At least four class-action lawsuits have been filed against IDScan.net following reports of a massive breach potentially compromising driver's license information for over 153 million people, according to Infosecurity Magazine. The legal actions, all filed in the US District Court for the Eastern District of Louisiana, target the New Orleans-based company that provides ID verification and fraud prevention services to businesses. Plaintiffs are demanding financial compensation and calling for the firm to strengthen its security measures.

A service called "Nexus" on a Russian cybercrime forum had claimed possession of more than 153 million driver's licenses primarily from American and Canadian drivers, along with over 10 million additional documents including ID cards, travel documents, and medical cards. The forum listing disappeared shortly after journalist Brian Krebs published his initial report, but Krebs traced activity from his own data and other identified victims back to IDScan.net. The company serves major corporate clients including car rental giant Hertz, FedEx, and hundreds of cannabis dispensaries throughout the United States. The FBI confirmed last week that it's investigating the incident, while at least two additional major law firms—Hall Attorneys and Markovits, Stock & DeMarco—are currently examining claims from potential victims.

"When you look at data brokers and the sheer amount of information they collect, purchase, acquire, aggregate and store over time, it's absolutely staggering," said John Strand, owner of Black Hills Information Security. The report notes that Strand called for treating this category of data with protections similar to those applied to protected health information, potentially bringing it under HIPAA-like safeguards or establishing a regulatory framework that handles large personal data collections with comparable seriousness. Markovits, Stock & DeMarco stated on its website that individuals who rented vehicles, visited cannabis dispensaries, or otherwise had identification documents scanned or verified through IDScan.net's systems may qualify for compensation and other legal remedies.

Hall Attorneys provided specific guidance for individuals who believe their information may have been exposed, urging them to identify the business, location, approximate date, and reason their ID was scanned or uploaded. The firm recommended asking whether the business used IDScan.net, VeriScan, DIVE, or another ID-verification provider, and whether front-and-back images, infrared or ultraviolet captures, selfies, or parsed ID fields were retained. People should keep records of their requests and responses while avoiding sending unredacted ID images, Social Security numbers, or account passwords in initial inquiries, and should treat unsolicited breach-check links as suspicious. IDScan.net reportedly said it's investigating the incident.

The scale of this alleged breach underscores how third-party verification vendors have become invisible collection points for sensitive identity data, often without consumers realizing their information is being stored beyond the immediate transaction. The legal pressure now mounting against IDScan.net may force the entire ID verification industry to reconsider how long they retain scanned documents and whether business convenience justifies the risk of creating such massive identity data repositories.