Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Trump Renamed AI “Super Intelligence.” The Word Already Meant Something Else.

    October 1, 2026

    Pixel Watch 2 Support Ends Today: What You Lose and What to Do Next

    October 1, 2026

    Singapore Built a Dating App That Pays for Your First Date. There Is a Catch About Who Can Use It.

    October 1, 2026
    Facebook
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • Gaming
    • Smartwatch
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»153 Million Driver’s Licenses Went Up for Sale. The Company That Scanned Them Just Confirmed the Hack.
    Tech News

    153 Million Driver’s Licenses Went Up for Sale. The Company That Scanned Them Just Confirmed the Hack.

    Marcus BennettBy Marcus BennettSeptember 11, 20268 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Digital padlock over computer circuitry representing a Windows kernel security vulnerability
    Photo: Pexels
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    For nine days, the story lived in that uncomfortable space where a company says nothing and a dark web listing says everything. On September 1, security journalist Brian Krebs reported that a newly launched marketplace was advertising more than 153 million driver’s license scans, and the trail appeared to lead back to IDScan.net, the New Orleans company whose software sits behind the ID check at dispensaries, rental counters and hotel front desks across the United States. On September 10, IDScan confirmed it: hackers got into its cloud environment and took customer data.

    The confirmation matters less for what it revealed than for what it finally settled. A driver’s license is not a password. You cannot rotate it, you cannot revoke it, and for most Americans it will not change for another five to eight years. Whatever ended up on that marketplace is, functionally, permanent.

    Quick facts

    • A dark web marketplace advertised more than 153 million driver’s license scans, first reported September 1, 2026
    • IDScan.net confirmed on September 10 that hackers accessed data in its cloud platform
    • Reported stolen data includes full names, driver’s license numbers, and ID numbers from other government documents such as passports
    • The FBI’s New Orleans field office has opened an investigation
    • IDScan says its technology serves more than 1,000 cannabis dispensaries, alongside retail, transportation and hospitality clients
    • The company has not published its own figure for how many people are affected
    • Multiple law firms have opened class action investigations

    What IDScan actually does, and why it held so much

    Most people have never heard of IDScan.net, which is precisely the point. It is infrastructure. When a budtender at a dispensary runs your license through a scanner, when a rental desk verifies that the person in front of them matches the document, when an age-restricted retailer needs a defensible record that it checked, there is a decent chance an IDScan product is doing the verification and writing the result somewhere.

    That business model creates a specific kind of risk. A verification vendor does not just touch identity documents in passing, it aggregates them. Every scan at every client location flows toward the same platform, which means a single company ends up holding a cross-section of the driving public that no individual dispensary or rental agency would ever accumulate on its own. Reporting on the incident has pointed to clients spanning retail, transportation, finance and hospitality, including customers of well-known brands, and IDScan itself says its technology serves more than a thousand dispensaries.

    Recommended for you:

    Thirty Robots Marched on Poland’s Digital Ministry to Demand Rules for AI
    Tech News·Sep 10, 2026

    Thirty Robots Marched on Poland’s Digital Ministry to Demand Rules for AI

    To put 153 million in perspective, the United States has roughly 235 million licensed drivers. If the marketplace listing is accurate and the records are largely distinct American licenses, the set represents something close to two thirds of everyone legally driving in the country.

    Putting 153 million records in scale Advertised record count against the total US licensed driver population US licensed drivers (approx.) 235 million Records advertised on the marketplace 153 million about 65% Driver counts are approximate federal figures. The 153 million number comes from the seller’s own listing and has not been independently verified or confirmed by IDScan, which has not published a figure of its own.

    The gap between the listing and the confirmation

    It is worth being precise about who has said what, because the two accounts do not line up perfectly and that gap is where most of the remaining uncertainty sits.

    QuestionWhat the marketplace claimedWhat IDScan has confirmed
    Number of recordsMore than 153 million license scansNo figure published
    What was takenLicense scans offered for saleNames, license numbers, and numbers from other government IDs including passports
    Where it came fromAttributed by researchers to IDScanThe company’s cloud environment
    How long access lastedReporting described a roughly year-long intrusionNot specified publicly
    Who is affectedUnspecifiedNotifications underway, credit monitoring offered

    Two details deserve emphasis. The first is the mention of passports and other government documents, which means the exposure may not stop at driver’s licenses for everyone in the set. The second is the reported duration. An intrusion measured in months rather than days is the difference between a smash and grab and a tenant, and it changes what a reasonable person should assume about how thoroughly the environment was picked over.

    Person holding a smartphone with a digital security lock overlay, representing identity theft risk after a large document breach

    Stolen identity documents tend to surface later as account takeovers rather than immediate fraud. Photo via Pexels.

    Why this one is worse than a typical breach

    Breach fatigue is real, and most people have learned to skim past these stories. This one is structurally different from a leaked email list, for three reasons.

    The data does not expire. After a password dump, you change passwords and move on. A license number is issued by a state and tied to you for years. There is no reset button, and requesting a new number is a bureaucratic process most states reserve for confirmed victims rather than worried citizens.

    It is exactly what identity verification systems ask for. The uncomfortable irony is that the data stolen from a company in the business of proving identity is the same data other companies use to prove identity. Name plus license number plus a document image is the standard package for opening accounts, disputing charges and passing remote verification checks. It is also why device takeovers have overtaken classic scams as the leading form of identity theft, since attackers increasingly work by convincingly impersonating the account holder rather than tricking them.

    Victims had no relationship with the company. You did not sign up for IDScan. You handed your license to a dispensary or a rental clerk, and the scan traveled somewhere you were never told about. That makes notification genuinely hard, and it means many affected people will never receive a letter because the company holding their data does not have their address, only their document.

    The part that should worry regulators

    Identity verification vendors sit upstream of thousands of businesses at once, which makes them an efficient single target. A breach at one dispensary exposes one dispensary. A breach at the vendor every dispensary uses exposes all of them, and the people whose licenses passed through them have no practical way to know which vendors hold their documents.

    What to actually do if you think you are in this

    Assume exposure if you have had a license scanned at an age-restricted business, a rental counter or a hotel in the past few years. That is a wide net, but the honest answer is that most people cannot narrow it further.

    The single highest-value step is a credit freeze with all three bureaus, which is free, reversible and blocks the most common downstream use of stolen identity data, which is opening new accounts in your name. Fraud alerts are weaker but easier. Beyond that, watch for account recovery attempts rather than card fraud, since document data is more useful for talking a support agent into a password reset than for a direct charge. If IDScan offers credit monitoring and you receive a notice, take it, but understand that monitoring tells you after something has happened rather than preventing it.

    Recommended for you:

    Mistral Raised Europe’s Biggest Tech Round Ever. The Pitch Wasn’t a Better Model, It Was Sovereignty
    AI & Software·Sep 11, 2026

    Mistral Raised Europe’s Biggest Tech Round Ever. The Pitch Wasn’t a Better Model, It Was Sovereignty

    It is also a reasonable moment to tighten the basics around the accounts an attacker would target first. Email and phone are the recovery path for almost everything else, and the same defensive posture that pushed major telecom carriers to build a shared threat intelligence hub after Salt Typhoon applies in miniature to individuals: assume the perimeter has already failed somewhere and make the next step harder. For anyone who does a lot of verification over public networks, running traffic through a tested VPN is a modest but real improvement.

    What happens next

    Three threads are now running in parallel. The FBI’s New Orleans field office is investigating the marketplace itself, which is the only avenue with any chance of taking the data out of circulation, and historically that chance is slim once a set has been listed. Class action firms have opened investigations and at least one suit has already been filed, which will eventually produce a more precise record count under oath than anything the company has volunteered. And IDScan is working through notification, which is where the practical impact for ordinary people will land.

    The broader question is whether anything changes for the category. Identity verification vendors have grown quickly on the promise that outsourcing compliance is safer than doing it yourself, and for the individual business that is usually true. What this incident illustrates is that the risk does not disappear when it is outsourced, it concentrates. It moves from thousands of small piles into one very large one, and the people in that pile are the last to find out it exists.

    Sources and further reading

    • The Record: IDScan confirms breach after 153 million license scans offered
    • Help Net Security: IDScan confirms breach of driver license data
    • SecurityWeek: 153 million driver license images offered on dark web
    cybersecurity data breach identity theft Privacy
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleMistral Raised Europe’s Biggest Tech Round Ever. The Pitch Wasn’t a Better Model, It Was Sovereignty
    Next Article Wardogs Just Sold a Million Copies on Day One, and It Broke Its Own Servers Doing It
    Marcus Bennett

      Marcus Bennett is GeekBlog's Android expert, covering everything from Google's Pixel line and Samsung Galaxy flagships to OnePlus, Nothing, Xiaomi and the broader Android ecosystem. He follows each Android OS release, One UI and Pixel Feature Drop, custom ROMs and the foldable wave, translating spec sheets and beta builds into hands-on guidance for readers choosing their next Android phone, tablet or wearable.

      Related Posts

      10 Mins Read

      Trump Renamed AI “Super Intelligence.” The Word Already Meant Something Else.

      9 Mins Read

      Singapore Built a Dating App That Pays for Your First Date. There Is a Catch About Who Can Use It.

      9 Mins Read

      Meta’s AI Agent Gave Out a Seller’s Home Address. A Stranger Showed Up With His Family.

      11 Mins Read

      Amazon’s New Fire Sticks Cannot Be Jailbroken. The Trade-Off Is Most of the App Store.

      5 Mins Read

      The FTC Is Investigating OpenAI and Anthropic Over Rogue AI Agents. No Subpoenas Have Gone Out Yet.

      6 Mins Read

      ElevenLabs Doubled Its Value to $22 Billion in Seven Months. Voice Agents Are the Reason.

      Top Posts

      Best Free Online Music Apps in 2026

      July 7, 20263 Views

      Chromebook vs PC: Which One Should You Actually Buy?

      July 7, 20262 Views

      The Light Flip Wants to Sell You a Phone That Does Less

      July 28, 20261 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      How to Convert HEIC to JPG on iPhone, Mac, Android and Windows

      September 3, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20265 Views

      The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

      September 9, 20263 Views
      Our Picks

      Trump Renamed AI “Super Intelligence.” The Word Already Meant Something Else.

      October 1, 2026

      Pixel Watch 2 Support Ends Today: What You Lose and What to Do Next

      October 1, 2026

      Singapore Built a Dating App That Pays for Your First Date. There Is a Catch About Who Can Use It.

      October 1, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      HEICJPG.online - Convert HEIC to JPG online
      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      • Editorial Policy
      • Cookie Policy
      • Your Privacy Choices
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.