---
title: "IDScan Confirms Massive Data Breach of Drivers License Records"
date: 2026-09-10
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/idscan-data-breach-confirmation.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# IDScan Confirms Massive Data Breach of Drivers License Records

IDScan.net has confirmed a data breach at its ID verification service after a report found a dark web site offering searchable license records on more than 150 million people in the US and Canada.

## What to Know?

- IDScan.net says an unauthorized party may have copied full names and driver’s license numbers from customer accounts on its cloud.
- The exposed data also includes identity numbers from other government documents, such as passports.
- Security journalist Brian Krebs found a dark web site that let anyone search license records, photos included, and confirmed his own entry was real.
- IDScan’s website says the company holds over 150 million driver’s license records, but it hasn’t given a victim count.
- The FBI is investigating the incident, and the Pentagon has said it’s aware of the suspected breach.

## How It Happened?

**IDScan**, a Louisiana-based company, verifies ID documents for corporate clients, with entertainment venues and cannabis dispensaries among them. Its [data security incident notice](https://idscan.net/notification-data-security-incident/) says the affected information sat in customer accounts on the IDScan.net cloud, where “**an unauthorized third party may have accessed and/or copied”** it.

The company says it “**received information**” about the intrusion on or around 1st September, 2026, the same day Krebs published his findings. Krebs matched the database against his own license, and a security researcher verified his entry the same way. **Defense Secretary Pete Hegseth’s record** turned up in the cache too.

The sellers claimed they’d been pulling fresh data out for over a year. Until the notice, IDScan would only say it was investigating an incident; the notice is its first admission that someone got in.

> We are investigating a data breach: Your personal information may have been compromised. You may be eligible to join a lawsuit if you have received notice of a <https://t.co/yEvMtBWQ7t> data breach. Contact us now: <https://t.co/v9BoqWVrzT>[\#IDScan](https://x.com/hashtag/IDScan?src=hash&ref_src=twsrc%5Etfw) [\#DataBreach](https://x.com/hashtag/DataBreach?src=hash&ref_src=twsrc%5Etfw) [pic.twitter.com/7JfffPzLkL](https://t.co/7JfffPzLkL)
> 
> — Scott+Scott (@scottscottlaw) [September 9, 2026](https://x.com/scottscottlaw/status/2097783359753625605?ref_src=twsrc%5Etfw)

 ## What the Notice Doesn’t Answer?

IDScan’s holdings figure lines up closely with the size of the cache Krebs found, yet the notice skips any count of affected people. It does include one telling line: “**Though full access to the information required payment, in an abundance of caution, we are notifying potentially impacted individuals.**” The wording suggests the stolen records sat behind a paywall, though IDScan doesn’t say who set the price or what buyers could see for free.

That sentence leaves several gaps the company hasn’t filled:

- **Did the hackers demand money from IDScan itself, or only from buyers on the [dark web sit](https://sqmagazine.co.uk/dark-web-statistics/)e?**
- **How long did the attackers have access to the cloud accounts?**
- **Which business customers had stored scans taken?**
- **Were license photos copied too? The notice lists names and ID numbers but says nothing about images.**

IDScan didn’t respond to TechCrunch’s request for comment on whether it received a ransom demand.

## Why It Matters?

Showing a license at a venue entrance feels routine, but each scan can end up stored with a vendor the cardholder never picked. When that vendor’s cloud is breached, millions of people are exposed at once, much as they were when [Discord’s support system was hacked](https://sqmagazine.co.uk/discord-support-data-breach-leak/) and ID photos submitted for age checks leaked. A license photo can’t be reset the way a password can.

**What comes next** is a victim count from IDScan and the outcome of the FBI probe, and businesses that use IDScan should ask the company exactly what their accounts held. Anyone who has had an ID scanned in the US or Canada should check their credit reports, and a credit freeze with **TransUnion**, **Experian** and **Equifax** helps reduce the risk of new accounts opened in their name. The notice also offers free credit monitoring at 1-833-516-2980 and points fraud victims to the FTC at identitytheft.gov.