IDScan admits unauthorized access to cloud data after massive ID leak

Identity verification firm IDScan disclosed that an unauthorized party may have accessed customer data in its cloud platform, including names and government ID numbers. The company is offering credit monitoring and identity protection to affected individuals. The breach is linked to a dark-web database containing over 153 million driver's license scans.
The security notice was published with a noindex tag, which kept it hidden from search engine results until TechCrunch located it. The dark-web marketplace Nexus, which advertised the stolen records, has since gone offline, though the data likely remains accessible to the criminals who acquired it.
IDScan's technology is used across car rentals, retail, and firearms sales. Beyond the 153 million driver's licenses, the leaked cache reportedly contained millions of ID cards, travel documents, and medical records. The FBI is investigating, and several unverified claims of database resale have surfaced.
This incident could have wide-reaching consequences for individuals whose identity documents were exposed, as stolen government IDs may enable long-term identity theft, financial fraud, or unauthorized account creation. Businesses relying on IDScan for verification could face reputational damage and regulatory scrutiny. Affected individuals may need to remain vigilant against phishing and credential-stuffing attacks, since the stolen data could be used to bypass security measures. The breach underscores the systemic risks of centralized identity verification platforms.