Breach Alert: The IDScan Data Breach and 153 Million Stolen Driver's Licenses

A major breach of driver's licenses and passports from IDScan was disclosed. Here's the next steps you should take, and how Papaya Privacy can help.
Andrew L.

If you've ever rented a car, checked into a hotel, verified your age at a dispensary, or opened an account with a company that needed to confirm "yes, this is really you," there's a good chance your driver's license passed through IDScan.net at some point. That's worth knowing, because IDScan just confirmed one of the largest identity-document breaches on record — and unlike most breaches, this one didn't just expose numbers. It exposed the ID itself.

What happened

IDScan.net is a New Orleans-based identity verification company that processes more than 21 million ID checks a month at over 20,000 locations, for clients that include Hertz, Target, FedEx, Caesars Entertainment, and cannabis dispensary chains like Planet 13. On September 1, 2026, a dark web marketplace called "Nexus" began advertising searchable access to what turned out to be IDScan's own database. The listing grew by hundreds of thousands of records a day, a sign that data was still being pulled out even as the site was live.

The FBI's New Orleans field office opened an investigation, and by September 2 the Nexus listing had disappeared from the forum where it was posted. IDScan issued a security notice on September 4 and confirmed the breach publicly on September 8, after security journalist Brian Krebs reported on it and verified his own scanned license was in the stolen data.

What was exposed

This breach is unusual for how complete the stolen records are. Rather than just a name and a number, Nexus was reportedly selling:

  • More than 153 million U.S. and Canadian driver's license scans, front and back
  • Over 10 million other ID cards, including infrared and ultraviolet scan versions
  • More than 3 million passports and other travel documents
  • Nearly 580,000 medical and dispensary access cards
  • Full names, government ID numbers, and personal photos tied to each record

In other words, this isn't just enough data to guess your identity — it's enough to reproduce a convincing copy of your ID. That's a meaningfully different (and more dangerous) kind of exposure than a typical breach of names and Social Security numbers, because a license number, a photo, and a matching name is exactly the combination that lets someone pass an identity check, open an account, or talk their way past a support agent who asks "can you confirm the name on the ID?"

Why it matters

IDScan exists specifically to help other companies verify identity — which means the same data that was supposed to stop fraud is now circulating among the people most likely to commit it. Stolen license data like this tends to have a long tail: it gets bundled, resold, and cross-referenced with information already sitting on data broker and people-search sites, making it easier for someone to build a full profile on you well after this particular headline fades. There's no evidence yet that any specific individual's data has been misused, but with a marketplace already built and records still growing before it was taken down, it's only a matter of time.

How Papaya Privacy helps with exactly this

This is the kind of breach our dark web monitoring was built for — and it's also why we recently expanded what you can monitor. Beyond the standard email addresses and SSNs, Papaya Privacy users can now add additional identifiers to their profile, including driver's license numbers, passport numbers, and other government ID numbers. Once it's added, we continuously scan dark web marketplaces and breach dumps for that specific information and alert you the moment it turns up — including in incidents like the IDScan breach.

Pair that with our data removal service, which scrubs your information from 350+ data broker and people-search sites, and you've got both the early-warning system and the cleanup: monitoring catches the breach the moment your data appears for sale, and removal keeps that same data from quietly accumulating on broker sites in the meantime. Papaya Privacy plans also include $1 million in identity theft insurance and hands-on restoration support if the worst does happen.

If you haven't already, this is a good moment to log in and add your driver's license number and passport number to your monitoring profile — it takes about a minute, and it's exactly the kind of exposure this week's news is about.

What to do now

  1. Check whether you were notified. If you've used a service where IDScan verifies IDs — car rentals, certain retailers, dispensaries, casinos — watch for a notification. IDScan says it's offering free credit monitoring to affected individuals.
  2. Freeze your credit at all three bureaus (Equifax, Experian, TransUnion). It's free and it's the single most effective step against someone opening new accounts in your name.
  3. Ask your state DMV about your options. Some states allow you to request a new license number if yours has been compromised — worth a call if you're concerned.
  4. Be skeptical of "verify your identity" requests. With real license images circulating, scammers can be far more convincing when they ask you to "confirm" personal details over phone, text, or email.
  5. Watch specifically for your driver's license number, not just your SSN. Most monitoring tools are built around Social Security numbers and credit files. This breach is a reminder that your license number is its own valuable target.

Sources: TechCrunch, Krebs on Security, BleepingComputer

Safe and Secure

PCI Compliant
SOC2 Compliant
HIPAA Compliant
Privacy Protection Shield

Why choose Papaya Privacy?

Data brokers, or people search sites, pose significant risks, including identity theft, financial fraud, robocalls, spam, doxxing, stalking, and harassment. Removing your data from these sites is crucial but time-consuming.
Learn More