Major Identity Verification Firm Exposes Over 150 Million Driver's Licenses in Massive Cyberattack

Major Identity Verification Firm Exposes Over 150 Million Driver's Licenses in Massive Cyberattack

2026-09-11 companies

New Orleans, Thursday, 10 September 2026.
Identity provider IDScan confirmed a major cybersecurity breach exposing over 150 million driver’s licenses, triggering an FBI investigation and highlighting severe enterprise risks in third-party customer data retention.

Confirmation and Scope of the Data Exposure

Identity verification provider IDScan.net has confirmed a significant cybersecurity incident resulting in the unauthorized exposure of sensitive government-issued records [1]. The breach involves more than 150 million driver’s licenses and full names, according to company statements released in early September 2026 [2]. The compromised database reportedly includes high-resolution scans of identification documents, such as passports and medical cards, which were advertised on a dark-web marketplace known as Nexus [3]. While IDScan.net maintains a repository of over 150 million driver’s license records, the company has not yet disclosed the specific number of affected individuals as the investigation remains ongoing [1]. The exposed data allegedly contains full names, addresses, dates of birth, license numbers, issuing jurisdictions, and photographs [2]. Security researchers linked the data to IDScan.net after timestamps and transaction histories from the Nexus marketplace pointed to businesses using IDScan tools [3]. This incident highlights growing operational vulnerabilities for enterprise clients relying on third-party identity management platforms to handle customer identification data [1].

Timeline of Discovery and Federal Response

IDScan.net detected unauthorized access to its data on or around September 1, 2026, and subsequently engaged third-party forensic specialists to assist in the investigation [2]. On September 2, 2026, the Pentagon confirmed awareness of the breach, and the FBI initiated a formal investigation into the incident [1]. The FBI’s New Orleans field office opened its inquiry around the same time the breach was detected, following reports linking the data to the company [8]. Although IDScan.net issued a formal written statement on September 8, 2026, confirming the discovery date, the company initially characterized the event as a potential security incident rather than a confirmed breach [2]. Federal law enforcement confirmed the investigation was active as of September 9, 2026, though the dark-web site previously hosting the stolen data has since been removed [5]. Despite the removal of the marketplace listing, cybercriminals likely retain copies of the compromised data, which reportedly included front-and-back scans in conventional, infrared, and ultraviolet formats [3]. As of September 10, 2026, there have been no confirmed reports of direct notification to affected individuals by IDScan.net, a requirement under most state breach-notification laws [2].

The cybersecurity incident has triggered a rapid legal response, with at least eight federal lawsuits filed against IDScan.net in the U.S. District Court for the Eastern District of Louisiana by September 7, 2026 [7]. By September 9, 2026, the number of class-action lawsuits filed in the U.S. against IDScan had increased to over a dozen [5]. The lawsuits allege negligence, breach of implied contract, fraud, and unjust enrichment, with plaintiffs seeking damages and injunctive relief to overhaul the firm’s internal security practices [7]. Companies identified as using IDScan.net’s identity-verification technology include Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, Jack Henry, and GameStop [7]. Legal experts anticipate that the existing suits will likely be consolidated, potentially through coordinated case management or formal multidistrict litigation if additional suits arise outside the district [8]. This breach has intensified scrutiny on identity-verification vendors, forcing enterprise clients to re-evaluate data retention policies, encryption standards, and third-party liability agreements [7]. Experts anticipate an increase in class-action filings within the next two to three weeks, with state attorneys general expected to open inquiries regarding the company’s notification timeline and data retention practices [2].

Sources


Cybersecurity Data Breach