Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available for sale on a dark web marketplace. The company acknowledged the breach in a notice published on September 4, stating that it became aware of the unauthorized access around September 1, coinciding with reports from cybersecurity journalist Brian Krebs regarding dark web activity.
According to the announcement, an unauthorized third party may have accessed and copied customer information stored within IDScan’s cloud platform. The compromised data may include full names and government-issued identification numbers. However, IDScan did not disclose the number of customers affected by the breach.
The incident gained public attention when Krebs reported that a dark web marketplace known as Nexus was offering access to the driver’s license scans of Canadian and U.S. citizens. In addition to the driver’s licenses, the breached database reportedly contains scans of 10 million identification cards, over three million travel documents, and at least 579,000 medical cards. Krebs was able to authenticate samples of the database by searching for his own records listed for sale on Nexus.
Despite the severity of the breach, IDScan’s announcement appeared to downplay the incident, suggesting that the data was not being made freely available to malicious actors. The company stated, “Though full access to the information required payment, in an abundance of caution, we are notifying potentially impacted individuals of this incident and providing access to free credit monitoring and identity protection services.” The FBI has launched an inquiry into the breach, and IDScan is currently facing several lawsuits related to the incident.
For further details, refer to the report by The Record.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



