Security1 publisher2 min readPublished
IDScan confirms breach in noindexed notice, as reports peg leaked database at 153 million licenses
The company says it learned on or around September 1 that data in customer accounts on its cloud may have been copied, and its notice lists names and ID numbers but not the licence scans Nexus was selling.
The Watch · Security desk

What happened
- Brian Krebs reported on September 1 that a dark-web platform called Nexus was advertising access to more than 153 million U.S. and Canadian driver's licence scans.
- IDScan then published a September 4 notice saying it learned on or around September 1 that certain data in its cloud accounts may have been accessed without authorization.
- TechCrunch found that notice configured with a noindex directive, which instructs search engines not to index the page.
- IDScan says it is cooperating with federal law enforcement, and the FBI confirmed to BleepingComputer that it is investigating the incident.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Businesses across the platform's customer base, from dispensaries to dealerships to gun shops, now owe notifications on records they never held themselves, on a clock that started at a vendor's discovery date.
- constraint A business drafting its own notice from IDScan's stated categories would tell people their name and licence number moved and omit the document image reportedly in circulation.
- decision Anyone buying KYC or age-verification tooling has to treat image retention in the vendor's cloud as a contract term, because it sets the size of the next disclosure rather than the vendor's.
- precedent A notice a search engine is told to skip leaves downstream businesses as the only route by which an affected individual hears about it, which is the route regulators will grade.
The product is why the aggregate exists. IDScan sells technology businesses use to scan, authenticate and extract data from government-issued IDs [13], and its platform is used by car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops and hospitality businesses [14]. Those records sit in accounts on the IDScan.net cloud, which is where the company says an unauthorized third party may have accessed or copied customer information [3]. One platform reaches every vertical.
Add the Nexus listing up. Alongside the 153 million driver's licence scans [10], the service allegedly held 10 million ID cards, 3 million travel documents and 579,000 medical cards [11], or 166,579,000 documents advertised [1]. IDScan has confirmed none of those numbers. Its notice gives categories, not volume, and the categories are full names and driver's licence or other government-issued identification numbers [4]. The licence images themselves, which BleepingComputer reports were also stolen, do not appear in it [5].
The linkage is stronger than the count. Brian Krebs verified samples from the database by searching for his own records and those of people who consented, then traced the exposed information back to IDScan [12]. That establishes provenance. How many records the set actually holds remains uncounted by anyone outside the investigation.
Discovery is dated on or around September 1, the notice September 4, three days later [2][2]. In that window BleepingComputer reported that multiple lawsuits had already been filed [7] while IDScan had neither acknowledged the incident publicly nor answered questions [8]. The notice, when it came, carried a noindex directive [6], so an individual searching to find out whether their licence is in the set would not be served the company's own disclosure.
No intrusion vector is public. IDScan says it took immediate steps to secure its systems and engaged third-party specialists [19], and that it is cooperating with federal law enforcement [17]. IDScan's statement does not say whether a business's own account credentials or API keys were the path in, which leaves credential rotation a precaution rather than a fix.
The company's mitigating detail is that full access to the exposed information required payment, and that it is notifying potentially impacted individuals in an abundance of caution with free credit monitoring and identity protection [9]. Nexus itself went offline once the reporting spread, and BleepingComputer's read is that the criminals likely still have the database [15]; several other actors have since claimed to be selling the entire set, which BleepingComputer could not confirm [16]. Requiring payment sets a price per lookup; how many copies of the set now exist is a separate question the payment wall does not answer.
What to watch
- An amended IDScan notice that confirms a record count would move 153 million from a marketplace listing to a company statement.
- State attorney general filings from IDScan's business customers would show how the notification duty is being split downstream.
- Validation of any actor now claiming to sell the full set would show the copies have spread past the original Nexus operators.