opinion

IDScan Breach Probe: 153 Million Driver’s Licenses Reportedly Offered on Russian Cybercrime Forum

Canada's privacy commissioner is investigating a breach at identity-verification firm IDScan.net, as a seller on a Russian-language forum reportedly offers scans of more than 170 million North American identity documents.

IDScan Breach Probe: 153 Million Driver's Licenses Reportedly Offered on Russian Cybercrime Forum

If you handed over your driver’s license at a car rental counter, a dispensary, or a cell phone store in the last few years, there’s a chance the scan ended up somewhere you never agreed to. According to American Thinker, Canada’s Privacy Commissioner has opened an investigation into a possible data breach at IDScan.net, a New Orleans-based identity-verification company, after it appeared that a third party gained access to its database.

The numbers being floated are hard to get your head around. American Thinker reports that as many as 153 million American and Canadian driver’s license records may have been compromised, alongside potentially 10 million identity cards, three million travel documents and international IDs, and at least 579,000 medical cards. The outlet frames the story as a corrective to a media cycle obsessed with hypothetical AI doomsday scenarios, arguing that data breaches are the quieter, already-here threat to ordinary people.

What IDScan.net actually does

The company sells identity-verification technology to businesses. According to KrebsOnSecurity, whose reporting American Thinker cites, IDScan’s customer list includes major retailers, car rental agencies, cell phone carriers, clothing companies, and marijuana dispensaries, among other high-profile businesses.

The pitch is straightforward: a business scans your ID, and the software makes a fast judgment about whether the document is likely legitimate. That has obvious value in a world of fake licenses, whether the user is an underage kid buying alcohol, someone renting a car, or someone trying to open a phone account under a false name.

The catch is what else the system does. American Thinker points to IDScan’s own documentation, which it says describes the default setting for new accounts as “Collect all,” with a default retention policy of not deleting records. In other words, the software does what computers do well: it scrapes, categorizes, and stores enormous amounts of information about the person on the other side of the counter.

IDScan reportedly performs more than 21 million identity verifications per month across roughly 20,000 locations worldwide, with operations concentrated in the U.S. and Canada. That volume is precisely what makes the alleged leak so consequential. A driver’s license isn’t just a permission slip to drive; it carries your photograph, your address, your date of birth, and often your height, weight, and organ-donor status.

The seller, the timestamps, and the forum post

American Thinker reports that the apparent breach may be connected to a user operating under the name Nexus on Exploit, a Russian-language cybercrime forum. Nexus reportedly offered digital scans of more than 170 million identity documents belonging to people in North America.

Nexus did not explicitly name IDScan as the source. Instead, the link came from detective work. American Thinker describes how timestamps on the stolen records matched real-world events that people could pin down with certainty. In the most cited example, Krebs and his mother handed over their licenses simultaneously at a Hertz rental counter, and the timestamps in the Nexus data matched that exact moment. Others reportedly performed similar matching against sites known to use IDScan’s service.

There was also a corporate admission. On September 4, IDScan announced that someone had gained access to, “and/or copied certain customer information stored within their accounts on the IDScan.net cloud,” according to American Thinker’s account.

Some important caveats are baked into the story. A figure like 153 million records does not mean half of America was compromised. The same person’s license can appear repeatedly in a database if they regularly present it at verification points. It also remains unclear whether the exposure was a comprehensive, global breach of all IDScan data or limited to specific corporate customers while others were left untouched. What does seem clear, per American Thinker, is that the Nexus service was robust enough that customers could search for specific individuals by name and buy their images and data.

In a detail that reads like something out of a spy novel, Brian Krebs reportedly learned about the dark web operation because the seller used his own driver’s license to advertise the service. American Thinker also notes that the database reportedly includes government officials, naming Pete Hegseth among them.

Why this story keeps getting buried

The outlet’s central argument is less about IDScan specifically and more about where public attention goes. American Thinker argues that while debates rage over speculative catastrophes from artificial intelligence or climate change, the mundane, ongoing failure to protect consumer data is already causing damage. The piece contends that people routinely hand sensitive information to strangers and assume it will stay secure indefinitely, an assumption the IDScan allegations put under strain.

That framing is worth taking seriously regardless of where one stands on AI policy. Data breaches lack the narrative drama of an apocalypse forecast, but they compound. Each leaked record becomes raw material for future fraud, and the victims rarely learn about it from the company that lost their data. In this case, American Thinker notes, it took a press release from Canada and a tip about a cybercrime forum to bring the story into view.

The remediation problem

The piece also confronts an uncomfortable reality: once a scan of your license is circulating, there is no recall. No service can pull it back. The best available strategy, the article suggests, is to make yourself harder to assemble from the fragments already floating around.

The argument here is that a stolen document is only half of an identity theft. The other half is the connective file that links that document to your current address, your phone number, your relatives, and your employer; that half isn’t stolen at all. According to American Thinker, it is sold legally by data brokers and people-search sites to anyone willing to pay roughly $20. A bare license image becomes dangerous when it can be matched to a live phone number and a plausible script.

The article’s back half is a promotion for Incogni, a data-removal service that sends legally binding deletion requests to brokers, monitors for resurfacing, and repeats the process as information gets relisted. The piece notes that American Thinker’s editorial staff selected the article and that Incogni had no input into the subject matter or reporting, a disclosure worth keeping in mind when weighing the recommendation.

What readers should take from it

Several things stand out. First, the investigation is ongoing. Canada’s Privacy Commissioner opening a file does not establish the full scope of what happened, and IDScan has not, in the source material, confirmed the 170 million figure or the link to Nexus. Second, the record-matching method described, while compelling, is circumstantial when applied to any individual. Third, the sheer breadth of businesses that rely on ID scanning means the potential victim pool extends far beyond any one retailer or rental desk.

For now, the practical advice embedded in the piece is unglamorous: assume that anything you have handed over for scanning may already be out there, and treat unsolicited calls or messages that arrive with accurate personal details as suspect rather than credible. The breach, if confirmed at the scale suggested, will not be resolved by a single fix. It will play out in follow-on attempts at fraud for years, the kind of slow-burning consequence that rarely leads a news cycle but reliably finds its way to someone’s phone.

Source: www.americanthinker.com — https://www.americanthinker.com/blog/2026/09/a-possible-idscan-data-breach-has-far-reaching-implications/

The FedFront Brief

Politics from the front lines, straight to your inbox — free, every weekday.

Join the Conversation

Your email address will not be published. Required fields are marked *