At least four proposed class action lawsuits have been filed over the IDScan driver’s licence breach, after hackers allegedly stole and put up for sale records covering more than 153 million North American drivers. The company, which processes over 21 million identity verifications a month across more than 20,000 locations, has so far issued no public statement on the incident.
Investigative journalist Brian Krebs first reported on 1 September that a dark-web identity-theft service called ‘Nexus’ was advertising access to more than 153 million US and Canadian driver’s licence scans, alongside 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified the samples by searching the database for his own records and those of individuals who had consented to the checks, and traced the source to KrebsOnSecurity‘s investigation of IDScan.
IDScan is an identity verification technology company whose hardware and software solutions allow businesses to scan, authenticate, and extract data from government-issued identity documents. Its systems are deployed across the US in car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality venues.
A customer list that reads like a corporate roll call
The scale of the potential exposure becomes clearer when you look at who relies on IDScan’s infrastructure. According to SafeState, the company’s customer list includes Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and Jack Henry. The lawsuits filed in Louisiana (where IDScan is based) specifically allege that the company failed to protect information belonging to clients such as global car rental company Hertz.
That breadth matters. With 21 million verifications processed monthly across more than 20,000 locations, the pool of people whose ID scans could be caught up in this incident is potentially enormous. Law firm Markovits, Stock & DeMarco says people whose IDs were scanned through any business using IDScan’s systems may be affected, and is seeking potential claimants for a class-action case. Hall Attorneys has similarly launched an investigation into possible class-action litigation.
IDScan reportedly began notifying some business customers around 1 September, according to Markovits, Stock & DeMarco. The company has not responded to requests for comment.
IDScan driver’s licence breach draws FBI and multidistrict litigation threat
The FBI’s New Orleans field office has launched an investigation into the incident. Reuters independently confirmed that investigation, though the agency has not issued any official statement and has not responded to requests for confirmation.
The illegal ‘Nexus’ service is no longer online, but that offers limited comfort: the underlying database remains accessible to cybercriminals. It is currently unclear whether IDScan’s own systems were directly compromised, and the precise number of affected individuals has not been confirmed.
With at least four proposed class actions already filed in the Eastern District of Louisiana, legal pressure is building quickly. Given the incident’s potential scale, related cases could eventually be consolidated into multidistrict litigation. State attorneys general and federal regulators could also launch separate investigations or enforcement actions, a pattern seen previously with high-profile data exposures involving 23andMe, Marriott, and Equifax.
The Nexus service’s advertising of the data, Krebs’s verification of the records, and the FBI’s involvement all point to an incident that will take considerably longer to resolve than the current silence from IDScan might suggest. The Eastern District of Louisiana courts will be the next place to watch as the consolidated litigation picture takes shape.

