Overview
- IDScan publicly confirmed on Thursday that hackers accessed driver’s license records stored in its cloud and that an internal investigation with third-party specialists is ongoing.
- The exposed records reportedly include full names, driver’s license and other government ID numbers, and high-fidelity scans or photos that cannot be changed and can be used for long-term impersonation or fraud.
- The FBI has opened an inquiry and Pentagon officials have acknowledged awareness of the incident as IDScan says it is cooperating with federal law enforcement.
- The dataset was advertised on dark‑web marketplaces such as Nexus and Exploit before listings were scrubbed, though copies and resale attempts persist and multiple lawsuits have been filed against IDScan.
- Security experts warn the breach highlights risks from centralized ID‑verification vendors and could trigger years of remediation, regulatory scrutiny, limits on data retention, and increased identity‑protection costs for affected people.