Illustration for: IDScan Confirms Breach Of 153 Million Licenses

IDScan Confirms Breach Of 153 Million Licenses

IDScan.net confirmed hackers stole more than 153 million driver's license records from its cloud systems, including a Cabinet secretary's data, after a dark-web marketplace began selling searchable access in early September.

By the Numbers

153M+
Records exposed
Sep 1, 2026
Krebs first reported
Sep 4, 2026
IDScan's own disclosure
2003, New Orleans
Company founded
21M+
Monthly verifications
TC
By the Markets Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
3 min read
ShareXLinkedInEmail

THE RUNDOWN

1

IDScan.net, a 20-year-old New Orleans identity-verification vendor used by Hertz, FedEx, Target and thousands of cannabis dispensaries and bars, confirmed hackers accessed customer account data covering more than 153 million U.S. and Canadian driver's licenses.

2

Security researcher Brian Krebs first surfaced the breach September 1 after finding a dark-web site called "Nexus" selling searchable access to the full database, including scanned photos; the FBI's New Orleans field office has since opened a formal investigation.

3

The exposed database reportedly includes the driver's license record of U.S. Secretary of Defense Pete Hegseth, illustrating that even high-security individuals' identity documents flow through third-party verification vendors most consumers never interact with directly.

4

IDScan's own disclosure, issued September 4, is notably hedged -- the company said an unauthorized party "may" have accessed data, a posture that has drawn criticism given Krebs had already verified real records days earlier.

TC

The VC Read · Trace's Take

Trace Cohen

The gap between Krebs proving the data was real on September 1 and IDScan's own hedged 'may have been accessed' notice on September 4 is the diligence item here, not the 153-million number -- that's a vendor managing its disclosure timeline, not one that got ahead of the story. For any portfolio company that outsources ID verification to a third party, this is the moment to ask exactly which vendor sits behind that compliance checkbox, because your own breach-notification obligations trigger on their security posture, not yours.

Analysis

IDScan.net, the New Orleans-based identity-verification company used by thousands of retailers, dispensaries and rental-car counters to scan customer IDs, confirmed a data breach exposing more than 150 million driver's license records, TechCrunch reported September 10. The confirmation follows more than a week of reporting after security journalist Brian Krebs first disclosed on September 1 that a dark-web platform called "Nexus" was selling searchable access to a database of more than 153 million U.S. and Canadian driver's license scans, including photos.

Krebs verified the leak was real by searching the database for his own driver's license record and those of others who consented to the test, then traced the data back to IDScan. The company issued its own security notice on September 4, stating it learned "on or around September 1" that certain customer data "may" have been accessed without authorization -- hedged language that undercuts the confirmation IDScan gave TechCrunch nine days later, and a gap that has drawn criticism from security researchers who note Krebs had already proven the data was real and searchable before IDScan's own notice went out.

What was actually exposed

The stolen data includes full names, driver's license numbers and, per multiple reports, identity numbers from other government-issued documents including passports, along with the scanned photos IDScan's systems capture as part of standard age and identity verification. CSO Online reported the database contained records for high-profile individuals, including U.S. Secretary of Defense Pete Hegseth -- a detail illustrating how deeply embedded third-party identity-verification vendors have become in everyday commerce most consumers never think about, since a person doesn't choose which ID-scanning vendor a bar, dispensary or car-rental counter uses.

Founded in 2003, IDScan.net has grown into one of the larger players in a category most people encounter without knowing its name: the company says it processes more than 21 million identity verifications a month across more than 20,000 client locations, with named enterprise customers including Hertz, FedEx and Target alongside thousands of smaller cannabis dispensaries and age-restricted retailers. That scale is exactly what makes a breach here different from a single retailer's data getting stolen -- IDScan sits behind dozens of unrelated brands' compliance workflows simultaneously, so one vendor-level failure fans out across an entire category of consumer-facing businesses at once.

The regulatory response

The FBI's New Orleans field office has opened a formal investigation into the breach. The combination of scale (150 million-plus records), document type (government-issued photo ID) and searchability (a dark-web platform that let buyers look up individuals by name) makes this one of the larger driver's-license-specific breaches publicly reported to date. Unlike a stolen password, which a user can reset, a stolen driver's license number and photo aren't something a person can simply reissue -- state DMVs generally require an in-person or documented process to reissue a license number, and even then the photo and prior number remain compromised indefinitely on any copy already downloaded from the dark-web database.

IDScan's investigation remains ongoing as of publication, and the company has not disclosed how long the exposed data sat accessible before Krebs found it, nor confirmed the root cause of the breach -- both questions the FBI's investigation and IDScan's own forensic review will need to answer before the incident's actual severity, as opposed to its record count, can be assessed. It is the second large third-party security failure Pulse has covered this same week, alongside an AI-driven exploit kit four separate espionage groups deployed within days of each other -- a reminder that vendor-level infrastructure, not just the AI labs themselves, is where a growing share of 2026's security incidents are actually originating. The risk in over-reading the 153-million headline number is treating it as the full picture: it is not yet known how many of those records were actually downloaded by buyers on the dark-web platform versus merely exposed and searchable, a distinction that matters for how many people face real identity-theft risk rather than a theoretical one. A 153-million-record exposure at a single mid-sized verification vendor, rather than at a major bank or platform with dedicated security teams built for that scale, is itself a signal that identity-verification infrastructure has grown faster than the security investment behind it.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.