153 Million Driver's Licenses Leaked: What the IDScan Breach Means for You

Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

Breach Published September 7, 2026 · 7 min read · By Yongrui Sun
153 Million Driver's Licenses Leaked: What the IDScan Breach Means for You
153 Million Driver's Licenses Leaked: What the IDScan Breach Means for You

A service calling itself Nexus appeared this week on a Russian-language cybercrime forum advertising scans of more than 153 million US and Canadian driver's licenses. To prove the data was real, the operators posted a free sample: a license scan said to belong to US Defense Secretary Pete Hegseth. The FBI's New Orleans field office has opened an inquiry, and researchers tracing the material point to an active intrusion at IDScan, a Louisiana-based identity-verification company. Here is what is known, what is not, and what is actually worth doing about it.

Editor’s take: Our honest advice: skip step three if you're early-stage — it's overkill until you have more than 20 active users. Coming back to it later is faster than doing it twice.

Editor's Take

A leaked licence number is a different problem from a leaked password precisely because it cannot be changed — it is a durable identifier attached to your name and address. That makes it useful for impersonation and for defeating knowledge-based verification long after the news cycle moves on. The practical response is less about this breach and more about assuming the data is permanent: freeze credit, tighten what counts as proof of identity, and watch for follow-on scams.

What Was Taken

According to the sales posting first reported by Krebs on Security, Nexus claims to hold scans of more than 153 million driver's licenses issued in the United States and Canada, alongside over 10 million identification cards, more than three million travel and international identity documents, and roughly 579,000 medical cards. The operators say the material came from a live intrusion at a major identity-verification provider, and that they had been extracting records into a private database for more than a year.

IDScan's own published material describes technology performing more than 21 million identity verifications each month across upward of 20,000 locations worldwide, for clients that include Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. The company also states it handles age and identity checks for more than 1,000 cannabis dispensaries across 19 states.

Two important caveats. The claims have not been independently confirmed, and IDScan has not publicly confirmed a breach, its source, or how many people are affected. The company did tell Krebs that his findings were welcome and helpful to its internal investigation, and later said it is working with law enforcement and forensic experts. The FBI has not released a public statement detailing the scope of its investigation. Treat this as credible and serious, not as settled fact.

Nexus went offline shortly after Krebs published his report, though the disappearance of a marketplace does not mean the underlying data is gone. Multiple law firms have begun investigating potential class-action claims. For anyone keeping score on timelines: Krebs was tipped off on August 31, published on September 1, and the FBI's New Orleans field office opened its formal inquiry the same day.

Why a Leaked License Is Not Like a Leaked Password

Every breach explainer says the same thing: change your password, turn on two-factor authentication, move on. That advice does not work here, and it is worth being precise about why.

You can reset a password in ninety seconds. You cannot reset your face, your date of birth, or the license number printed on a document that banks, lenders, car rental counters, and government services accept as proof that you are you. Since May 2025 the TSA has required a Real ID-compliant license for domestic air travel, which pushed the document into even more verification workflows. A high-resolution scan of it lets someone pass document checks that no password would ever get them past.

The compounding problem is the surrounding data. A license scan on its own is useful; a license scan plus your current address, phone numbers, and relatives' names is a working identity kit. That supporting information is exactly what data brokers sell, and it is the piece that remains publicly available long after a breach is cleaned up.

Who Should Actually Worry

There is no lookup tool yet, so exposure has to be reasoned about rather than checked. You are more likely to be in the dataset if, in the past two years, you have:

In other words: most adults in North America. That is not a reason to panic, but it is a reason to spend one hour this week on the steps below.

Six Things to Do This Week

  1. Freeze your credit at all three bureaus. Equifax, Experian, and TransUnion each offer free freezes. This is the single highest-value action because it blocks most new-account fraud that relies on identity documents. It does not affect your score, and you can lift it temporarily when you legitimately apply for credit.
  2. Ask your state DMV about a new license number. Most states will issue a replacement credential with a different number, though many require a fraud or identity-theft report first. Ask specifically for a fraud flag on your record — it makes impersonation harder later.
  3. Set up IRS and bank account alerts. An IRS Identity Protection PIN prevents someone else from filing a return under your Social Security number. Bank transaction alerts catch the small test charges that precede larger fraud.
  4. Check what data brokers hold on you. Free privacy scans show which people-search sites list your address, phone numbers, and family members — the supporting material that makes a leaked license far more dangerous. PrivacyHawk's free tier runs that scan and includes ten opt-outs a month at no cost.
  5. Watch for targeted phishing, not generic spam. The realistic follow-on risk is credential-stuffing and convincing impersonation: messages that reference your actual address or the state that issued your license. Be suspicious of any unexpected password-reset email or verification-code request.
  6. Consider identity monitoring if your SSN has already been exposed. Dark web and Social Security number monitoring will not undo this breach, but it shortens the time between misuse and discovery, which is the variable that determines how much damage gets done.

Check What's Public About You

The leaked scan cannot be pulled back — but the address, phone, and family data that makes it usable can. Run a free privacy scan and remove what brokers are still selling.

Get PrivacyHawk Compare removal services

The Uncomfortable Part

None of this is caused by anything you did wrong. Your license was scanned because a business was legally required to check it, that business outsourced the check to a vendor, and the vendor's security did not hold. The exposure is a byproduct of a compliance process that now runs at industrial scale — 21 million verifications a month through one company, each one creating another copy of a government document that was never meant to be widely duplicated.

The practical response is unglamorous: reduce what is publicly available about you so that a leaked document has less to attach to, freeze credit so that the document cannot be used to open accounts, and monitor so that misuse gets caught early. Our identity theft protection comparison covers the monitoring side in detail, and our dark web monitoring guide covers the cheaper alerting options if a full monitoring subscription is not in the budget.

YS
Founder & Editor

Yongrui Sun leads the researchers and editors behind this site. We compare tools using vendor documentation and published pricing. We do not run hands-on lab tests and we do not aggregate third-party review scores; ratings reflect our own editorial criteria, documented in our methodology. We do not run hands-on lab tests, and where a figure comes from a vendor or an independent testing lab we say which.

Sources

Claims regarding the source and scope of the leaked data have not been independently confirmed. IDScan had not published a public response at the time of writing.

How we compared

This report is based on public claims about the dataset and the sample published as evidence.

Frequently asked questions

Was my driver's license part of the IDScan breach?

There is no public lookup tool yet. The exposed records are believed to come from IDScan, an identity-verification vendor whose technology performs more than 21 million verifications a month across 20,000+ locations, so anyone who has had a license scanned for age or identity checks at a retailer, rental company, dispensary, or financial institution could be included. Treat it as possible exposure and act accordingly.

Can I get a new driver's license number?

In most US states you can request a replacement license with a new number, though you will usually need to report identity theft or fraud first, and the process varies by state. Contact your state DMV or licensing agency and ask specifically about a new credential number or a fraud flag on your record.

Why is a leaked license scan worse than a leaked password?

You can change a password in a minute. A license number and the high-resolution image on it are tied to your face, address, and date of birth, and they are accepted as proof of identity by banks, lenders, and government services. A scan lets a fraudster pass document-verification checks that a password alone would never get past.

Should I freeze my credit after this breach?

Yes, if you believe your license may be included. A credit freeze at Equifax, Experian, and TransUnion is free, does not affect your credit score, and blocks most new-account fraud that uses your identity documents. You can lift it temporarily when you legitimately need to apply for credit.

Can a data removal service help after a license leak?

It helps with a different half of the problem. Removal services cannot pull a leaked scan back, but they reduce the supporting data — home address, phone numbers, relatives' names — that fraudsters combine with a license image to pass verification. Free scans exist, so you can check your exposure before paying.

153 Million Driver's Licenses Leaked: What the IDScan Breach Means for You — comparison snapshot
153 Million Driver's Licenses Leaked: What the IDScan Breach Means for You — comparison snapshot