Practical ideas. Real strategies. Better income. Subscribe
AI & Technology

IDScan Data Breach: 153 Million Driver’s License Scans Were Advertised for Sale—What You Should Do Now

Driver’s license dissolving into digital data beside headline about 153 million licenses advertised for sale

IDScan data breach concerns are growing after a dark-web identity service advertised access to more than 153 million driver’s license scans from people in the United States and Canada.

The number is enormous.

But there is an important distinction between what has been reported and what IDScan itself has confirmed.

IDScan.net, a company that provides identity-verification and ID-scanning technology, has confirmed that an unauthorized third party may have accessed or copied customer information stored in accounts on its cloud platform.

The company says the affected information may include full names and driver’s license or other government-issued identification numbers.

IDScan has not publicly confirmed that 153 million people were affected.

That figure came from a dark-web service advertising the stolen records and was subsequently investigated by cybersecurity journalist Brian Krebs and federal law enforcement.

The FBI has said it is investigating.

For consumers, the practical question is not simply how large the breach ultimately turns out to be.

It is:

What should you do if information from your driver’s license may now be in the hands of criminals?

What Happened in the IDScan Data Breach?

On September 4, IDScan published a notification of a data security incident.

The company said that on or around September 1, it received information indicating that certain data may have been accessed without authorization.

IDScan said it took steps to secure its systems and brought in third-party specialists to investigate.

According to the company:

An unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud.

IDScan said the affected information may include full names and driver’s license or other government-issued identification numbers.

The investigation remains ongoing.

The company also said it is cooperating with federal law enforcement and is notifying potentially affected individuals.

Where Does the 153 Million Number Come From?

This is where the story requires careful wording.

The figure of more than 153 million driver’s licenses did not come from IDScan’s breach notice.

It came from a dark-web identity service called Nexus, which reportedly advertised access to an enormous database of government-issued identification documents.

Cybersecurity journalist Brian Krebs first detailed the discovery in his report, “FBI Probes Service Selling 153M+ Drivers Licenses.”

According to Krebs’ reporting, the service claimed to possess more than 153 million driver’s license records from the United States and Canada, along with millions of other identification and travel documents.

Krebs did more than simply repeat the seller’s claim.

He searched the database and found his own driver’s license.

He also worked with other people to verify that additional records appeared authentic.

Reuters reported that the FBI was investigating and that Krebs had authenticated records with multiple individuals.

The dark-web service disappeared shortly after the reporting became public.

That still does not mean every one of the claimed 153 million records has been independently verified.

The safest way to describe the situation is:

IDScan has confirmed unauthorized access to data in its cloud. A dark-web service separately claimed to have more than 153 million U.S. and Canadian driver’s license scans.

Why Driver’s License Data Is Different From a Typical Password Leak

Many data breaches involve email addresses and passwords.

Those can be serious, but passwords have one major advantage:

You can change them.

A driver’s license is different.

It contains identity information intended to prove who you are.

Depending on the document and what was stored, that can include information such as:

  • your full name;
  • driver’s license number;
  • address;
  • date of birth;
  • photograph;
  • issuing state;
  • expiration information;
  • and other identifying details.

IDScan’s public notice specifically confirms that affected information may include full names and government-issued identification numbers.

It does not publicly confirm every type of information reportedly offered by the dark-web seller.

That distinction matters.

But even a name paired with a valid driver’s license number can be valuable to criminals attempting identity fraud or social engineering.

Why Someone Might Have Your IDScan Data Without Knowing IDScan

One unusual aspect of an identity-verification provider is that consumers may interact with its technology without thinking of themselves as direct customers.

You might hand your driver’s license to a business.

That business may use a third-party system to scan, authenticate or verify the document.

You may never notice the name of the technology provider involved in the process.

That makes this kind of breach different from losing data at a company where you knowingly created an account.

You cannot necessarily determine your exposure simply by asking:

“Have I ever visited IDScan.net?”

Many people potentially affected by an identity-verification breach may never have personally visited the vendor’s website.

That is one reason official notification matters.

IDScan says it is contacting potentially affected individuals as its investigation continues.

IDScan Is Offering Free Identity Protection

IDScan says it is providing potentially affected individuals with access to free credit-monitoring and identity-protection services.

The company has published enrollment information in its official breach notice.

If you receive a legitimate notification that you were affected, free monitoring can be useful.

Credit monitoring can alert you when certain changes appear on your credit file.

But monitoring and prevention are not the same thing.

A monitoring service may tell you that suspicious activity has occurred.

A credit freeze can make certain types of new-account fraud harder to carry out in the first place.

That is why understanding the difference matters.