MediumII Cyber Warfare & Critical Infrastructure10 September 2026, Thursday
153 million US and Canadian driving licence scans stolen from identity verification company IDScan
The data were put up for sale on a Russia-linked illicit marketplace; the FBI has opened an investigation.
According to The Record and Help Net Security, 153 million driving licence scans from the US and Canada, along with 10 million identity cards, more than 3 million travel documents and 579,000 health cards, were stolen from Louisiana-based identity verification company IDScan. The company detected the breach around 1 September and confirmed it on 4 September; the notifications became public on 10–11 September.
The data were reportedly put up for sale on 31 August on a Russia-linked illicit marketplace called Nexus, and the FBI's New Orleans field office has opened an investigation. The incident has been recorded as one of the largest leaks of identity documents to date and increases the risk of both phishing and fraudulent account opening. The concentration of identity verification services in a single supplier creates a supply chain risk of a critical infrastructure nature.
Talay assessment
Bottom line
The theft of 153 million driving licence scans shows that concentrating identity verification in a small number of vendors is a risk at the level of critical infrastructure. Because the data has already been offered for sale on an illicit market, the leak cannot be undone and the impact will surface as a protracted wave of phishing and fraudulent account openings. The most likely course is a gradual rise in fraud attempts alongside widening lawsuits and regulatory scrutiny.
Likely effects
- US and Canadian financial securityNegative1–6 months
Driving licence, ID card and health card data make fraudulent account openings and phishing attacks at banks and fintech firms easier; millions of people and institutions relying on identity verification are affected.
- Identity verification industryNegative6 months+
The incident will increase regulatory pressure on retention periods and encryption standards for document scans accumulated at single vendors; compliance costs in the sector rise and client trust weakens.
- Türkiye digital identity securityUncertain1–6 months
For Turkish banks and fintech firms, where remote onboarding and digital identity verification services are spreading, the incident is a concrete warning on overseeing data retention and concentration risk at third-party vendors.
Possibilities, ranked
- 1Gradual fraud wave and lawsuits75%
Stolen data is used in phishing and fraudulent account attempts over months; class actions are filed against the company and state-level notification and investigation processes expand.
Watch: Notification counts to affected individuals, class actions filed against IDScan and fraudulent account warnings from financial institutions
- 2Limited exploitation15%
Law enforcement action restricts the spread of the data on the illicit market; reported fraud cases stay lower than expected.
Watch: A law enforcement operation against the Nexus market and limited fraud reports linked to the leaked data
- 3Regulatory turning point10%
The incident accelerates federal data retention and security rules for identity verification vendors; the sector comes under broad scrutiny.
Watch: A regulatory proposal on identity verification vendors in Congress or federal agencies and an indictment arising from the FBI investigation
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.