IDScan is facing lawsuits after reports that a dark-web identity-theft service advertised access to a large database of identity documents, according to BleepingComputer. The alleged data set included more than 153 million U.S. and Canadian driver’s license scans, along with 10 million ID cards, 3 million travel documents, and 579,000 medical cards, BleepingComputer reported, citing Brian Krebs’s September 1 report. The incident is still not confirmed in full. BleepingComputer says it remains unclear whether IDScan’s own systems were compromised, and the number of affected people has not been established. IDScan has not published a statement about the allegations and did not respond to BleepingComputer’s requests for comment. Krebs reported that the dark-web service, called Nexus, advertised access to the identity-document database. According to BleepingComputer’s summary of his reporting, Krebs checked samples by searching for his own records and for records of other people who had consented to the checks, then traced the leak to IDScan. IDScan sells identity verification hardware and software that businesses use to scan, authenticate, and extract information from government-issued identity documents. BleepingComputer says its systems are used across the U.S. by car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, and hospitality establishments. The lawsuits were filed in Louisiana, where IDScan is based, and allege that the company failed to protect information from its clients, including global car rental company Hertz, according to BleepingComputer. Several law firms, including Markovits, Stock & DeMarco and Hall Attorneys, have also opened investigations into potential class-action litigation tied to the reported incident. Markovits, Stock & DeMarco says IDScan began notifying some business customers around September 1, according to BleepingComputer. The law firm says people whose IDs were scanned by businesses using IDScan’s systems may be affected, and it is seeking potential claimants for a possible class-action case. BleepingComputer also reports that Krebs said the FBI’s New Orleans office launched an investigation, and that Reuters independently confirmed that point. The FBI has not issued an official statement on the incident and did not respond to BleepingComputer’s request for confirmation, according to the report. The Nexus service is no longer online, BleepingComputer says, but the outlet reports that cybercriminals still have access to the database. Given the alleged scale, BleepingComputer says additional lawsuits, including potential class actions, could be filed and related cases could eventually be consolidated into multidistrict litigation. Any regulatory action remains possible but unconfirmed. Who benefits: Affected business customers and individuals benefit from faster confirmation and notification if IDScan or investigators establish what happened. Law firms investigating potential class actions may also benefit if more claimants come forward. Who's exposed: IDScan is exposed to litigation and reputational risk while the facts remain contested and incomplete. Businesses that used IDScan systems, and people whose IDs were scanned through those businesses, may also face uncertainty until the company or investigators clarify the scope.