Identity verification provider IDScan.net is facing multiple class-action lawsuits following reports that a massive database containing approximately 153 million driver’s license scans was offered for sale on the dark web. The legal actions, led by firms including Markovits, Stock & DeMarco, LLC and Hall Attorneys, follow a major security incident involving a dark web service known as “Nexus.”
The FBI’s New Orleans field office has reportedly opened an inquiry into the situation. While IDScan.net has not officially confirmed a breach, the company stated it is investigating the incident. The scale of the exposure is significant, reportedly encompassing records for the vast majority of U.S. drivers and approximately 1.1 million records from Canada.
Unlike standard password leaks, the data allegedly exposed in this incident is permanent and high-fidelity. The “Nexus” database reportedly included high-resolution front-and-back images of licenses, along with infrared (IR) and ultraviolet (UV) scans used by businesses to verify the authenticity of government documents. Because driver’s license numbers and biometric images cannot be easily changed or “reset” like a password, the long-term risk of identity theft for affected individuals is substantially higher.

Verification and High-Profile Targets
The legitimacy of the data was supported by independent research from journalist Brian Krebs, who identified his own license scan and that of his mother within the Nexus database. The records included timestamps that correlated exactly with car rental transactions at Hertz. Other records in the database have been linked to transactions at marijuana dispensaries, such as Planet13, where ID scanning is often a legal requirement for entry or purchase.
The exposure also reportedly includes sensitive data belonging to high-ranking government officials. Among the records found in the Nexus database was a scan of the driver’s license of U.S. Secretary of Defense Pete Hegseth, highlighting the broad reach of the vendor’s data collection across different sectors of public and private life.
Supply Chain Risks and Vendor Denials
The incident underscores the growing risks associated with third-party identity verification. Businesses across retail, hospitality, and travel rely on these vendors to automate compliance and fraud prevention, often without consumers realizing their sensitive government IDs are being stored by a middleman.
As news of the breach spread, several major companies listed as partners or clients on the IDScan.net website moved to distance themselves from the vendor. Target and Caesars Entertainment have issued statements clarifying that they either do not currently share guest data with the company or have not utilized the service for several years. This suggests the leaked database may contain historical data or that the vendor’s public client list may be outdated.
The lawsuits filed against IDScan.net argue that the company failed to implement industry-standard security measures to protect the highly sensitive information it collected. According to reporting from CSO Online, the legal backlash signals a shift in how courts and regulators view the liability of third-party data processors who handle government-issued identification and biometric data.
Security analysts warn that the data remains in the hands of cybercriminals and may be used for sophisticated social engineering and identity fraud for years to come. Drivers concerned about their data are advised to monitor their credit reports and remain vigilant against phishing attempts that leverage specific personal details found on a driver’s license.
