IDScan Data Breach: 153 Million Driver's Licenses Were Searchable. What Do You Do Now?

IDScan Data Breach: 153 Million Driver’s Licenses Were Searchable. What Do You Do Now?

Somewhere in this file is a man who handed his driver’s license to a bartender in Las Vegas last spring. The bartender ran it through a scanner, the scanner sent it to a company he had not heard of, and that company kept a copy. His full name, his license number, his date of birth, his home address and the photo on the card now sit in one record on a criminal search site, where anyone with an account could type his name and see it. He did not sign up for anything. He showed ID to buy a drink.

Confirmation: confirmed by the company. IDScan.net posted a notice saying an unauthorized party “may have accessed and/or copied” customer information on its cloud on or around 1 September 2026. The 153 million figure is the criminals’ own claim for their search service, verified in samples by a security reporter; IDScan has not published a count.

What happened

On 1 September 2026, security reporter Brian Krebs found a dark-web service called Nexus selling searchable access to what it claimed were more than 153 million US and Canadian driver’s license records, and traced the source to IDScan.net. IDScan is a Louisiana company whose scanners and software check identity documents for bars, casinos, car-rental counters, cannabis dispensaries and retailers. When a clerk scans your license, IDScan reads it, and for many customers it stores what it read.

The timeline, from Krebs on Security, TechCrunch and IDScan’s own notice:

  • 1 September. Krebs published his investigation. A blank search on Nexus returned about 11.5 million pages of results. Records showed name, address, date of birth, license number and, where available, the photo. He confirmed the data was real by finding his own license in it, and coordinated with others who found theirs, including the US Secretary of Defense. The site said it was adding roughly 400,000 to 500,000 records a day. Nexus went offline within hours of the article.
  • On or around 1 September. IDScan says this is when an unauthorized third party accessed customer accounts on its cloud. It says it has secured its systems, brought in outside investigators and is working with federal law enforcement.
  • 2 September. TechCrunch reported that the source appeared to be IDScan, whose customers it described as major tech and consumer brands. Krebs named Hertz, Target, FedEx, Caesars Entertainment, Motorola Solutions, Jack Henry and the dispensary chain Planet 13, and said IDScan handles ID checks for more than 1,000 dispensaries in 19 states.
  • 4 September. IDScan dated its public notice, describing the data as “full names and driver’s license or other government-issued identification numbers.”
  • 10 September. IDScan confirmed the breach to reporters, saying its investigation was ongoing.

The count is the criminals’ figure, not IDScan’s. Nexus advertised 153 million driver’s licenses plus 10 million ID cards, 3 million travel documents and 579,000 medical cards. That is what the sellers claimed to hold; the samples reporters checked were real, but nobody outside the criminal group has counted the whole set, and IDScan has not said how many people or which of its customers are affected. Treat 153 million as the size of the claim, not a confirmed number of victims.

IDScan says it is offering free credit monitoring and identity protection, with a call line at 1-833-516-2980 on weekdays.

What was exposed

IDScan confirms names and driver’s license or government-ID numbers. Krebs saw addresses, dates of birth and license photos in the records for sale, so for many people the record is the whole front of the card. No email addresses and no passwords are in either account of the data.

What each item is worth to a criminal:

  • Your license number with your name and date of birth. The three fields a lender, a phone carrier or a DMV website uses to confirm you are you. With them, someone can open an account, take over a phone number, or get a replacement card mailed to an address they control.
  • Your photo. The piece that gets a fake ID past a human. A forged card with your real number and your real face passes a scan and a glance.
  • Your home address. Where the fraudulent mail goes, and the detail that makes a scam call sound like it comes from your bank or your state.
  • Where you were scanned. IDScan’s customers are casinos, dispensaries and rental counters. A record that says which one you visited is leverage on its own.

No password leaked here, and no email address. So the risk is not that someone signs in to your accounts with this file. It is that someone pairs it with an email address from an older breach and impersonates you, or impersonates the DMV to you.

What to do now

Most of this has nothing to do with OptMsg, and the important part takes fifteen minutes.

1. Freeze your credit at Equifax, Experian and TransUnion. It costs nothing, and it stops a new account being opened with your name, date of birth and license number. This is the single step that answers most of what this file enables. Lift it when you apply for something yourself. 2. Check your driving record with your state. Most DMVs let you view it online. A ticket or a license reissue you did not request means someone is using your number. 3. Expect the follow-up phish to look like the DMV, a state agency, a casino loyalty program or a rental company. “Your license has been flagged,” “verify your identity to keep your account,” “claim your credit monitoring.” Do not follow links in them. IDScan’s real offer is on its own website and its call line, not in an email. 4. Put a PIN on your mobile account. A leaked license is a standard tool for the phone-store visit that ends in a SIM swap. Every US carrier offers a port-out or account PIN. 5. Turn on the strongest sign-in each account offers, starting with your email account. It is the reset route into everything else. A passkey where available, an authenticator app otherwise, and a password manager so each account has its own password. 6. Ask before you scan. You usually cannot refuse an age check, but you can ask whether the venue stores the scan. Some states already limit what a bar may keep from a scanned license. 7. If a fake ID in your name surfaces, file a report with your state police and the FTC at identitytheft.gov so the paper trail starts with you.

How OptMsg changes this exposure

Honestly, and at its real size: OptMsg would not have prevented this breach. It happened at IDScan, in a cloud account you had no say in, holding a card you were required to show. Your email address is not in this file. What an opt-in inbox changes is the step where a criminal turns this record into contact with you.

Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the “your license has been flagged” email, sent to an address paired with this record from some older breach, lands in Trash, where you are not reading it under time pressure. Your real state agency reaches your Inbox once you approve it as a sender. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert so that a genuine message is not lost.

The password point is smaller here than usual, because no password leaked. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. If someone matches this record to an email address and a password from an old breach, the pair opens nothing at OptMsg. That keeps the reset route into your other accounts shut while you deal with the license itself.

What that does not cover: a forged card with your face on it, a phone call from “the DMV,” a text to your number, a phishing page you open yourself, or someone with your unlocked phone. Those are the steps above, and the credit freeze does most of the work.

If you want the next breach’s follow-up mail to land in Trash instead of in front of you, see how Simple by Design works, or read why your inbox should not care about a leaked password.

Ready for an inbox that stays quiet after a breach? Create Your Account.

Your Inbox. Your Rules.

Frequently asked questions

How do I know if I am in the IDScan data breach? There is no public lookup. IDScan has not published a list of affected customers, and the data holds no email addresses, so Have I Been Pwned cannot index it. If you have had your license scanned at a casino, a dispensary, a bar, a car-rental counter or a large retailer in the US or Canada in recent years, assume you may be in it and freeze your credit.

What was stolen in the IDScan breach? IDScan confirms full names and driver’s license or other government-ID numbers. The records seen for sale also showed home addresses, dates of birth and license photos. No passwords and no email addresses.

Is the 153 million figure confirmed? No. It is the number the criminal search service advertised. Reporters verified samples were real, including their own licenses, but IDScan has not given a count of affected people.

Can someone use my driver’s license number to steal my identity? Yes. With your name, date of birth and license number, someone can pass the identity checks used by lenders, phone carriers and some state websites. A credit freeze at all three bureaus and a PIN on your mobile account close most of that.

Would OptMsg have stopped this? No. The breach happened at IDScan, and your email address is not in the file. What OptMsg changes is the aftermath: mail from a sender you have not approved goes to Trash rather than your Inbox, and there is no password on an OptMsg account for a leaked credential to match.

Sources

Scroll to Top