IDScan confirms massive data breach exposing millions of identification records

The identity verification firm acknowledges a significant security incident involving sensitive driver's license and passport data.

IDScan has officially confirmed a data breach affecting millions of records after being alerted to a dark web database containing U.S. and Canadian identification documents. The exposed data includes personal details such as full names, driver's license numbers, and passport information.

The Breach Disclosure

Louisiana-based identification verification company IDScan has formally acknowledged a major data breach following reports that its systems were compromised. The company, which specializes in verifying identity documents for diverse corporate clients ranging from entertainment venues to cannabis dispensaries, confirmed the incident in a website notice. This admission follows a period of internal investigation, with the company stating it first became aware of claims regarding the hack on or about September 1, 2026. While the company has not provided an exact count of the affected individuals, it noted that it maintains a database of more than 150 million driver's license records, all of which were stored in its cloud infrastructure.

Discovery and Verification

The breach came to light through the efforts of cybersecurity journalist Brian Krebs, who identified a site on the dark web hosting a searchable database of sensitive identity information. This illicit portal purportedly allowed unauthorized parties to query millions of records for individuals living in the United States and Canada, including access to photographic evidence. To validate the authenticity of the leaked material, Krebs successfully examined his own record within the database. The breach reportedly also included information belonging to high-profile figures, such as U.S. Secretary of Defense Pete Hegseth. A security researcher also confirmed the accuracy of his own exposed data as part of the investigative process.

Nature of the Stolen Information

The scope of the stolen data is extensive, encompassing critical government-issued identification details. According to the notice published by IDScan, the hackers successfully extracted full names and driver’s license numbers from their cloud systems. Furthermore, the cache of stolen information includes identity numbers from various other government-issued documents, most notably passports. Although the company noted that full access to the stolen information required payment—a detail that suggests the perpetrators may have attempted to leverage the data for ransom or financial gain—the exposure of such high-fidelity personal identification poses a severe risk for potential identity theft and fraud for all individuals impacted by the compromise.

Official Inquiries and Response

In the wake of the incident, law enforcement and government agencies have become involved. The FBI has confirmed that it is actively investigating the data breach, while the Pentagon has acknowledged it was informed of the suspected security failure. IDScan maintains that its internal investigation is ongoing, though the firm has been largely silent regarding specific inquiries from the media. The company did not provide direct commentary on whether it was contacted by hackers with a ransom demand or if it chose to engage with any such actors. By posting the notice to its website, the company is attempting to inform potentially affected parties, even as it continues to manage the fallout of an incident that has now spanned a reported year-long period of unauthorized access.

Concerns

The breach exposes highly sensitive, immutable identity data—including driver's licenses and passports—for over 150 million individuals, creating a long-term risk of identity theft that is difficult for victims to mitigate.

What's next

The FBI's investigation into the breach is currently ongoing to determine the full extent of the intrusion and the methods used by the attackers. Meanwhile, affected individuals may face a long period of heightened vigilance regarding their personal information as the leaked data continues to circulate on the dark web.

FAQs

What information was taken during the IDScan breach?

The stolen data includes full names, driver’s license numbers, and identity information from other government documents such as passports. The breach also reportedly included photos associated with these identification records.

How many people are impacted by this incident?

IDScan has not provided an exact number of affected individuals. However, the company holds over 150 million driver's license records, and the dark web portal contained information corresponding to that scale.

Who is currently investigating the breach?

The FBI has confirmed it is investigating the incident. Additionally, the Pentagon has stated it is aware of the breach.

Did IDScan confirm the hack immediately?

No, the company initially said it was investigating an incident without confirming a breach. It officially acknowledged the theft on September 10, following reports of the database appearing on the dark web.

Was there a ransom demand involved?

IDScan stated that full access to the stolen information required payment, which implies the hackers may have been attempting to extort the company or sell the data for a fee. The company has not confirmed whether it was directly contacted with a specific ransom request.

Sources

data-breachidscanidentity-theftcybersecurityprivacyidentity-verificationgovernment-id

More news