 153 million driver’s licenses, more than 10 million identification cards, over three million travel documents or international IDs, and at least 579,000 medical cards. A blank search reportedly returned roughly 11.5 million pages with about 15 results per page. Canadian licenses accounted for about 1.1 million results, while most records appeared to cover people in the United States.
The cache was also growing. Krebs observed nearly 400,000 additional driver’s-license records appear over 24 hours, while the operator claimed it had been continuously taking data for more than a year. The Nexus site disappeared shortly after the report was published, but taking down a sales portal does not retrieve copies that may already have been downloaded.
How researchers connected the cache to IDScan
The timestamps attached to several license images matched occasions when their owners had presented IDs during travel. Krebs and his mother found scans timestamped seconds apart on a day when both handed licenses to a Hertz rental counter. Other researchers matched records to a car rental or a visit to a dispensary that used an ID scanner.
Those observations pointed to a shared verification provider rather than a compromise of one rental office or venue. IDScan markets its technology to car-rental companies, retailers, hospitality businesses, financial services firms, and more than 1,000 dispensaries. Its systems perform more than 21 million verifications a month at over 20,000 locations, according to figures cited by Krebs.
The evidence does not establish that every business ever named by IDScan was affected. Caesars Entertainment, for example, told Krebs that it had stopped using VeriScan in February 2025 and did not authorize IDScan to retain data from its accounts. The company said IDScan told it the incident should have no impact on Caesars.
IDScan’s retention defaults deserve scrutiny
IDScan’s own support documentation shows how a quick identity check can become a long-lived data store. New VeriScan Cloud accounts default to “Collect all,” which can include a cropped ID photo, a live webcam photo, high-resolution front and back scans, and attached records. New accounts also default to keeping all records in the cloud without a deletion date.
The controls depend on the subscription. Premium, Enterprise, and ID Authentication customers can choose to delete records after a set period. Enterprise and ID Authentication plans can purge personally identifiable information while retaining selected or anonymized fields after eight hours, one day, seven days, 30 days, 60 days, 90 days, or one year. IDScan’s documentation says Basic accounts collect all data and retain it by default, with neither setting change available on that plan.
Those defaults do not prove which settings produced the records in the breach. They do show that the platform was designed to make comprehensive collection and indefinite retention the starting point. That is a poor default for businesses that only need an answer such as “over 21,” “license valid,” or “name matches reservation.” Once full-resolution identity documents are stored, the verification system becomes a high-value identity archive.
What people can do now
There is no public, trustworthy lookup tool for the reported cache, and IDScan has not published a full customer list or final victim count. People who receive a notice should use the enrollment details in the notice or contact IDScan through the phone number on its incident page rather than following links in unexpected emails or texts.
- Freeze credit at all three bureaus. A freeze is free and restricts access to a credit report, making it harder to open a new account in someone else’s name. It must be placed separately with Equifax, Experian, and TransUnion.
- Review credit reports and financial accounts. U.S. consumers can check reports regularly through AnnualCreditReport.com and should investigate unfamiliar accounts, inquiries, address changes, or collections.
- Expect convincing impersonation attempts. A license image supplies a name, address, birth date, signature, photo, document number, and physical details that can make phishing, account-recovery fraud, and fake support calls more believable.
- Report actual misuse. The federal government directs identity-theft victims to IdentityTheft.gov for a recovery plan and report. Contact the relevant state motor-vehicle agency if a license number or image is being used fraudulently.
A credit freeze cannot stop every misuse of an identity document. It does not prevent phishing, fake-account verification outside the credit system, or attempts to defeat document checks with a real person’s images. It is still one of the strongest immediate steps because it limits a common path from exposed identity data to new financial accounts.
What businesses using ID scanners should audit
Organizations should identify every location, kiosk, app, and vendor that scans IDs, then document exactly which fields and images are collected. The first question is whether the full document needs to leave the device at all. Age checks and access decisions often require a narrow result, not a reusable copy of the credential.
Where collection is necessary, administrators should replace indefinite retention with the shortest defensible period, purge front and back images after the transaction, and keep only the minimum record required for compliance. Contracts should spell out deletion deadlines, subprocessor access, tenant isolation, breach notification, encryption, audit rights, and proof that deletion settings are actually enforced.
The IDScan incident is especially consequential because the compromised material was built to prove that a document was real. Infrared and ultraviolet images, photos, signatures, and document numbers can outlast a password reset. Identity verification reduces fraud only when the evidence used for the check does not become a permanent fraud kit itself.
Sources: IDScan.net incident notice; IDScan VeriScan collection and retention documentation; KrebsOnSecurity investigation; TechCrunch confirmation report; USAGov identity-theft guidance.