
IDScan has confirmed a data breach that exposed driver’s licenses and other identity documents from its systems, following reports that more than 150 million records were accessible through a dark web database. The identity verification company said hackers stole information from its cloud environment, marking its first public acknowledgement that it had been hacked.
IDScan confirms the breach after initial investigation
The Louisiana-based company said in a website notice that it received information on or around September 1 about a claim of compromise, the same day independent cybersecurity journalist Brian Krebs first reported the incident. Last week, IDScan said it was investigating a security incident but had not yet confirmed that an intrusion had occurred.
In the new notice, the company said the stolen material included people’s full names and driver’s license numbers, as well as identity numbers from other government-issued documents such as passports. IDScan did not immediately respond to TechCrunch’s request for comment about the breach, including whether hackers demanded payment in exchange for not releasing the data.
What IDScan says was taken
IDScan’s notice says the attackers obtained driver’s licenses from the company’s cloud systems. The company also said the exposed records included details from other government-issued identity documents. While IDScan has not disclosed a final tally of affected individuals, it noted on its website that it holds more than 150 million driver’s license records.
The company wrote that “though full access to the information required payment,” it was publishing the notice to warn potentially affected people. That wording appears to reference a ransom demand or other payment-related barrier tied to access to the full cache of stolen data, though IDScan has not publicly confirmed the precise nature of any extortion attempt.
How IDScan is used by customers
IDScan is an identity verification service used by corporate customers to check and verify identity documents. Its clients include entertainment venues and cannabis dispensaries, businesses that often need to confirm age and identity before allowing access to goods or services.
Because of that role, the company handles highly sensitive data at scale. Identity verification platforms often store document images and associated personal details to automate checks and support compliance requirements, which can make them attractive targets for attackers looking for large collections of government-issued identification records.
Brian Krebs’s reporting brought the breach into view
The breach became public after Krebs reported that he had been alerted to a website on the dark web that allowed anyone to search driver’s license information for more than 150 million people living in the United States and Canada. According to Krebs, the database also exposed photos tied to those records.
Krebs said he verified the authenticity of the data by checking his own record. His report also said the exposed database included high-profile individuals, among them U.S. Secretary of Defense Pete Hegseth, as well as a security researcher who separately verified his own information for the story.
That reporting appears to have prompted rapid attention from law enforcement and government agencies. The Pentagon told TechCrunch last week that it was aware of the suspected breach, and an FBI spokesperson said the bureau was also investigating the incident.
What the company has and has not said
IDScan’s latest statement confirms the theft of data but leaves a number of important questions unanswered. The company has not said how the attackers gained access to its systems, how long they remained undetected, or whether the breach involved data exfiltration over an extended period.
It also has not said whether the attackers made direct contact to threaten publication of the stolen information, whether any ransom demand was made, or whether the company paid anything. For now, the public notice focuses on warning affected individuals while the investigation continues.
That limited disclosure is common early in a breach response, but it leaves customers, users and regulators without a full picture of the attack. The scale of the records involved, combined with the sensitivity of the data, suggests the incident could have significant privacy and security implications for people whose documents were stored by the service.
Why stolen driver’s licenses are especially sensitive
Driver’s licenses are among the most useful forms of identity data for fraudsters because they typically contain a full name, document number, address, date of birth and a photograph. When those details are combined with other government-issued identity numbers, the data can be used for account takeovers, identity theft and fraudulent verification attempts.
Unlike passwords, identity documents usually cannot be changed quickly. That means a breach involving licenses and passports can create long-term risk for the people affected, especially if the records are leaked, sold or reused across multiple criminal schemes.
- Full names and license numbers can help attackers impersonate victims.
- Photos can improve the realism of fake identity profiles.
- Passport and other government ID numbers add value for fraud and verification bypass attempts.
- Large datasets can be repackaged and resold repeatedly on criminal forums.
Questions that remain as the investigation continues
Even with IDScan’s confirmation, several details remain unresolved. The company has not specified whether the breach affected only U.S. records or also Canadian records, despite the reported dark web search tool covering both countries. It also has not said whether the incident involved a single customer-facing repository or multiple internal systems.
There is also no public timeline yet for when the intrusion began, how much data was taken, or whether the exposed material included other forms of identity documentation beyond driver’s licenses and passports. Those details will likely matter to customers trying to assess risk and determine what notifications or follow-up steps may be necessary.
For now, the case underscores how much sensitive information identity verification providers can accumulate, and how quickly that data can become a large-scale exposure when systems are compromised. The incident is also a reminder that a verification service can become a single point of failure for millions of identity records.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 10, 2026 at 10:32 pm
6 views

