Hackers Leak 153M Driver’s Licenses Via IDScan.net Breach
Hackers accessed live IDScan.net data streams for 13 months, leaking 153 million IDs.
Why it matters: Legal tech firms use identity verification services like IDScan.net, which now show serious vulnerabilities. This breach highlights urgent security gaps in protecting sensitive personal data essential for compliance and risk management.
- 153 million U.S. and Canadian driver’s licenses and IDs exposed on a Russian cybercrime forum starting in late 2022.
- FBI’s New Orleans field office opened an investigation into the breach in early 2024.
- Data included IDs linked to at least one known individual, U.S. Secretary of Defense Pete Hegseth.
- Security journalist Brian Krebs reported that Nexus searches reveal about 11.5 million leaked entries tied to the breach.
- IDScan.net provides verification services to firms including Hertz and Planet13 and has launched an active internal security review.
Hackers gained continuous access to IDScan.net’s live data feed—a stream of scanned driver’s licenses and identity documents—from around November 2022 to December 2023. This means the attackers viewed identity data in real time as IDs were scanned by customers.
The breach exposed approximately 153 million records involving U.S. and Canadian citizens. Among the leaked information were details linked to at least one high-profile individual: U.S. Secretary of Defense Pete Hegseth. This identifies that sensitive personal data of government figures, alongside ordinary individuals, was compromised.
Users of IDScan.net’s identity verification service include well-known businesses like Hertz rental cars and cannabis retailer Planet13. The intrusion represents significant risks for diverse sectors relying on third-party authentication.
The FBI’s New Orleans field office publicly confirmed it opened an investigation into the incident in February 2024. Authorities are working to understand the breach's full scope and impact.
Security reporter Brian Krebs’s analysis, citing Nexus search data, estimated 11.5 million individual pages of ID entries were leaked, underscoring the breach's vast scale and long duration.
In response, IDScan.net voluntarily commenced an internal security review and notified impacted clients. They emphasized steps to harden their systems and prevent similar unauthorized access.
For legal professionals, this incident exemplifies the inherent risks in relying on third-party digital identity verification tools. Given growing regulatory scrutiny on data protection, law firms and corporations must actively evaluate vendor security and enhance contractual safeguards governing sensitive personal information.
By the numbers:
- 153 million — estimated number of U.S. and Canadian IDs leaked
- 11.5 million — approximate number of leaked individual ID pages found via Nexus searches
- 13 months — duration of hacker access to live data streams at IDScan.net
Yes, but: IDScan.net has taken steps to investigate and mitigate risks, but full breach consequences and affected individuals remain unclear.
What's next: FBI investigation is ongoing with no public timeline; IDScan.net plans further security audits and client notifications over coming months.