VMTech
Discuss a project

IDScan confirms theft of more than 150 million licence records

IDScan confirms theft of more than 150 million licence records

ID verification provider IDScan has confirmed that hackers stole driver’s licence data from its cloud systems. The Louisiana-based company says it holds more than 150 million driver’s licence records, although it has not disclosed how many individuals were affected by the incident.

The company said the stolen information includes full names and driver’s licence numbers, as well as identity numbers from other government-issued documents, including passports. IDScan provides document-checking and identity-verification services to corporate customers ranging from entertainment venues to cannabis dispensaries.

Confirmation follows report of searchable records

IDScan’s website notice is its first acknowledgement that it was hacked. The company had said the previous week that it was investigating an incident, but had not confirmed an intrusion at that point.

IDScan said it received information about a claim of a hack on or around September 1. That was the same day independent cybersecurity journalist Brian Krebs reported that IDScan had suffered a breach during what was described as a year-long compromise.

Krebs reported being alerted to a dark-web website that allowed users to search driver’s licence information for more than 150 million people in the United States and Canada. The site reportedly included photographs, and Krebs verified the authenticity of the data by examining his own record. The database also contained records belonging to high-profile individuals, including US Secretary of Defense Pete Hegseth.

Investigation remains open

A security researcher also confirmed data associated with their own record for Krebs’ report. The Pentagon said it was aware of the suspected breach, while an FBI spokesperson said the bureau was investigating the incident.

IDScan said its own investigation remains ongoing. Its notice stated that full access to the information required payment, apparently referring to the hackers’ conditions for obtaining the full cache. The company did not say whether it had received a ransom demand intended to prevent publication of the data, and it did not respond to a request for comment on that point.

Identity data raises long-term exposure concerns

Unlike a password, a government identity document number cannot simply be reset after a breach. The combination of names, licence details, passport-related identifiers and photographs may be relevant to organisations that rely on document verification for customer onboarding or access control.

Businesses that share customer identity documents with verification providers should review what data is retained, which cloud environments hold it, and how suppliers communicate suspected intrusions. The practical implication is that vendor due diligence and incident plans must account for the enduring sensitivity of identity-document records.

#cybersecurity#databreach#identitysecurity#vendorrisk
Open analytics
On the site 0 views
min read 3 10.09.2026
Instagram

IDScan confirms theft of more than 150 million licence records

Open the post on Instagram ↗