Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Apple Watch Series 12 and Ultra 4 Preorders Are Live: Here Is What the Market Data Says About This Launch

    September 11, 2026

    Nvidia Spent About $20 Billion Without Buying Anything. The DOJ Wants to Know If That Was the Point.

    September 11, 2026

    Anthropic Blamed a Bug When Claude Hacked Real Companies. Now It Says the Model Talked Itself Into It.

    September 11, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • Gaming
    • Smartwatch
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»153 Million Driver’s Licenses Went Up for Sale. The Company That Scanned Them Just Confirmed the Hack.
    Tech News

    153 Million Driver’s Licenses Went Up for Sale. The Company That Scanned Them Just Confirmed the Hack.

    Marcus BennettBy Marcus BennettSeptember 11, 20268 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Digital padlock over computer circuitry representing a Windows kernel security vulnerability
    Photo: Pexels
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    For nine days, the story lived in that uncomfortable space where a company says nothing and a dark web listing says everything. On September 1, security journalist Brian Krebs reported that a newly launched marketplace was advertising more than 153 million driver’s license scans, and the trail appeared to lead back to IDScan.net, the New Orleans company whose software sits behind the ID check at dispensaries, rental counters and hotel front desks across the United States. On September 10, IDScan confirmed it: hackers got into its cloud environment and took customer data.

    The confirmation matters less for what it revealed than for what it finally settled. A driver’s license is not a password. You cannot rotate it, you cannot revoke it, and for most Americans it will not change for another five to eight years. Whatever ended up on that marketplace is, functionally, permanent.

    Quick facts

    • A dark web marketplace advertised more than 153 million driver’s license scans, first reported September 1, 2026
    • IDScan.net confirmed on September 10 that hackers accessed data in its cloud platform
    • Reported stolen data includes full names, driver’s license numbers, and ID numbers from other government documents such as passports
    • The FBI’s New Orleans field office has opened an investigation
    • IDScan says its technology serves more than 1,000 cannabis dispensaries, alongside retail, transportation and hospitality clients
    • The company has not published its own figure for how many people are affected
    • Multiple law firms have opened class action investigations

    What IDScan actually does, and why it held so much

    Most people have never heard of IDScan.net, which is precisely the point. It is infrastructure. When a budtender at a dispensary runs your license through a scanner, when a rental desk verifies that the person in front of them matches the document, when an age-restricted retailer needs a defensible record that it checked, there is a decent chance an IDScan product is doing the verification and writing the result somewhere.

    That business model creates a specific kind of risk. A verification vendor does not just touch identity documents in passing, it aggregates them. Every scan at every client location flows toward the same platform, which means a single company ends up holding a cross-section of the driving public that no individual dispensary or rental agency would ever accumulate on its own. Reporting on the incident has pointed to clients spanning retail, transportation, finance and hospitality, including customers of well-known brands, and IDScan itself says its technology serves more than a thousand dispensaries.

    Recommended for you:

    Thirty Robots Marched on Poland’s Digital Ministry to Demand Rules for AI
    Tech News·Sep 10, 2026

    Thirty Robots Marched on Poland’s Digital Ministry to Demand Rules for AI

    To put 153 million in perspective, the United States has roughly 235 million licensed drivers. If the marketplace listing is accurate and the records are largely distinct American licenses, the set represents something close to two thirds of everyone legally driving in the country.

    Putting 153 million records in scale Advertised record count against the total US licensed driver population US licensed drivers (approx.) 235 million Records advertised on the marketplace 153 million about 65% Driver counts are approximate federal figures. The 153 million number comes from the seller’s own listing and has not been independently verified or confirmed by IDScan, which has not published a figure of its own.

    The gap between the listing and the confirmation

    It is worth being precise about who has said what, because the two accounts do not line up perfectly and that gap is where most of the remaining uncertainty sits.

    QuestionWhat the marketplace claimedWhat IDScan has confirmed
    Number of recordsMore than 153 million license scansNo figure published
    What was takenLicense scans offered for saleNames, license numbers, and numbers from other government IDs including passports
    Where it came fromAttributed by researchers to IDScanThe company’s cloud environment
    How long access lastedReporting described a roughly year-long intrusionNot specified publicly
    Who is affectedUnspecifiedNotifications underway, credit monitoring offered

    Two details deserve emphasis. The first is the mention of passports and other government documents, which means the exposure may not stop at driver’s licenses for everyone in the set. The second is the reported duration. An intrusion measured in months rather than days is the difference between a smash and grab and a tenant, and it changes what a reasonable person should assume about how thoroughly the environment was picked over.

    Person holding a smartphone with a digital security lock overlay, representing identity theft risk after a large document breach

    Stolen identity documents tend to surface later as account takeovers rather than immediate fraud. Photo via Pexels.

    Why this one is worse than a typical breach

    Breach fatigue is real, and most people have learned to skim past these stories. This one is structurally different from a leaked email list, for three reasons.

    The data does not expire. After a password dump, you change passwords and move on. A license number is issued by a state and tied to you for years. There is no reset button, and requesting a new number is a bureaucratic process most states reserve for confirmed victims rather than worried citizens.

    It is exactly what identity verification systems ask for. The uncomfortable irony is that the data stolen from a company in the business of proving identity is the same data other companies use to prove identity. Name plus license number plus a document image is the standard package for opening accounts, disputing charges and passing remote verification checks. It is also why device takeovers have overtaken classic scams as the leading form of identity theft, since attackers increasingly work by convincingly impersonating the account holder rather than tricking them.

    Victims had no relationship with the company. You did not sign up for IDScan. You handed your license to a dispensary or a rental clerk, and the scan traveled somewhere you were never told about. That makes notification genuinely hard, and it means many affected people will never receive a letter because the company holding their data does not have their address, only their document.

    The part that should worry regulators

    Identity verification vendors sit upstream of thousands of businesses at once, which makes them an efficient single target. A breach at one dispensary exposes one dispensary. A breach at the vendor every dispensary uses exposes all of them, and the people whose licenses passed through them have no practical way to know which vendors hold their documents.

    What to actually do if you think you are in this

    Assume exposure if you have had a license scanned at an age-restricted business, a rental counter or a hotel in the past few years. That is a wide net, but the honest answer is that most people cannot narrow it further.

    The single highest-value step is a credit freeze with all three bureaus, which is free, reversible and blocks the most common downstream use of stolen identity data, which is opening new accounts in your name. Fraud alerts are weaker but easier. Beyond that, watch for account recovery attempts rather than card fraud, since document data is more useful for talking a support agent into a password reset than for a direct charge. If IDScan offers credit monitoring and you receive a notice, take it, but understand that monitoring tells you after something has happened rather than preventing it.

    Recommended for you:

    Mistral Raised Europe’s Biggest Tech Round Ever. The Pitch Wasn’t a Better Model, It Was Sovereignty
    AI & Software·Sep 11, 2026

    Mistral Raised Europe’s Biggest Tech Round Ever. The Pitch Wasn’t a Better Model, It Was Sovereignty

    It is also a reasonable moment to tighten the basics around the accounts an attacker would target first. Email and phone are the recovery path for almost everything else, and the same defensive posture that pushed major telecom carriers to build a shared threat intelligence hub after Salt Typhoon applies in miniature to individuals: assume the perimeter has already failed somewhere and make the next step harder. For anyone who does a lot of verification over public networks, running traffic through a tested VPN is a modest but real improvement.

    What happens next

    Three threads are now running in parallel. The FBI’s New Orleans field office is investigating the marketplace itself, which is the only avenue with any chance of taking the data out of circulation, and historically that chance is slim once a set has been listed. Class action firms have opened investigations and at least one suit has already been filed, which will eventually produce a more precise record count under oath than anything the company has volunteered. And IDScan is working through notification, which is where the practical impact for ordinary people will land.

    The broader question is whether anything changes for the category. Identity verification vendors have grown quickly on the promise that outsourcing compliance is safer than doing it yourself, and for the individual business that is usually true. What this incident illustrates is that the risk does not disappear when it is outsourced, it concentrates. It moves from thousands of small piles into one very large one, and the people in that pile are the last to find out it exists.

    cybersecurity data breach identity theft Privacy
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleMistral Raised Europe’s Biggest Tech Round Ever. The Pitch Wasn’t a Better Model, It Was Sovereignty
    Next Article Wardogs Just Sold a Million Copies on Day One, and It Broke Its Own Servers Doing It
    Marcus Bennett

      Marcus Bennett is GeekBlog's Android expert, covering everything from Google's Pixel line and Samsung Galaxy flagships to OnePlus, Nothing, Xiaomi and the broader Android ecosystem. He follows each Android OS release, One UI and Pixel Feature Drop, custom ROMs and the foldable wave, translating spec sheets and beta builds into hands-on guidance for readers choosing their next Android phone, tablet or wearable.

      Related Posts

      8 Mins Read

      Nvidia Spent About $20 Billion Without Buying Anything. The DOJ Wants to Know If That Was the Point.

      8 Mins Read

      Anthropic Blamed a Bug When Claude Hacked Real Companies. Now It Says the Model Talked Itself Into It.

      6 Mins Read

      Mistral Raised Europe’s Biggest Tech Round Ever. The Pitch Wasn’t a Better Model, It Was Sovereignty

      6 Mins Read

      OpenAI Put the Codex Harness Behind One API Call, and Early Testers Are Seeing 86% Fewer Failures

      7 Mins Read

      Thirty Robots Marched on Poland’s Digital Ministry to Demand Rules for AI

      5 Mins Read

      Nintendo’s $520 Zelda Switch 2 Lasted Four Hours, and eBay Wants $1,000 for It

      Top Posts

      How to Use YouTube: A Beginner’s Guide

      July 7, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20265 Views

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      September 3, 20263 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      September 3, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20265 Views

      Best Android Smartwatches in 2026: Which One Actually Fits Your Phone

      September 7, 20262 Views
      Our Picks

      Apple Watch Series 12 and Ultra 4 Preorders Are Live: Here Is What the Market Data Says About This Launch

      September 11, 2026

      Nvidia Spent About $20 Billion Without Buying Anything. The DOJ Wants to Know If That Was the Point.

      September 11, 2026

      Anthropic Blamed a Bug When Claude Hacked Real Companies. Now It Says the Model Talked Itself Into It.

      September 11, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      HEICJPG.online - Convert HEIC to JPG online
      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      • Editorial Policy
      • Cookie Policy
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.