IDScan.net Breach Leaks 153 Million Driver's Licenses

IDScan.net Confirms Breach; 153M Driver's Licenses for Sale Online

CRITICAL
September 19, 2026
October 11, 2026
5m read
Data BreachCloud Security

Impact Scope

People Affected

153 million

Industries Affected

TechnologyRetailHospitality

Geographic Impact

United StatesCanada (regional)

Related Entities(initial)

Other

IDScan.netNexus

Full Report(when first published)

Executive Summary

Identity verification provider IDScan.net has confirmed it was the victim of a major data breach that resulted in the theft of a database containing over 153 million U.S. and Canadian driver's licenses. The confirmation came after the massive dataset was advertised for sale on a dark web marketplace called 'Nexus.' The company stated that on September 1, 2026, it identified unauthorized access to its cloud platform where customer-provided identification data was stored. The breach exposes millions of individuals to a high risk of identity theft and fraud. The FBI is reportedly investigating the incident.


Threat Overview

The incident appears to be a classic case of a cloud storage breach. An unauthorized third party gained access to IDScan.net's cloud environment and exfiltrated a huge trove of sensitive data. This data was subsequently put up for sale on the 'Nexus' dark web forum, a common tactic for monetizing stolen information. A journalist was able to verify the data's authenticity by finding their own driver's license among the samples offered by the threat actor.

IDScan.net provides identity verification services to a wide range of industries, including retail and car rentals, which require customers to scan their driver's licenses.

Technical Analysis

The core of the incident was the compromise of IDScan.net's cloud platform. While the specific method of unauthorized access was not disclosed, this type of breach often stems from misconfigured cloud storage (e.g., a public S3 bucket), stolen credentials, or a vulnerability in a cloud-hosted application. This is a form of T1530 - Data from Cloud Storage.

The stolen database contains highly sensitive Personally Identifiable Information (PII), including:

  • Full names
  • Driver's license numbers
  • Other government-issued ID numbers
  • Scanned images of the identification documents

The dataset for sale reportedly contained:

  • 153 million driver's licenses
  • 10 million ID cards
  • 3 million travel documents (e.g., passports)

Impact Assessment

The impact of this breach is critical and far-reaching.

  • Mass Identity Theft: With full names and scans of government IDs, criminals have all the information needed to perpetrate sophisticated identity theft, open fraudulent lines of credit, file fake tax returns, and bypass identity verification checks at other services.
  • National Security Risk: As highlighted by Lawfare, a centralized database of this many identity documents is a goldmine for foreign intelligence agencies for tracking individuals, creating fake identities for operatives, and conducting espionage.
  • Impact on IDScan.net: The company faces severe reputational damage, loss of customer trust, and potential legal and regulatory consequences. The company is offering credit monitoring services to affected individuals.

IOCs — Directly from Articles

Type
other
Value
Nexus
Description
The name of the dark web marketplace where the stolen data was listed for sale.

Cyber Observables — Hunting Hints

For organizations managing large PII databases in the cloud, hunting should focus on detecting unauthorized access and exfiltration:

Type
log_source
Value
Cloud Trail / Audit Logs
Description
Monitor for anomalous API calls such as ListBuckets, GetObject, or CreatePresignedUrl from unexpected users, roles, or IP addresses.
Type
network_traffic_pattern
Value
Large data egress from storage
Description
Configure alerts for unusually large data transfers out of cloud storage buckets, especially to non-corporate IP addresses.
Type
other
Value
Public storage exposure
Description
Regularly run automated scans to detect publicly accessible cloud storage buckets or databases.
Type
user_account_pattern
Value
Dormant account activity
Description
Monitor for any activity from IAM user or service accounts that have been inactive for a long period.

Detection & Response

  • Detection: Implement a Cloud Security Posture Management (CSPM) tool to continuously scan for misconfigurations. Use a Cloud Workload Protection Platform (CWPP) to monitor for threats within cloud environments. Enable and analyze cloud provider logs (e.g., AWS CloudTrail, Azure Monitor) to detect suspicious API activity. This aligns with D3FEND Cloud Storage Access Logging.
  • Response: IDScan.net has engaged third-party forensic specialists, notified law enforcement (FBI), and is in the process of notifying affected individuals. For affected individuals, accepting the offer of free credit monitoring, placing a freeze on their credit reports with all major bureaus (Equifax, Experian, TransUnion), and being vigilant for phishing attacks are critical next steps.

Mitigation

To prevent similar breaches, organizations handling sensitive PII in the cloud must implement a defense-in-depth strategy:

  1. Secure Cloud Configuration: Enforce strict access controls on all cloud storage. Disable public access by default and use fine-grained IAM policies to grant access on a need-to-know basis. (M1054 - Software Configuration).
  2. Data Encryption: Encrypt all sensitive data both at rest and in transit. Use customer-managed encryption keys (CMEK) for an additional layer of control. (M1041 - Encrypt Sensitive Information).
  3. Multi-Factor Authentication (MFA): Enforce MFA for all user and administrative accounts that can access the cloud management console or sensitive data. (M1032 - Multi-factor Authentication).
  4. Data Minimization: Only collect and retain the minimum amount of PII necessary for business operations. Securely delete data that is no longer needed.
  5. Continuous Monitoring: Implement and actively monitor alerts from cloud security tools for signs of misconfigurations or unauthorized access.

Timeline of Events

1
September 1, 2026
IDScan.net becomes aware of unauthorized access to its cloud platform.
2
September 10, 2026
News of the breach and the data being for sale on the dark web becomes public.
3
September 19, 2026
This article was published

Article Updates

October 11, 2026

Lawsuits against IDScan.net double to 19 following data breach, alleging negligence.

MITRE ATT&CK Mitigations

Properly configuring cloud storage access controls, such as disabling public access, is fundamental to preventing this type of breach.

Mapped D3FEND Techniques:

Encrypting data at rest in cloud storage can make the data unusable to an attacker even if they manage to exfiltrate it.

Mapped D3FEND Techniques:

Enforcing MFA on all cloud administrative accounts makes it much harder for attackers to gain initial access via stolen credentials.

Mapped D3FEND Techniques:

Audit

M1047enterprise

Continuously auditing cloud logs for anomalous access patterns or configuration changes is critical for early detection.

Mapped D3FEND Techniques:

Timeline of Events

1
September 1, 2026

IDScan.net becomes aware of unauthorized access to its cloud platform.

2
September 10, 2026

News of the breach and the data being for sale on the dark web becomes public.

Sources & References(when first published)

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachCloud SecurityPIIIdentity TheftDriver's LicenseDark Web

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.