Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver’s licenses.
Several law firms, including Markovits, Stock & DeMarco, and Hall Attorneys, have also launched investigations into potential class-action litigation related to the reported security incident at IDScan.
Brian Krebs originally reported on September 1 that a dark-web identity-theft service called “Nexus” advertised access to more than 153 million U.S. and Canadian driver’s license scans, 10 million ID cards, 3 million travel documents, and 579,000 medical cards.
Krebs verified the samples by searching the database for his own records and those of other individuals who had consented to the checks, and tracked the leak to IDScan.
IDScan is an identity verification technology company that provides hardware and software solutions for businesses to scan, authenticate, and extract information from government-issued identity documents.
Its systems are used across the U.S. in car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments.
The company has not published any statements about these allegations, and it did not respond to BleepingComputer’s requests for comments.
Currently, it is unclear if IDScan’s systems were compromised or the number of impacted individuals.
Krebs also reported that the FBI’s New Orleans office has launched an investigation into the incident, which Reuters also confirmed independently.
As of publication, the agency has not issued an official statement on the incident and has not responded to our requests for confirmation.
The illegal service Nexus is no longer online. However, cybercriminals still have access to the database.
The lawsuits were filed in Louisiana, where IDScan is based, and allege that IDScan failed to protect information from its clients, such as global car rental company Hertz.
According to Markovits, Stock & DeMarco, IDScan has started to notify some business customers around September 1st.
The law firm says people whose IDs were scanned through businesses using IDScan’s systems may be affected, and is seeking potential claimants for a possible class-action case.
Given the incident’s potential scale, additional lawsuits—including potential class actions—could be filed, and related cases could eventually be consolidated into multidistrict litigation.
State attorneys general and federal regulators could launch separate investigations or enforcement actions, as it has happened with similar-scale data exposures in the recent past, including for 23andMe, Marriott, and Equifax.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

