ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen

The identity verification provider IDScan has verified that driver’s licenses were stolen from its database during a security breach. This confirmation comes one week after reports surfaced that the ID validation company had fallen victim to a year-long cyberattack.

In an official announcement on its website, the firm disclosed that unauthorized actors extracted driver’s licenses from its cloud storage. The compromised data encompasses full names, driver’s license numbers, and identification numbers from other government-issued credentials like passports.

Based in Louisiana, IDScan provides identity verification services to various businesses, ranging from dispensaries to entertainment arenas. This public notice marks the firm’s first formal admission of the hack, following statements last week in which it acknowledged investigating an issue but stopped short of confirming a breach.

According to its notice, IDScan was alerted to the potential breach on or about September 1, coinciding with the day independent security reporter Brian Krebs initially broke the story of the security failure.

Krebs noted that he discovered a dark web portal where anyone could look up the driver’s license details—including photographs—of more than 150 million individuals across the U.S. and Canada. He confirmed the database’s validity by locating his own personal record. The leaked information also reportedly included high-profile individuals, such as U.S. Secretary of Defense Pete Hegseth, and a cybersecurity expert who similarly validated his own compromised details.

A Department of Defense representative informed recently that they were aware of the suspected compromise, while an FBI spokesperson confirmed that the bureau is investigating the matter.

IDScan indicated that its probe into the matter is still active. The company pointed out that “although full access to the information required payment”—suggesting the attackers are selling the data or demanding a ransom—it published the advisory to alert anyone whose information might be exposed. While the organization has not specified the exact number of victims, its website claims that its database contains over 150 million driver’s license entries.

The firm did not reply to inquiries seeking comment on the situation, including whether it had received ransom demands from the hackers to prevent the data’s release.

Exit mobile version