IDScan Data Breach: 17 Lawsuits in Four Weeks, Most Now Before One Judge, and No Settlement — IDScan Says an Intruder Was in Its VeriScan Cloud From April 4 to September 2, 2026, but Has Not Said How Many People Are Affected
Does this affect you?
AI Legal Assistant · free · answers in seconds · general information, not legal advice
Bunch v. IDscan.net, Inc., Case No. 2:26-cv-01929-WBV-DPC, and 16 related suits in the United States District Court for the Eastern District of Louisiana, filed between September 2 and September 28, 2026; at least 12 are assigned to Chief Judge Wendy B. Vitter, and a motion to consolidate lists a submission date of October 13, 2026. IDScan.net, the Louisiana company whose VeriScan platform businesses use to scan IDs at rental counters, cannabis dispensaries and other front desks, says in a notice updated September 29, 2026 that an unauthorized third party had access to part of its cloud from April 4 to September 2, 2026, and that names, contact details, dates of birth and driver's license, passport or other ID numbers may be involved. A dark-web seller claims more than 153 million U.S. and Canadian license scans; IDScan has confirmed neither that figure nor any count. There is no settlement and no claim form. What you can do now: enroll in IDScan's free credit monitoring at 1-833-516-2980 and freeze your credit.
By Settlement Insight Data Desk ·

What IDScan has confirmed about the IDScan data breach — and what it hasn't
IDScan.net sells ID scanners and a cloud platform called VeriScan that businesses use to read and check driver's licenses, passports and other IDs at the door or the counter. On September 4, 2026 it put a “Notification of Data Security Incident” on its website; the version online now is marked “Updated September 29. Initially posted September 4, 2026.” It says that on or around September 1 the company “received information indicating that certain data may have been accessed without authorization,” and that its investigation, which is still going on, found that “an unauthorized third party gained access to a portion of our cloud environment between April 4, 2026, and September 2, 2026.” According to the notice, the event “was limited to the VeriScan platform”; no other IDScan product or service has been identified as involved.
What may have been taken, in IDScan's words: “a combination of the full name, contact information, date of birth, driver’s license, passport, and/or other government-issued identification numbers.” Not every item applies to every person, because what was stored depended on “how a particular customer organization used the VeriScan platform and the information it chose to collect, process, or store.” IDScan says it is “not aware of any misuse of personal information as a result of this event” but that the information “could give rise to a risk of fraud or identity theft.”
Two things are missing from the notice: a count of the people affected, and any mention of pictures of the IDs themselves. Both come from outside reporting. On September 1 the security news site KrebsOnSecurity reported that a new dark-web identity-theft service was advertising more than 153 million U.S. and Canadian driver's license scans — plus more than 10 million ID cards, more than three million travel documents and at least 579,000 medical cards — and traced samples back to IDScan. The people selling it claimed they had been “continuously exfiltrating new data for over a year.” Those numbers are the sellers' claims, not IDScan's; KrebsOnSecurity, which searched the service, wrote that the sellers were “likely not exaggerating” the 153 million figure. BleepingComputer wrote on September 10 that the breach “reportedly also allowed threat actors to steal scans of driver's licenses,” that the service went offline after the first report while the criminals “likely still have access to the database,” and that several people have since claimed to be selling the whole database — sales it could not confirm. The FBI's New Orleans field office opened an investigation, which the FBI confirmed to BleepingComputer; IDScan says it is cooperating with law enforcement.
Who may be affected: people whose ID went through VeriScan — possibly well before April
You were not IDScan's customer; the businesses that scanned your license were — the notice calls them “customer organizations.” BleepingComputer lists them as “car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses”; TechCrunch describes customers “from entertainment venues to cannabis dispensaries.” IDScan's own site sells age checks to “keep alcohol, tobacco, and cannabis products out of the hands of minors.” According to KrebsOnSecurity, IDScan says it checks IDs for more than 1,000 marijuana dispensaries in 19 states and that its systems perform more than 21 million verifications a month at more than 20,000 locations. Several people KrebsOnSecurity found in the stolen set had handed their licenses to a Hertz rental counter, and one had shown ID at a Las Vegas cannabis dispensary. The first lawsuit alleges that its plaintiff's information reached IDScan through a Hertz car rental, and a later suit names Hertz and the dispensary chain Planet 13 as co-defendants. A brand on IDScan's client list is not proof that its customers are in the data, though: the “trust” page named Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment, and a Caesars spokesperson told KrebsOnSecurity that Caesars has not used VeriScan since February 2025 and had no active VeriScan account at the time of the incident.
The dates need care. The April 4 to September 2, 2026 window in IDScan's notice describes when the intruder was inside its cloud, not when your ID was scanned. The reporter's own license, which KrebsOnSecurity found in the data, carried a timestamp from June 2025, about ten months before that window opened — so an ID scanned in 2025 can be in the data if it was still stored. The notice does not say how long VeriScan keeps scans.
How many people? IDScan has not said. Its breach report to the Texas Attorney General, published there on September 21, 2026, lists the information as name, driver's license number, government-issued ID number and date of birth, gives the method of notice as “Posted at company website or special website”, and puts the number of affected Texans at 1 — a field the Attorney General's page says “may change after a report is listed.” The California Attorney General's breach list, which includes notices posted through September 29, 2026, had no IDScan entry when we checked on September 30. Because the Texas report names website posting, not mail, as the way people are told, do not wait for a letter from IDScan before you act. IDScan has started notifying some of its business customers, according to a law firm quoted by BleepingComputer. The same notice covers Canada; it has a French version and lists Canadian credit bureaus.
The lawsuits: 17 cases in four weeks, most before one judge, and a motion to combine them
The first suit, Bunch v. IDscan.net, Inc., No. 2:26-cv-01929, was filed on September 2, 2026 in the United States District Court for the Eastern District of Louisiana — IDScan's home court; the complaint describes IDScan as a Louisiana corporation based in New Orleans — and assigned to Chief Judge Wendy B. Vitter. It is a proposed class action on behalf of “all persons in the United States whose PII was exposed in Defendant IDScan’s 2026 Data Breach,” with a California subclass, and it claims negligence, breach of implied contract and breach of a third-party-beneficiary contract — the contract between Hertz and IDScan. It asks for damages and for an order making IDScan strengthen its security, submit to annual audits and “immediately provide adequate credit monitoring” to class members. These are allegations; no court has found IDScan liable for anything.
By September 30 the federal docket services CourtListener and Justia listed 17 suits against IDscan.net, Inc. in that court, filed between September 2 and September 28: four on the first day, one on September 3, four on September 4, one on September 8, two on September 9, one on September 10, one each on September 23 and 24, and two on September 28. At least 12 of them are now assigned to Chief Judge Vitter; in Wagner v. IDscan.net, Inc., for example, the originally assigned judge signed an order on September 9 transferring the case to her. Five were still listed before other judges of the district on September 30. Two more suits naming IDScan were filed elsewhere: Hasenzahl v. Hertz Corporation (No. 5:26-cv-05735) on September 7, and Djordjevic v. Planet 13 Holdings Inc. in the District of Nevada on September 23.
On September 16 two plaintiffs asked the court to consolidate the cases, but filed the motion in the Bunch docket; on September 18 the clerk noted it had gone into “the prospective master case instead of the prospective member cases” and had to be refiled. It was refiled in Rioux v. IDscan.net, Inc. on September 23, where the clerk marked it deficient; the docket lists a submission date of October 13, 2026. As of September 30 we found no consolidation order, and we could not confirm whether anyone has asked the Judicial Panel on Multidistrict Litigation to gather the cases from different states in one court. IDScan's answer in the Bunch case was due September 29, according to the proof of service.
For you, that means there is nothing to file. No class has been certified, there is no settlement, no claim form and no deadline. Law firms advertising about IDScan are looking for clients; BleepingComputer counted several that “launched investigations into potential class-action litigation.” For what data breach settlements have paid in other cases, see our data breach settlement calculator; any dollar figure for IDScan today would be a guess.
What to do now: no claim form, but four free steps
- Enroll in IDScan's credit monitoring. The notice offers free credit monitoring and identity protection; call 1-833-516-2980 on weekdays between 8 a.m. and 8 p.m. Eastern, excluding holidays, to ask questions or enroll. The notice does not name the monitoring company or an enrollment deadline.
- Freeze your credit or place a fraud alert with all three bureaus. The notice lists TransUnion 1-800-680-7289, Experian 1-888-397-3742 and Equifax 1-888-298-0045. A name, a birth date and a license number are the kind of details used to open accounts in someone else's name; a freeze makes that much harder.
- Report misuse. If someone uses your identity, report it at IdentityTheft.gov or 1-877-438-4338, and to the police — the notice points out that you have the right to file a police report. If your license number itself is misused, ask your state's motor vehicle agency whether it will issue a new number — re-issuance is a state process with its own cost and delay.
- Watch your accounts. IDScan itself advises people to monitor their account statements for suspicious activity, and to be careful about sharing personal information with anyone who contacts them.
In Canada, the notice lists TransUnion and Equifax Canada and says a “Potential Fraud Warning” stays on a credit file for six years.
Is it real? The genuine notice, and what a scam looks like
The notice is genuine and is posted at IDScan.net’s notice page, but it is hard to find: the page tells search engines not to list it (a “noindex” instruction, which BleepingComputer reported TechCrunch had spotted, and which was still in the page when we read it on September 30). The only IDScan contact details it gives are the call center at 1-833-516-2980 and a mailing address, 8814 Veterans Memorial Blvd, Suite 3-124, Metairie, LA 70003. Because there is no settlement, there is no settlement administrator and no payment. A text, email or call offering “IDScan settlement money,” asking for a fee, or asking you to type your license number into a site to “see if you were in the leak” is not from IDScan or from the court. If a business you dealt with — a rental company or a dispensary — writes to you about this incident, check the letter against that business's own website before calling any number in it. Our guides to IDX and Cyberscout breach letters show how to check a notice.
Hertz customers should not mix this up with the earlier Cleo file-transfer breach at Hertz, which has its own lawsuits — see our Hertz data breach page.
Why this breach is different
Most breaches expose what one company knew about its own customers. This one, if the sellers' claims hold, exposes what many businesses captured at the door — and, according to KrebsOnSecurity, some records hold six image files: front and back photos, a plain scan, and infrared and ultraviolet versions, the kinds of views ID checkers use to spot fakes. A card number can be cancelled; a license number and photo are much harder to replace. The court cases are at the very start, and the next date on the record is the October 13, 2026 submission date for the consolidation motion. This article reflects the record as of September 30, 2026.
The Data Behind This Story
- Company
- IDscan.net, Inc. (IDScan.net), a Louisiana corporation based in New Orleans; breach limited to its cloud-based VeriScan ID-scanning platform, per its notice
- What IDScan confirmed
- An unauthorized third party had access to a portion of its cloud environment between April 4, 2026 and September 2, 2026; learned of it on or around September 1, 2026 (notice first posted September 4, updated September 29, 2026)
- Data IDScan names
- A combination of full name, contact information, date of birth, driver's license, passport and/or other government-issued ID numbers; varies by business customer
- Not confirmed by IDScan
- How many people are affected, and whether ID images were taken. A dark-web seller claimed more than 153 million U.S. and Canadian license scans (unverified claim)
- State filings
- Texas Attorney General: published September 21, 2026, notice by website posting, Texans affected listed as 1. California Attorney General list (through September 29, 2026): no IDScan entry on September 30
- Lawsuits
- 17 in the U.S. District Court for the Eastern District of Louisiana, filed September 2–28, 2026; first case Bunch v. IDscan.net, Inc., No. 2:26-cv-01929; at least 12 assigned to Chief Judge Wendy B. Vitter as of September 30, 2026
- Consolidation
- Motion filed September 16 in the wrong case, refiled September 23 in Rioux v. IDscan.net, Inc., No. 2:26-cv-01932, marked deficient; submission date October 13, 2026; no consolidation order seen as of September 30, 2026
- Other courts
- Hasenzahl v. Hertz Corporation et al., No. 5:26-cv-05735 (filed September 7, 2026); Djordjevic v. Planet 13 Holdings Inc. et al., D. Nev. No. 2:26-cv-03064 (filed September 23, 2026)
- Settlement / claim form
- None as of September 30, 2026 — no settlement, no claim form, no deadline
- Free credit monitoring
- Offered by IDScan; enroll or ask questions at 1-833-516-2980, weekdays 8 a.m.–8 p.m. ET, excluding holidays
- Investigation
- FBI New Orleans field office opened an investigation (reported by KrebsOnSecurity; FBI confirmed to BleepingComputer); IDScan says it is cooperating
- Official contact
- IDScan.net, 8814 Veterans Memorial Blvd, Suite 3-124, Metairie, LA 70003 · 1-833-516-2980 · notice posted on IDScan.net
- Source: IDScan.net, “Notification of Data Security Incident” (updated September 29, initially posted September 4, 2026), read September 30, 2026, including the page source: discovery on or around September 1, access window April 4 – September 2, 2026, VeriScan-only scope, data types, free credit monitoring and 1-833-516-2980, mailing address, credit-bureau and FTC contacts, police-report right, Canadian section and French version, noindex directive
- Source: Texas Attorney General, Data Security Breach Reports, entry “IDScan.net”, read September 30, 2026 in a browser: data types, Texans affected listed as 1, notice posted at company website, published 09/21/2026
- Source: California Attorney General, data breach list (CSV export), read September 30, 2026: entries through 09/29/2026, no IDScan or VeriScan entry
- Source: CourtListener, docket Bunch v. IDscan.net, Inc., No. 2:26-cv-01929 (E.D. La.), last updated September 30, 2026, read September 30, 2026: assignment to Chief Judge Wendy B. Vitter, motion to consolidate filed in error September 16, clerk correction September 18, service and answer date
- Source: CourtListener RECAP search “IDscan.net”, E.D. La., read September 30, 2026: 17 IDScan breach dockets filed September 2–28, 2026 with judges assigned; Wagner transfer order signed September 9; motion to consolidate refiled in Rioux (No. 2:26-cv-01932) September 23, marked deficient, submission date 10/13/2026
- Source: Class Action Complaint, Bunch v. IDscan.net, Inc., Dkt. 1, filed September 2, 2026 (RECAP PDF), read September 30, 2026: class and California subclass definitions, three counts, Hertz contract allegations, requested relief
- Source: Justia Dockets index, party “IDscan.net, Inc.”, read September 30, 2026 in a browser: cross-check of the E.D. La. filings; Pugh et al. v. IDscan.net, Inc. et al. naming Hertz and Planet 13; Hasenzahl v. Hertz Corporation et al.; Djordjevic v. Planet 13 Holdings Inc. et al. (D. Nev.); Chambers assignment to Judge Sarah S. Vance
- Source: KrebsOnSecurity, “FBI Probes Service Selling 153M+ Drivers Licenses,” September 2026 (with updates), read September 30, 2026: the sellers' claimed record counts and “over a year” claim, six-image records, June 2025 timestamp, Hertz and dispensary links, IDScan's dispensary and verification figures, client list, Caesars statement, FBI New Orleans inquiry — seller figures cited as claims
- Source: BleepingComputer, “IDScan confirms breach tied to 153 million stolen driver's licenses,” September 10, 2026, read September 30, 2026: scans reportedly taken though not in the notice, industries using IDScan, service taken offline, unconfirmed resale claims, FBI confirmation, noindex on the notice
- Source: BleepingComputer, “IDScan sued over alleged data breach affecting 153 million drivers,” September 4, 2026, read September 30, 2026: suits filed where IDScan is based, allegations about clients such as Hertz, law-firm investigations, business-customer notices around September 1
- Source: TechCrunch, “ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen,” September 10, 2026, read September 30, 2026: customer range from entertainment venues to cannabis dispensaries; IDScan has not said how many are affected
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.