A major breach has struck verification provider IDScan, with more than 150 million driver’s licenses and other government IDs stolen from its cloud systems. The company has officially confirmed the incident following earlier reports of a year-long hack. The exposed data includes full names, driver’s license numbers, passport identity numbers, and photos.
Built in Louisiana, IDScan supplies identity checks for venues from cannabis dispensaries to entertainment businesses. Their tools scan customer IDs and verify identities as a condition of service. On September 10, 2026, the company acknowledged for the first time that its systems were infiltrated and documents were stolen, after weeks of investigation.
How the Breach Unfolded
Word of trouble began circulating around September 1, when IDScan was alerted to claims its database was being sold or shared on the dark web. Journalist Brian Krebs became aware of a searchable dump that exposed over 150 million driver’s licenses belonging to individuals in the U.S. and Canada, many including photos. To verify the leak’s legitimacy, he confirmed his own records were in the stolen data. High-profile individuals were also implicated.
IDScan responded with a website notice confirming hackers accessed data including “government-issued document identity numbers” and pledging to notify people whose records were affected. However, the company has not disclosed how many individuals in total are impacted. It did confirm holding over 150 million driver’s license records in its system.
Repercussions and Next Steps
The breach has drawn attention from U.S. federal agencies. The Pentagon and FBI have both confirmed awareness of the incident, with the latter launching an investigation. The company’s notice mentions that full access to the stolen dataset required “payment,” hinting at some demand for ransom or purchase, though IDScan has yet to clarify whether a formal ransom demand was made.
As of now, IDScan is conducting a full investigation and working to determine scope and risk. Affected individuals are being encouraged to monitor their identity documents closely for fraud or misuse.
This incident marks one of the largest identity breaches in recent years and raises serious questions about how sensitive personal data is stored and protected by identity verification services. Organizations that rely on third-party ID verification must now reckon with how breaches of their providers could ripple out and expose millions of customers.
For the industry, this breach is a major wake-up call. Identity verification companies will need to beef up cloud security, tighten access controls, and transparently disclose issues. For individuals, this may mean added vigilance—watch for credit monitoring alerts, suspicious use of your documents, and strange communications claiming to be from official sources.