Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » IDScan driver’s licence breach triggers wave of class action lawsuits
    Technology

    IDScan driver’s licence breach triggers wave of class action lawsuits

    Gary BehanBy Gary Behan11/09/2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    IDScan driver's licence breach
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    At least four proposed class action lawsuits have been filed over the IDScan driver’s licence breach, after hackers allegedly stole and put up for sale records covering more than 153 million North American drivers. The company, which processes over 21 million identity verifications a month across more than 20,000 locations, has so far issued no public statement on the incident.

    Investigative journalist Brian Krebs first reported on 1 September that a dark-web identity-theft service called ‘Nexus’ was advertising access to more than 153 million US and Canadian driver’s licence scans, alongside 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified the samples by searching the database for his own records and those of individuals who had consented to the checks, and traced the source to KrebsOnSecurity‘s investigation of IDScan.

    IDScan is an identity verification technology company whose hardware and software solutions allow businesses to scan, authenticate, and extract data from government-issued identity documents. Its systems are deployed across the US in car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality venues.

    A customer list that reads like a corporate roll call

    The scale of the potential exposure becomes clearer when you look at who relies on IDScan’s infrastructure. According to SafeState, the company’s customer list includes Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and Jack Henry. The lawsuits filed in Louisiana (where IDScan is based) specifically allege that the company failed to protect information belonging to clients such as global car rental company Hertz.

    That breadth matters. With 21 million verifications processed monthly across more than 20,000 locations, the pool of people whose ID scans could be caught up in this incident is potentially enormous. Law firm Markovits, Stock & DeMarco says people whose IDs were scanned through any business using IDScan’s systems may be affected, and is seeking potential claimants for a class-action case. Hall Attorneys has similarly launched an investigation into possible class-action litigation.

    IDScan reportedly began notifying some business customers around 1 September, according to Markovits, Stock & DeMarco. The company has not responded to requests for comment.

    IDScan driver’s licence breach draws FBI and multidistrict litigation threat

    The FBI’s New Orleans field office has launched an investigation into the incident. Reuters independently confirmed that investigation, though the agency has not issued any official statement and has not responded to requests for confirmation.

    The illegal ‘Nexus’ service is no longer online, but that offers limited comfort: the underlying database remains accessible to cybercriminals. It is currently unclear whether IDScan’s own systems were directly compromised, and the precise number of affected individuals has not been confirmed.

    With at least four proposed class actions already filed in the Eastern District of Louisiana, legal pressure is building quickly. Given the incident’s potential scale, related cases could eventually be consolidated into multidistrict litigation. State attorneys general and federal regulators could also launch separate investigations or enforcement actions, a pattern seen previously with high-profile data exposures involving 23andMe, Marriott, and Equifax.

    The Nexus service’s advertising of the data, Krebs’s verification of the records, and the FBI’s involvement all point to an incident that will take considerably longer to resolve than the current silence from IDScan might suggest. The Eastern District of Louisiana courts will be the next place to watch as the consolidated litigation picture takes shape.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleCitrix NetScaler Auth Bypass CVE-2026-19490 Hit by Active Exploit Attempts
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Citrix NetScaler Auth Bypass CVE-2026-19490 Hit by Active Exploit Attempts

    11/09/2026

    Chrome V8 Zero-Day CVE-2026-85046 Scores 8.8 as Google Rushes Fix

    11/09/2026

    Hôpital Privé de la Loire GDPR fine hits €500,000 over 727,000-record breach

    10/09/2026

    KB5120998 mouse reset bug hits non-English Windows 11 systems only, Microsoft confirms

    10/09/2026

    Plex Media Server vulnerabilities prompt urgent patch push across desktop and server

    10/09/2026

    Teams and Outlook ARM crash traced to August Patch Tuesday update

    09/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.