Friday, September 11, 2026
Privacy-First Edition
Back to NNN
Technology

Massive hack gives scammers access to over 150 million drivers licenses

Adobe Stock Images See more of our coverage in your search results.

Add The New York Post on Google In one of the most troubling identity theft incidents in recent history, a massive data breach at the ID verification service IDScan has exposed an estimated 153 million personal identity documents.

Unlike typical breaches that leak passwords or credit card numbers, this cyberattack stole ID scans of front-and-back images of driver’s licenses and other identity documents, including non-driver identification cards, travel documents or international IDs, dispensary cards and government access cards.

The sheer scale of the compromised data leaves millions of people vulnerable to long-term identity theft and fraud. Here is what you need to know about the breach and how to protect yourself.

The breach was brought to light by independent cybersecurity journalist Brian Krebs. Krebs was alerted by a source to a new Russian-language cybercrime forum and dark web marketplace known as “Nexus.”

The operators of Nexus boasted they had acquired a huge haul of personal information by continuously exfiltrating sensitive data into a private database for over a year. To verify the legitimacy of the claims, Krebs accessed the dark web service and searched for his own information. He successfully located his own scanned driver’s license, alongside those of several other individuals he contacted to authenticate the leaked files.

The source of the stolen data was traced back to IDScan.net, a Louisiana-based company that provides in-person identity and age verification services. The company provides identity verification technology for major corporations such as Hertz, FedEx, Target, and GameStop, as well as more than 1,000 cannabis dispensaries, car rental agencies and gun shops across 19 states.

Because these businesses rely heavily on IDScan to authenticate government-issued IDs, the company’s databases are a goldmine for cybercriminals. To understand the sheer volume of data flowing through their systems, IDScan reported that it processed a staggering 150 million ID scans in the year 2025 alone.

A Hertz rental car. Adobe Stock Images Was your driver’s license part of the unprecedented IDScan hack? If you have used your driver’s license to verify your identity in the real world or online with any of IDScan’s corporate clients, there is a strong chance your data was captured by Nexus. IDScan hasn’t released a detailed report of exactly who was involved in the data breach, but given the high number of documents stolen, it’s likely that it affected all 50 states.

On September 4, 2026, IDScan published a data security incident notification acknowledging the breach. In their statement, the company noted that on or around September 1, they received information indicating that an unauthorized third party “may have accessed and/or copied certain customer information” stored within its accounts on the IDScan.net cloud platform.

The company stated that the compromised data likely includes full names and driver’s license or other government-issued identification numbers. The dataset includes driver’s licenses primarily belonging to U.S. residents, along with roughly 1.1 million Canadians, as well as 10 million ID cards, 3 million travel documents, and over 579,000 medical cards. The leaked files reportedly feature photographs of the front and back of the licenses, along with ultraviolet and infrared images used for anti-forgery verification.

Upon discovering the breach, IDScan stated that they “took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident.” They are currently cooperating with federal law enforcement, including the FBI. IDScan is notifying potentially impacted individuals “in an abundance of caution” and is providing access to free credit monitoring and identity protection services.

IDScan’s press release appears to downplay the damage by saying the hackers required payment to access the full datasets on the dark web, implying not all the records may have been used by hackers. But that’s cold comfort when your face, address and driver’s license number may be passed around global criminal networks.

Security experts warn that a compromised driver’s license is significantly more dangerous than a stolen credit card. A driver’s license contains your date of birth, home address, physical descriptors, and a government ID number, all useful data bad actors can use to impersonate you to financial institutions. Because you cannot easily change your driver’s license number, victims carry this exposure for life.

To protect yourself from identity theft following the IDScan breach, experts advise taking the following proactive steps:

Assume you are affected: With over 150 million records exposed, the safest course of action is to assume your data is out there. Look out for communications from IDScan or its clients, and immediately enroll in the free credit monitoring and identity protection services being offered.

Freeze your credit: Contact the three major credit bureaus (Equifax, Experian, and TransUnion) to place a freeze on your credit reports to prevent criminals from opening new loans, credit cards, or accounts in your name using your stolen identity documents. Of course, you also won’t be able to open new lines of credit until you unfreeze the reports.

Monitor your accounts closely: Set up real-time transaction alerts for your banking and credit card accounts. Review your monthly statements line-by-line rather than just skimming the balance. Fraudsters often make small, seemingly innocuous test charges before making larger withdrawals.

Enable Two-Factor Authentication (2FA): Secure your sensitive online accounts using 2FA, preferably utilizing biometric logins, authenticator apps or hardware keys rather than SMS text messages, which can be intercepted.

Watch for targeted scams: Armed with your personal information, criminals can craft highly convincing phishing emails or text messages. Be deeply skeptical of unsolicited communications asking for financial details, passwords or payments.

The IDScan breach is a stark reminder of the fragile nature of digital identity verification. Because the stolen information cannot simply be reset or replaced, consumers must remain permanently vigilant. By securing your credit and monitoring your financial footprint, you can help defend yourself against the lifelong consequences of identity theft.

This article was written by Brooklyn-based financial journalist and Commerce Editor for the New York Post Will Kenton. Specializing in investing, personal finance and retirement planning, Will’s expertise is rooted in behavioral economics — a field he explored as associate editor of the New School Economics Review. Will aims to help readers navigate the “predictable irrationality” that influences financial decisions, providing practical real-world solutions to student loan debt, investments, mortgages and more. Before joining The Post in 2026, Will covered the intersection of money, economics and culture for Investopedia, AP News, Business Insider and TIME Stamped.

Read original at New York Post

The Perspectives

0 verified voices · Three viewpoints · Real discourse

Left
0
Be the first to share a left perspective
Center
0
Be the first to share a center perspective
Right
0
Be the first to share a right perspective

Related Stories