SOCLYDE logo
Current languageEN
Cybersecurity newsData breachDigital identityService providers

Idscan: an official notice, and 153 million alleged identity documents

IDScan's September 4, 2026 notice confirms possible unauthorized access to cloud-stored customer data. The 153 million license figure comes from an external marketplace claim and investigation, not an IDScan-confirmed count.

By Soclyde Team

Identity card being inserted into a counter scanner

In summary

  • On September 4, 2026, IDScan.net published a notice saying an unauthorized third party may have accessed or copied some customer information stored in cloud accounts.
  • The official notice names full names and driver's license or other government-issued identification numbers as possible data types; it does not confirm how many people were affected.
  • The figure of more than 153 million driver's licenses comes from the Nexus service described by KrebsOnSecurity and later reporting, so it should be treated as an external claim or estimate.

Explore next

Soclyde resources

Article contents

On September 4, 2026, IDScan.net published a security notice saying an unauthorized third party may have accessed or copied some customer information stored in IDScan.net cloud accounts. The company said it received information about possible unauthorized access around September 1, secured systems, brought in outside specialists, and is cooperating with federal law enforcement.

That confirmed fact needs to be separated from the much larger number that made the incident public. KrebsOnSecurity described a service called Nexus that claimed to offer more than 153 million scans of U.S. and Canadian driver's licenses, along with other identity documents. IDScan has not confirmed that volume as a count of victims or documents copied from its systems.

What IDScan confirmed

IDScan's official notice describes an incident in its cloud environment. It says an unauthorized third party may have accessed or copied some customer information stored in IDScan.net accounts, with affected data potentially including full names and driver's license or other government-issued identification numbers.

The wording remains cautious: the investigation is ongoing, and the notice does not identify the number of affected people, affected customers, or the technical path used by the attacker. It also says full access to the information required payment, while offering credit monitoring and identity protection services to potentially impacted individuals.

What the 153 million figure means

The figure of more than 153 million comes from the Nexus service described by KrebsOnSecurity. According to that investigation, Nexus claimed to hold U.S. and Canadian driver's-license scans, more than 10 million identification cards, more than 3 million travel documents or international IDs, and at least 579,000 medical cards. Those figures describe the collection advertised by the service, not an official count published by IDScan.

KrebsOnSecurity said it verified samples, including records that lined up with times when people had presented licenses at rental counters or businesses using identity-verification workflows. The Record, BleepingComputer, and Tom's Hardware later connected IDScan's notice to those reports. The connection is serious and documented, but the nuance matters: IDScan confirms a cloud incident; the 153 million volume remains a claim observed and analyzed by outside sources.

Why identity scans change the risk

A password can be changed; a driver's license, identity photo, or government identifier follows a person for far longer. Even when the official notice confirms only names and identification numbers, the possibility that full images circulated, if the Nexus reports are accurate, creates a long-lived fraud risk: account opening, age-verification bypass, false identity checks, and highly personalized phishing.

The risk is not only credit related. A person who receives a call or message containing their name, license number, or an accurate memory of a recent scan may wrongly assume the sender is legitimate. Identity data then becomes a way to make a second step credible: asking for a code, another document, a payment, or account access.

Practical precautions for individuals

If you receive an IDScan notice or a message from a business that scanned your ID, verify it through a channel you open yourself: the official site, the phone number published in the notice, or a known customer-support route. Do not upload a driver's license or passport to a supposed public lookup tool; there is no reliable public registry for checking Nexus exposure without creating another risk.

In the United States, affected people may consider a fraud alert or credit freeze with the relevant credit bureaus. In Canada and other countries, use the local equivalent rather than automatically following U.S. procedures. In every case, monitor financial accounts, credit requests, government messages, and outreach that uses accurate details to create urgency.

What organizations should ask providers

Organizations that scan driver's licenses, passports, or other identity documents should ask for answers that apply to their own customer accounts: which sites, flows, dates, fields, images, and retention windows are involved. A general provider response is not enough when data is stored by customer or tenant inside a cloud service.

The main control is minimization. If the business need is to check age, presence, or identity at one moment, retaining complete document images must be justified, limited, and audited. Contracts should require deletion evidence, exportable logs, fast notification after abnormal access, and a clear channel for people who do not know which provider processed their document.

The Soclyde connection

Soclyde does not protect IDScan, Nexus, or data already removed from a third-party cloud. The connection is more practical: this incident shows how every provider becomes a concentration point when it stores data or access on an organization's behalf. A small team needs to know which services hold secrets, which integrations use dedicated accounts, and which access can be cut quickly after an alert.

Soclyde helps teams generate unique secrets, keep them in a local-first encrypted vault, and avoid password reuse across vendors, email, and business tools. That does not replace identity-document minimization, but it prevents a personal-data leak from being worsened by reused account credentials. To structure that hygiene, read our secure password generator guide or contact Soclyde.

Key points

IDScan's September 4, 2026 notice confirms a security incident in which some customer information stored in the cloud may have been accessed or copied. It confirms categories such as full names and driver's license or other government identifiers, but not a total number of affected people.

The 153 million driver's-license figure should remain attributed to Nexus and the investigations that observed that service, not presented as an official IDScan statistic. For individuals and organizations, the right response is to verify notices through safe channels, limit new sharing of identity documents, and demand minimal, provable, and revocable retention.

Frequently asked questions

Did IDScan confirm 153 million victims?

No. IDScan confirmed that an unauthorized third party may have accessed or copied some customer data stored in its cloud, but it did not publish a count of affected people, customers, or documents. The 153 million driver's-license figure comes from the Nexus collection documented by KrebsOnSecurity.

What data is confirmed in IDScan's notice?

The official notice lists full names and driver's license or other government-issued identification numbers as data categories that may be present in the affected information. Complete document images, per-document volumes, and the alleged exfiltration duration remain tied to external reporting or Nexus claims.

What should I do if my ID may have been scanned by an IDScan customer?

Verify any notice through an official channel, avoid links to supposed public lookup tools, monitor your accounts, and use credit-freeze or fraud-alert options where they exist in your country. If a business scanned your ID, ask in writing which provider was used and what retention period applied.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading