IT-PUB NEWS

IDScan confirms breach after 150 million records leak

11.09.2026 14:03 • Author: IT-PUB
IDScan confirms breach after 150 million records leak

The ID verification company says hackers stole driver’s license and passport data from its cloud systems as agencies investigate the incident.

ID verification service IDScan has confirmed that hackers stole driver’s license records from its systems, days after reports surfaced of a large breach involving more than 150 million people. The company said the stolen data came from its cloud environment and included full names, driver’s license numbers, and other government ID numbers such as passport details.

The incident carries weight because IDScan is used by corporate customers to verify the identity documents of their own users and customers, including businesses in entertainment and cannabis retail. That makes this more than a problem inside one company’s network — it involves a service entrusted with highly sensitive identity data on behalf of others.

As IT-PUB News notes, IDScan has not disclosed how many people were affected, but the company says on its website that it holds more than 150 million driver’s license records.

IDScan says hackers accessed data stored in its cloud

In a notice posted on its website, IDScan said hackers accessed driver’s licenses stored in its cloud. The company said the stolen information includes people’s full names and driver’s license numbers, along with identity numbers from other government-issued documents, including passports.

IDScan, based in Louisiana, provides identity verification services to business clients. Its tools are used by companies that need to check whether a customer’s documents are real and valid.

The notice is the company’s first direct acknowledgment that it was hacked. Last week, IDScan said it was investigating an incident, but it had not yet confirmed that an intrusion had taken place.

A dark web report brought the breach into public view

IDScan said it “received information” about a claimed hack on or around September 1, the same day independent cybersecurity journalist Brian Krebs first reported the breach.

Krebs said he was alerted to a dark web website that allowed anyone to search driver’s license information for more than 150 million people in the United States and Canada, including access to photos. He verified the data by checking his own record.

His report also said the database contained records linked to high-profile individuals, including U.S. Secretary of Defense Pete Hegseth, as well as a security researcher who also confirmed his information for the report.

That helped push the case into wider view. A database containing identity documents and photos is especially sensitive because it can be used for impersonation or other forms of fraud if it falls into the wrong hands.

Federal agencies are already investigating the incident

The breach has also drawn the attention of government agencies. The Pentagon told TechCrunch last week that it was aware of the suspected breach, and an FBI spokesperson said the bureau was also investigating the incident.

IDScan said its own investigation was still ongoing. In its notice, the company said that “though full access to the information required payment,” it was posting the alert to notify potentially affected individuals. The wording suggests a demand for money in exchange for access to the full cache of stolen data, though the company did not say that directly.

IDScan did not respond to TechCrunch’s request for comment on whether the hackers contacted the company with a ransom demand or any other message about the release of the data.

Stolen identity documents can create long-term harm

The case stands out because it involves some of the most personal information people hand over to businesses: government-issued identity documents. Unlike a password, a driver’s license number or passport number cannot be replaced with a quick reset.

That makes the fallout potentially broader and longer-lasting. If the stolen records are genuine, the exposure could create risks of identity theft and other misuse of personal data. It also raises questions about how identity verification providers store and protect the documents they collect from customers.

For businesses that rely on services like IDScan, the breach is a reminder that security failures in one part of the digital chain can affect many others. For individuals, it is another example of how data shared for routine verification can become a target when stored at scale, while the full scope of the incident is still not public.


Improve SEO for a small/medium business website for $50