The numbers
Timeline
🔍Why the trail points to one company
Two details reported by Krebs connect the documents to IDScan.net: the scans carry timestamps consistent with infrared and ultraviolet capture — the company's own technology — and the scan dates line up with car rentals at Hertz. Known customers of the company include Hertz, Target, FedEx and cannabis dispensaries. None of this is a confession, and none of it has been confirmed by the company. It is a chain of circumstantial evidence, reported by a named journalist, and now the subject of a federal investigation.
Source: Krebs on Security, 1 September 2026.🔐A licence is not a password
A password takes seconds to change. A licence number, a date of birth, an address and a photograph cannot be reissued because someone copied them. What makes this case different from an ordinary leak is the format: the reported images include infrared and ultraviolet layers, which exist precisely so that a checker can tell a real document from a fake one. A scan that carries those layers is not a photocopy — it is the material used to pass a verification.
🌐Outside North America: not your data, but your model
On the evidence available, the documents are American and Canadian. No British or Australian licence data has been reported in this case. What travels beyond North America is not the leak — it is the arrangement that produced it: identity documents scanned at a rental desk, a shop counter or a dispensary, then held by a third party you never chose and whose name you may never have seen. That model is in use worldwide.
What this changes for you
If your licence has been scanned at a car rental counter or a retail checkout in North America, you have no way to know whether it is in this collection, and no way to withdraw it. That is the uncomfortable part, and pretending otherwise would be dishonest.
Frequently asked questions
Has the breach been confirmed?
No. As of 5 September 2026, IDScan.net has acknowledged investigating a potential security incident and stated it has not reached conclusions regarding the nature or scope of the incident, including what information was involved. The FBI has confirmed it opened an investigation on 1 September 2026. The figure of 153 million comes from the criminal sellers themselves, not from any organisation or regulator.
Am I affected if I live in the UK or Australia?
On the evidence available, no. The documents offered are described as United States and Canadian. No British or Australian licence data has been reported in this case. The reason this matters outside North America is different: it shows what happens when scanned identity documents are centralised by a third party, which is a model used worldwide.
Why is a scanned licence worse than a leaked password?
A password can be changed in seconds. A driving licence number, date of birth, address and photograph cannot. The images reported in this case include infrared and ultraviolet captures, the layers used to check that a document is genuine. That is the difference between a stolen key and a stolen face.
What should I do now?
There is no action that undoes an exposed identity document. What is useful is to expect the follow-on contact: calls or messages that quote real details about you to establish credibility. Treat any unsolicited contact that already knows your details as more suspicious, not less, and verify through a number you already have.
Can Egidio detect this kind of scam?
Egidio cannot know whether your licence was exposed, and it cannot verify who is calling. What it recognises are the known patterns of a scam call or message: manufactured urgency, a request for money or codes, an unusual channel. If leaked details are used to make an approach more convincing, the underlying script rarely changes.
Further reading
Egidio — Threat Laboratory, « 153 million driving licence scans, offered for sale », egidio.app/en/laboratoire/drivers-licence-scans-dark-web/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.