What to Do If Your Driver's License Was Stolen in the IDScan Breach
153 million driver's licenses surfaced on a dark-web market before IDScan admitted the breach. Here's the exact response sequence that actually reduces fraud ri
AnIntent Editorial
Photo by Emil Kalibradov on Unsplash
Roughly 153 million driver's license records surfaced on a dark-web marketplace called Nexus on August 31, 2026, according to Xident's breakdown of the incident. The company that scanned your ID at a concert, a dispensary, or a rental counter did not tell you it happened. Criminals did, by posting the database for sale nine days before IDScan issued a public notice.
That gap matters. Every day between exposure and action is a day someone else can open credit in your name using a real driver's license number tied to your real face.
The Fast Response Sequence That Actually Works
If you have any reason to believe a business scanned your ID with IDScan's system in the past 18 months, run these steps in order. They are sequenced so the highest-leverage moves happen first:
- Freeze your credit at Equifax, Experian, and TransUnion. Freezes are free, take minutes online, and block new accounts from being opened in your name.
- Place a fraud alert with any one of the three bureaus. That bureau is required to notify the other two.
- Request a free credit report from AnnualCreditReport.com and review every open line.
- Contact your state DMV and ask what the procedure is for flagging or reissuing a driver's license number that was exposed in a third-party breach.
- Enable the free credit monitoring that IDScan is offering. According to OffSeq's threat brief, IDScan is notifying affected individuals and offering free credit monitoring and identity protection services.
- Watch for a notification letter from IDScan or the business that scanned your ID, and keep it. That paper is your legal proof of exposure if fraud shows up later.
The credit freeze is the single most useful action on this list. Everything else is monitoring after the fact.
Why This Breach Is Structurally Worse Than a Password Leak
A stolen password can be rotated. A stolen driver's license number cannot. It is tied to your face, your date of birth, and a physical document that most states reissue only when it expires or is reported lost.
TechCrunch reported on September 10, 2026 that IDScan, a Louisiana-based ID verification service, confirmed hackers stole driver's licenses from its cloud environment, and that the stolen data includes full names and driver's license numbers along with identity numbers from other government-issued documents such as passports. That combination is exactly what synthetic identity fraud rings buy.
There is a detail buried in the technical write-ups that most outlets have not emphasized. Xident's analysis flagged that the stolen data reportedly included infrared scan data, a detail KrebsOnSecurity called out as deserving more attention than it received. Infrared captures are used to prove a license is authentic, which means whoever holds that data can potentially replay it against verification systems that trust the same signal. A basic photo of your license is bad. An IR scan of it is worse, because it defeats the exact anti-fraud check IDScan sold to its clients.
How to Know If You Were Actually Affected
There is no public lookup tool. Parade points out that because IDScan provides identity-verification services to businesses rather than consumers directly, affected individuals may not immediately know whether their driver's license was included in the breach. You will not get an email from IDScan the way you would from a retailer. The notice will come from the business that used IDScan at the point of sale, if it comes at all.
Legal filings offer the clearest picture of where to look. Tech Insider reports that legal-tracking documents covering the incident name Hertz, FedEx, and Target as IDScan clients that rely on identity verification for rental transactions, shipping pickups, and retail age checks. If you rented a car, picked up a package requiring ID, or bought age-restricted goods in the US or Canada in the past two years, assume exposure is plausible until a notice tells you otherwise.
The broader customer footprint is worse than those three names suggest. TechCrunch describes IDScan as used by corporate customers across entertainment venues, cannabis dispensaries, and other businesses to verify customers' identity documents at the point of sale. Concert bag-check ID scans, dispensary intake tablets, and bar door scanners all sit inside that pipeline.
Freeze Your Credit Before You Do Anything Else
A credit freeze locks your file so no lender can open a new account without you thawing it first. It is free at all three US bureaus and is the specific action Parade highlights when it notes that fast action like credit freezes, dark web monitoring, and fraud alerts can significantly lower risk of identity theft and financial fraud even before confirmed misuse occurs.
Use each bureau's own site. Do not pay a third party to do this:
- Equifax: freeze via the security portal on equifax.com
- Experian: freeze via experian.com/freeze
- TransUnion: freeze via transunion.com/credit-freeze
You will need your Social Security number, address history, and a set of knowledge-based verification questions. Save the PIN each bureau issues. Thawing later without it is slow.
If you plan to apply for a mortgage, auto loan, or new credit card in the next 90 days, freeze anyway. Then request a temporary lift for the specific bureau the lender uses. A permanent freeze does not damage your credit score and does not affect existing accounts.
Contact Your DMV About the License Number Itself
This is the step most guides skip because the answer is state-dependent. Some states will issue a new driver's license number if you can document that yours appeared in a confirmed breach. Others will only reissue a physical card while keeping the same number. A handful will do nothing until fraud is proven.
Call the DMV directly and ask two specific questions: whether they will assign a new number given the IDScan incident, and whether they can add an internal flag to your record so any address change or duplicate license request triggers manual review. Get the answer in writing if possible. The IDScan notification letter, when it arrives, is your documentation.
For identity theft cases that escalate, file a report at IdentityTheft.gov. That report is what the DMV, the bureaus, and your bank will ask for.
The One Check That Catches Most Downstream Fraud
Set a recurring calendar reminder for every 30 days over the next 12 months to pull a fresh credit report from AnnualCreditReport.com. Rotate bureaus each time so you get Equifax in month one, Experian in month two, TransUnion in month three. Look for two things: hard inquiries you did not authorize, and new accounts you did not open.
Synthetic identity fraud built on stolen license data often incubates for six to nine months before the first fraudulent account posts. The window where victims usually notice is exactly when they stop checking. A calendar reminder beats a monitoring app you forget to open.
Also monitor your medical insurance explanation-of-benefits statements. The dataset reportedly included approximately 10 million ID cards and 579,000 medical cards, according to Xident's writeup of the Nexus listing, which means medical identity theft is a live risk for a subset of victims, not just financial fraud.
Why the Numbers in the Headlines Are Still Uncertain
The 153 million figure has been repeated across nearly every outlet, but its provenance matters. Xident notes that the figure originated from the Nexus dark-web listing itself and has not been independently verified by IDScan or law enforcement, and IDScan has published no official count. Tech Insider confirms the same gap, reporting that IDScan has not published its own total count of affected records as of September 10, 2026.
The timeline itself has a discrepancy. Parade cites September 4 as the date IDScan confirmed an unauthorized third party may have accessed or copied customer information stored in its cloud, while TechCrunch and OffSeq point to September 10 for the public-facing website notice. The most likely explanation is an internal customer disclosure on September 4 followed by a public statement six days later.
What is not disputed is how the breach came to light. Xident's analysis states plainly that the breach went undetected for approximately one year, not by the company, not by Fortune 500 customers, not by auditors, and was discovered because criminals advertised it. Tech Insider adds that KrebsOnSecurity first tied the Nexus dark-web marketplace to IDScan on September 1, 2026, nine days before IDScan issued its official confirmation notice.
A year is not a detection failure. It is a design failure. Xident calculates that IDScan runs approximately 21 million verifications per month, making the stolen dataset roughly equivalent to seven months of throughput never deleted. The company retained scans it had no operational reason to keep.
What to Do About Businesses That Used IDScan
Contact the venues and retailers directly. If a bar, dispensary, or rental agency scanned your ID with IDScan, they are the party legally required to notify you. Tech Insider notes that the shift from IDScan's language of "may have accessed" to confirmed theft is what triggers downstream notification obligations for the businesses that used IDScan's verification pipeline. If you have not received a notice from a business you know scanned your ID after September 10, ask them in writing what their notification timeline is.
Keep every letter. Multiple lawsuits are already in motion, and class membership will likely be determined by whether you can document exposure. OffSeq reports that multiple lawsuits have been filed against IDScan following the breach confirmation.
One detail changes how you should think about long-term risk. OffSeq confirms that the Nexus dark-web platform has since been taken offline, but the database may still be accessible to threat actors who downloaded it. Taking down a marketplace does not delete the copies. The data is out. Assume it stays out.
The Investigation and What Comes Next
OffSeq reports that the incident was discovered around September 1, 2026, and IDScan has engaged third-party forensic specialists and law enforcement to investigate. Expect the affected-count number to move as forensic analysis reconciles the Nexus dataset with IDScan's internal logs. The 153 million figure could be revised down if there are duplicates, or up if the retention window turns out to exceed seven months.
If you only do one thing after finishing this article, freeze your credit at all three bureaus. It takes fifteen minutes and closes the largest single attack path opened by a driver's license breach of this scale. Then wait for the letter and file it somewhere you can find in six months.
Frequently Asked Questions
Does IDScan offer free credit monitoring to affected people?
Yes. IDScan is notifying affected individuals and offering free credit monitoring and identity protection services, according to OffSeq's threat brief. Enroll once you receive a notification letter, since the letter typically contains the enrollment code.
Can I get a new driver's license number after the IDScan breach?
It depends on your state. Some DMVs will issue a new number when you present documentation of a confirmed third-party breach, while others reissue only the physical card. Call your state DMV directly and ask both whether a new number is available and whether they can flag your record for manual review on future changes.
Was infrared scan data really included in the IDScan breach?
Xident's analysis reports that the stolen data reportedly included infrared scan data, a detail KrebsOnSecurity flagged as underreported. Infrared captures are used by verification systems to prove a license is authentic, so their exposure is more damaging than a standard photo.
Which companies used IDScan for identity verification?
Legal-tracking documents cited by Tech Insider name Hertz, FedEx, and Target as IDScan clients using it for rental transactions, shipping pickups, and retail age checks. TechCrunch adds that entertainment venues and cannabis dispensaries are also part of IDScan's customer base.
Is the stolen IDScan database still available on the dark web?
The Nexus marketplace that first listed the data has been taken offline, per OffSeq, but the database may still be accessible to threat actors who downloaded it before takedown. Treat the exposure as permanent and plan monitoring on a multi-year timeline rather than weeks.
Written by
AnIntent Editorial
AnIntent is an independent technology and automotive publication. Our editorial team researches every article from live primary sources, cross-checks key facts across multiple references, and cites claims inline so readers can verify them directly. We cover smartphones, laptops, EVs, gaming hardware, AI tools, and more — with no sponsored content and no paid placements.