For nine days, the story lived in that uncomfortable space where a company says nothing and a dark web listing says everything. On September 1, security journalist Brian Krebs reported that a newly launched marketplace was advertising more than 153 million driver’s license scans, and the trail appeared to lead back to IDScan.net, the New Orleans company whose software sits behind the ID check at dispensaries, rental counters and hotel front desks across the United States. On September 10, IDScan confirmed it: hackers got into its cloud environment and took customer data.
The confirmation matters less for what it revealed than for what it finally settled. A driver’s license is not a password. You cannot rotate it, you cannot revoke it, and for most Americans it will not change for another five to eight years. Whatever ended up on that marketplace is, functionally, permanent.
Quick facts
- A dark web marketplace advertised more than 153 million driver’s license scans, first reported September 1, 2026
- IDScan.net confirmed on September 10 that hackers accessed data in its cloud platform
- Reported stolen data includes full names, driver’s license numbers, and ID numbers from other government documents such as passports
- The FBI’s New Orleans field office has opened an investigation
- IDScan says its technology serves more than 1,000 cannabis dispensaries, alongside retail, transportation and hospitality clients
- The company has not published its own figure for how many people are affected
- Multiple law firms have opened class action investigations
What IDScan actually does, and why it held so much
Most people have never heard of IDScan.net, which is precisely the point. It is infrastructure. When a budtender at a dispensary runs your license through a scanner, when a rental desk verifies that the person in front of them matches the document, when an age-restricted retailer needs a defensible record that it checked, there is a decent chance an IDScan product is doing the verification and writing the result somewhere.
That business model creates a specific kind of risk. A verification vendor does not just touch identity documents in passing, it aggregates them. Every scan at every client location flows toward the same platform, which means a single company ends up holding a cross-section of the driving public that no individual dispensary or rental agency would ever accumulate on its own. Reporting on the incident has pointed to clients spanning retail, transportation, finance and hospitality, including customers of well-known brands, and IDScan itself says its technology serves more than a thousand dispensaries.
To put 153 million in perspective, the United States has roughly 235 million licensed drivers. If the marketplace listing is accurate and the records are largely distinct American licenses, the set represents something close to two thirds of everyone legally driving in the country.
The gap between the listing and the confirmation
It is worth being precise about who has said what, because the two accounts do not line up perfectly and that gap is where most of the remaining uncertainty sits.
| Question | What the marketplace claimed | What IDScan has confirmed |
|---|---|---|
| Number of records | More than 153 million license scans | No figure published |
| What was taken | License scans offered for sale | Names, license numbers, and numbers from other government IDs including passports |
| Where it came from | Attributed by researchers to IDScan | The company’s cloud environment |
| How long access lasted | Reporting described a roughly year-long intrusion | Not specified publicly |
| Who is affected | Unspecified | Notifications underway, credit monitoring offered |
Two details deserve emphasis. The first is the mention of passports and other government documents, which means the exposure may not stop at driver’s licenses for everyone in the set. The second is the reported duration. An intrusion measured in months rather than days is the difference between a smash and grab and a tenant, and it changes what a reasonable person should assume about how thoroughly the environment was picked over.

Stolen identity documents tend to surface later as account takeovers rather than immediate fraud. Photo via Pexels.
Why this one is worse than a typical breach
Breach fatigue is real, and most people have learned to skim past these stories. This one is structurally different from a leaked email list, for three reasons.
The data does not expire. After a password dump, you change passwords and move on. A license number is issued by a state and tied to you for years. There is no reset button, and requesting a new number is a bureaucratic process most states reserve for confirmed victims rather than worried citizens.
It is exactly what identity verification systems ask for. The uncomfortable irony is that the data stolen from a company in the business of proving identity is the same data other companies use to prove identity. Name plus license number plus a document image is the standard package for opening accounts, disputing charges and passing remote verification checks. It is also why device takeovers have overtaken classic scams as the leading form of identity theft, since attackers increasingly work by convincingly impersonating the account holder rather than tricking them.
Victims had no relationship with the company. You did not sign up for IDScan. You handed your license to a dispensary or a rental clerk, and the scan traveled somewhere you were never told about. That makes notification genuinely hard, and it means many affected people will never receive a letter because the company holding their data does not have their address, only their document.
The part that should worry regulators
Identity verification vendors sit upstream of thousands of businesses at once, which makes them an efficient single target. A breach at one dispensary exposes one dispensary. A breach at the vendor every dispensary uses exposes all of them, and the people whose licenses passed through them have no practical way to know which vendors hold their documents.
What to actually do if you think you are in this
Assume exposure if you have had a license scanned at an age-restricted business, a rental counter or a hotel in the past few years. That is a wide net, but the honest answer is that most people cannot narrow it further.
The single highest-value step is a credit freeze with all three bureaus, which is free, reversible and blocks the most common downstream use of stolen identity data, which is opening new accounts in your name. Fraud alerts are weaker but easier. Beyond that, watch for account recovery attempts rather than card fraud, since document data is more useful for talking a support agent into a password reset than for a direct charge. If IDScan offers credit monitoring and you receive a notice, take it, but understand that monitoring tells you after something has happened rather than preventing it.
It is also a reasonable moment to tighten the basics around the accounts an attacker would target first. Email and phone are the recovery path for almost everything else, and the same defensive posture that pushed major telecom carriers to build a shared threat intelligence hub after Salt Typhoon applies in miniature to individuals: assume the perimeter has already failed somewhere and make the next step harder. For anyone who does a lot of verification over public networks, running traffic through a tested VPN is a modest but real improvement.
What happens next
Three threads are now running in parallel. The FBI’s New Orleans field office is investigating the marketplace itself, which is the only avenue with any chance of taking the data out of circulation, and historically that chance is slim once a set has been listed. Class action firms have opened investigations and at least one suit has already been filed, which will eventually produce a more precise record count under oath than anything the company has volunteered. And IDScan is working through notification, which is where the practical impact for ordinary people will land.
The broader question is whether anything changes for the category. Identity verification vendors have grown quickly on the promise that outsourcing compliance is safer than doing it yourself, and for the individual business that is usually true. What this incident illustrates is that the risk does not disappear when it is outsourced, it concentrates. It moves from thousands of small piles into one very large one, and the people in that pile are the last to find out it exists.

