IDScan, a major identity verification company, has confirmed a massive security incident. The IDScan data breach involved the theft of driver’s licenses from its cloud systems, affecting more than 150 million people across the United States and Canada. The Louisiana-based firm acknowledged the intrusion in a website notice, marking its first official confirmation of the hack.
The company stated it received information on or around September 1 about a claim of a hack. This came on the same day an independent cybersecurity journalist first reported a data breach at IDScan. Last week, the company said it was investigating an incident but had not yet confirmed an intrusion. The notice now serves as the company’s formal acknowledgment that its systems were compromised.
IDScan is used by corporate customers ranging from entertainment venues to cannabis dispensaries. These businesses rely on the service to check and verify the identity documents of their customers. The stolen information includes people’s full names and driver’s license numbers, along with identity numbers from other government-issued documents such as passports.
What Was Stolen in the IDScan Data Breach
The IDScan data breach exposed a vast trove of sensitive personal information. According to the independent journalist’s report, a dark web website allowed anyone to search the driver’s license information of over 150 million people living in the United States and Canada. The database included access to their photos.
The journalist verified the authenticity of the data by examining his own record. The database also contained high-profile individuals, including the U.S. Secretary of Defense Pete Hegseth. A security researcher also verified his data for the report. The Pentagon told media last week that it was aware of the suspected breach, and a spokesperson for the FBI said it was also investigating the incident.
IDScan has not said exactly how many individuals are affected. However, the company notes on its website that it holds over 150 million driver’s license records. This figure aligns with the number cited in the independent report.
Company Response and Investigation
IDScan said on its website that its investigation is ongoing. The company’s statement noted that “though full access to the information required payment” — likely referring to a demand for money made by the hackers to access the full cache of stolen data. Despite this, the company was providing notice on its website to notify potentially affected individuals.
The company did not respond to requests for comment about the incident. Questions remain about whether the hackers contacted the company with a ransom demand not to release the data. The IDScan data breach notice is the company’s first public acknowledgment of the hack, and it has not provided further details about the scope or cause of the intrusion.
How the IDScan Data Breach Affects Consumers
If you have ever had your driver’s license or passport scanned by a business that uses IDScan, your information may have been exposed. The IDScan data breach affects people in the United States and Canada, and the stolen data includes full names, driver’s license numbers, and other government-issued identity numbers.
Check your records: Review your credit reports and personal accounts for any suspicious activity.
Watch for phishing: Be cautious of emails, calls, or texts claiming to be from IDScan or government agencies.
Consider a credit freeze: Placing a freeze on your credit can prevent hackers from opening new accounts in your name.
Monitor government documents: Keep an eye on any correspondence related to your driver’s license or passport.
The IDScan data breach is a reminder of the risks associated with sharing identity documents. Businesses that rely on third-party verification services should review their security protocols and consider alternative methods for protecting customer data.
Timeline of Events
Late August 2026: Independent journalist reports a data breach at IDScan.
September 1, 2026: IDScan receives information about a claim of a hack.
Early September 2026: IDScan confirms the breach in a website notice.
Ongoing: Investigation continues; FBI and Pentagon acknowledge awareness.
What This Means for Identity Verification
The IDScan data breach raises serious questions about the security of identity verification services. These companies hold vast amounts of sensitive data, making them attractive targets for hackers. The year-long hack, as reported, suggests that the intruders had access to IDScan’s systems for an extended period before being detected.
For consumers, the breach highlights the importance of monitoring personal information. For businesses, it underscores the need for robust cybersecurity measures when handling customer identity documents.
IDScan has not yet released a detailed statement about how the breach occurred or what steps it is taking to prevent future incidents. The company continues to state that its investigation is ongoing.
Key Takeaways
The IDScan data breach affected more than 150 million driver’s licenses.
Stolen data includes full names, driver’s license numbers, and passport identity numbers.
The breach was discovered after an independent journalist reported a dark web database.
The FBI and Pentagon are investigating the incident.
IDScan has confirmed the breach but has not provided details on the number of affected individuals.
Consumers should remain vigilant and take steps to protect their identity. The IDScan data breach is one of the largest of its kind, and its full impact is still unfolding.