IDScan Confirms Breach After 153 Million Driver's License Scans Surface on the Dark Web

· 916 vistas
0:00🔊 Listen
This article is not available in your language yet — showing the English version.
IDScan Confirms Breach After 153 Million Driver's License Scans Surface on the Dark Web
Anuncio
🍔 Sponsored — HTML ad test

One of the largest identity-document breaches on record is now confirmed. IDScan, a Louisiana-based ID verification company, said on September 10, 2026, that hackers accessed customer data stored on its cloud platform, after a dark web service appeared offering searchable access to more than 150 million driver's licenses from the United States and Canada.

How it unfolded

Security journalist Brian Krebs first reported on September 1 that a new dark web site allowed anyone to look up license details, including photos, for over 150 million people. IDScan says it received notice of the claimed hack that same day, posted a notice on its website on September 4, and confirmed the breach on September 10 after an investigation that is still ongoing. The FBI is investigating, and the Pentagon was aware of the suspected breach. Among the records reportedly in the trove is that of Defense Secretary Pete Hegseth, and a security researcher verified the authenticity of sample data.

What was taken

IDScan is used by corporate customers, from entertainment venues to cannabis dispensaries, to check IDs at the door. Reporting indicates the stolen records include:

  • Full names and driver's license numbers.
  • Identity numbers from other government documents, including passports.
  • Front-and-back license images, plus infrared and ultraviolet scans.

IDScan said that although full access to the information on the dark web site required payment, it is notifying potentially affected individuals. The company did not confirm whether a ransom was demanded.

A brutal month for breaches

The IDScan incident tops a heavy September. Healthcare company AdaptHealth confirmed data on 4.1 million people was exposed in an attack attributed to the ShinyHunters group, Veradigm disclosed a vendor-related breach affecting 3.5 million patients, and education platform Mathspace said attackers reached data on more than 1 million students, staff and parents through an internal reporting tool.

If you have shown ID at a venue that scans licenses, assume your license number and photo may be exposed. Consider a credit freeze, watch for identity-verification fraud, and be wary of any message claiming to come from IDScan or a state DMV.

Source: TechCrunch, Krebs on Security

Photo: TechCrunch (source)