ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
ID verification firm IDScan has acknowledged a data breach in which hackers stole driver’s license records from its cloud systems, including full names, driver’s license numbers and identity numbers from other government-issued documents. The disclosure follows a dark-web report that a searchable database held information for more than 150 million people in the United States and Canada, a claim an independent journalist verified using his own record.

Why It Matters
The breach involves highly sensitive personally identifying information tied to government IDs and appears to cover a very large number of records, raising risks for affected individuals and prompting investigations by federal authorities. IDScan’s services are widely used by businesses to verify customers’ identities, meaning the incident could affect consumers across multiple sectors.
Key Facts
- company: IDScan
- confirmation: IDScan confirmed on its website that driver’s licenses were stolen from its cloud systems
- types of data stolen: full names, driver’s license numbers, and identity numbers from other government-issued documents (e.g., passports)
- records implicated: IDScan holds over 150 million driver’s license records; an independent report described a searchable dark-web database for more than 150 million people in the U.S. and Canada
- disclosure timing: IDScan said it received information about a claimed hack on or around September 1, 2026
ID verification provider IDScan has publicly confirmed that attackers accessed and removed driver’s license records from the company’s cloud storage. According to a notice on its website, the stolen data includes individuals’ full names, driver’s license numbers and identity numbers from other government-issued documents such as passports.
The confirmation follows reporting by independent cybersecurity journalist Brian Krebs, who said a dark-web site offered a searchable database containing data for more than 150 million people in the United States and Canada, including photos. Krebs said he validated the dataset by locating his own record; the cache reportedly included high-profile entries such as U.S. Secretary of Defense Pete Hegseth and a security researcher who also confirmed his information.
IDScan, a Louisiana-based firm whose identity-checking tools are used by businesses from entertainment venues to cannabis dispensaries, said its investigation is ongoing. The company noted it learned about a claim of a hack on or around September 1 and that "full access to the information required payment," language that appears to reference a demand tied to access to the stolen files. IDScan has not specified how many individuals were affected and did not respond to TechCrunch’s request for comment about whether a ransom demand was made.
Federal authorities have taken notice: the Pentagon told TechCrunch it was aware of the suspected breach, and the FBI said it is investigating. The scale and sensitivity of the exposed records prompted IDScan to post a notice to alert potentially affected people while its inquiry continues.
Keep Reading

US Army places $11M bet on Austin-based GPS alternative Tern

European founders and VCs urge lawmakers ‘to get EU Inc right’

Defense tech Mach Industries doubles valuation to $3.7B in 3 months
