Overview
- IDScan said it learned on or around September 1 that certain customer data stored on its cloud may have been accessed and that a third-party forensic team is investigating the incident.
- Reporting and researcher verification linked a searchable dark-web cache of roughly 150–153 million U.S. and Canadian driver’s license scans to the company, with records showing full names, license numbers and other government ID numbers.
- Security journalist Brian Krebs confirmed sample records by finding his own entry and traced the listing to a cybercrime service called Nexus and posts on the Russian forum Exploit before the listings were taken offline or scrubbed.
- Federal authorities including the FBI and Pentagon have been notified and opened inquiries, multiple civil lawsuits have been filed against IDScan, and the company is notifying potentially affected people and offering free identity‑protection services.
- The breach highlights the risk of centralizing immutable ID images at third‑party verification vendors because photos and government ID numbers cannot be reset, so consumers should consider credit freezes, close monitoring and contacting their motor‑vehicle agency.