IDScan.net Breach Investigation: What to Do About ID Scans

Stephanie Adlam
8 Min Read
An identity card forms an orange question mark beside the words IDScan and Who has your ID?
Copied identity documents raise questions about exposure and the next steps for their owners.

The FBI is investigating reports of identity-document scans being sold online, while IDScan.net is investigating a possible connection to the data. The widely repeated figure of more than 153 million driver’s-license records is a seller’s claim—not a confirmed count of affected people. If you had an ID scanned, verify any notice through the business you dealt with and watch for identity misuse; do not upload another ID to an unfamiliar “breach checker.” [1] [2]

What is confirmed about the IDScan investigation?

Brian Krebs reported finding authentic records in a service called Nexus. IDScan told him it was investigating. Separately, the FBI confirmed its inquiry to Reuters, which could not establish where the data came from. The service later disappeared; that does not prove copies were deleted. The final scope, affected-person list and intrusion path remain unresolved in the reporting reviewed for this article. [1] [2]

The distinction matters. A photograph of a government ID is not the same exposure as a password or credit-card number. Changing a password does not change the image, name, birth date or document details on a previously copied card. At the same time, a report about stolen IDs does not establish that your bank account has been accessed.

Can you check whether your driver’s license was exposed?

There is no verified public individual-lookup service identified in the sources reviewed here. An email-breach search is not a complete inventory of identity-document scans. A negative result cannot clear this particular risk.

Start with the organization that collected your ID, using a receipt, an existing account or contact details you independently verify. Ask three specific questions:

  • Was my document processed through IDScan.net or a related service?
  • Have you received an incident notice covering my transaction or records?
  • Which fields or images, if any, have you confirmed were involved, and what support is available?

A company’s use of an ID service is a reason to ask, not proof that every customer record was exposed. Keep the reply and check for updates. Do not post receipts, licence numbers or ID photographs in public comments to crowdsource an answer.

What to do: no notice, a confirmed notice, or actual misuse

  • No notice and no suspicious activity: review your credit reports and important account activity, and consider preventive credit controls. You do not need to prove membership in this dataset to improve your account security. Avoid paying someone who claims they can search or erase all dark-web copies.
  • A notice arrives: verify it outside the message before opening an attachment or enrolling in a service. Save the original notice. Match the listed data types to your response—an exposed ID image, a password and payment details require different actions. Use any legitimate assistance through the verified organization’s channel.
  • An unfamiliar account, credit inquiry or recovery request appears: contact the affected provider’s fraud team promptly, dispute unauthorized activity and preserve dates, messages and case numbers. Do not wait for the IDScan investigation to finish before addressing real misuse.

Unexpected bills, account changes or collection notices deserve attention even when you cannot connect them to a particular leak. Our identity-theft warning-sign guide covers the broader signals. A suspicious event still needs verification; it is not automatic proof that this incident caused it.

United States: freezes, alerts and recovery

A free security freeze restricts access to your credit report and helps prevent new-credit fraud. Request it separately from Equifax, Experian and TransUnion. You can freeze proactively and temporarily lift it when a legitimate application needs a credit check. It does not change your credit score. [3]

An initial fraud alert is different: it asks lenders to verify your identity, rather than blocking report access. Contact one of the three bureaus; it must notify the other two. The initial alert lasts one year and is free. Neither measure erases leaked documents or replaces checking activity in existing accounts. For actual identity theft, the FTC’s IdentityTheft.gov provides reporting and recovery steps. [3] [5]

Canada: contact both credit bureaus

Get your reports from Equifax Canada and TransUnion Canada. Check for accounts you did not open and incorrect personal details. If you suspect fraud, contact the lender and both bureaus about fraud alerts, and report through Canada’s National Fraud Reporting System. Unlike the US initial-alert process, do not assume notifying one bureau covers both. [4]

Security-freeze availability depends on provincial or territorial rules and bureau eligibility. The Financial Consumer Agency of Canada advises checking with the bureaus; do not assume the US nationwide process applies. Monitoring may reveal changes, but it is not a guarantee against misuse. [4]

Should you replace your license or scan your computer?

Ask the issuing state or provincial authority what it recommends for a copied or misused document. Explain whether you have only seen a news report, received a verified notice, or observed fraud. Do not assume a replacement plastic card changes the underlying number or invalidates every old image; follow the issuer’s incident-specific procedure.

This news does not by itself mean your computer is infected. An antivirus scan cannot tell you whether a vendor held your ID or remove a copy from someone else’s database. If a follow-up message instead led you to run a file or install remote-access software, that is a separate endpoint-security incident requiring containment and review.

Be cautious of unsolicited “verification,” compensation and recovery offers. As the Carhartt contact-data incident illustrates, knowing accurate personal details does not authenticate a caller. An unfamiliar public domain can be checked with Gridinsoft Online Virus Scanner, but a clean result is not proof of authorization. Never submit your ID image, licence number or private recovery link to a reputation checker.

References

  1. Brian Krebs. “FBI Probes Service Selling 153M+ Drivers Licenses.” KrebsOnSecurity, September 1, 2026; updated September 2. Original investigation.
  2. Raphael Satter. “FBI probes report of data breach exposing millions of drivers’ licenses in US, Canada.” Reuters, September 2, 2026. FBI statement and reporting.
  3. Federal Trade Commission. “Credit Freezes and Fraud Alerts.” August 2025; accessed September 4, 2026. US credit-protection guidance.
  4. Financial Consumer Agency of Canada. “Checking your credit report for errors and fraud.” Accessed September 4, 2026. Canadian fraud-response guidance.
  5. Federal Trade Commission. “What To Do After a Data Breach.” Accessed September 4, 2026. Reporting and recovery resources.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?