IDScan.net confirmed on Sept. 4 that an unauthorized third party may have accessed or copied customer information stored in accounts on its cloud platform, including full names and driver’s license or other government-issued identification numbers. The disclosure followed reports that a dark-web service was offering access to a vast cache of identity documents linked to the verification provider.
The company has not said how many people were affected. It also has not confirmed the reported tally of more than 153 million driver’s license records advertised by the dark-web service, known as Nexus. That figure remains a claim assessed by independent reporting, not a number verified in IDScan’s notice.
What IDScan confirmed
IDScan said it received information about possible unauthorized access on or around Sept. 1, secured its systems and brought in third-party specialists. Its investigation remains open, and the company said it is cooperating with federal law enforcement.
IDScan is notifying potentially affected individuals and offering credit monitoring and identity-protection services. The notice identifies full names and government-issued identification numbers as information that may have been exposed, but it does not identify affected customers, establish the intrusion’s duration or describe how the access occurred.
The reported scale remains under review
KrebsOnSecurity reported on Sept. 1 that Nexus claimed to hold more than 153 million U.S. and Canadian driver’s licenses, plus millions of other identification documents. Reporter Brian Krebs said he verified his own license in the database and traced timestamps on several records to transactions involving ID checks. TechCrunch later reported that the FBI confirmed it was looking into the incident.
IDScan’s public notice does not name Nexus, validate its inventory or say that every advertised record came from its systems. Those limits matter because the confirmed facts establish a breach involving highly sensitive identity data, while the precise scale and full chain of custody are still unresolved.
Identity checks create concentrated vendor risk
IDScan markets its verification tools to businesses in retail, hospitality, gaming, transportation and other industries that routinely collect identity documents for age, access or fraud checks. When those records are retained by a third-party platform, the customer experience may appear local while the security and notification exposure is centralized.
For executives, the incident turns identity verification from a compliance workflow into a data-governance question. Buyers need to understand what a vendor stores, for how long, how customer accounts are separated and how quickly a breach can be detected and disclosed. Until IDScan completes its investigation, the number of affected people and the full operational impact remain unknown.
