IDScan, a major identity verification company based in Louisiana, has confirmed a significant data breach involving the theft of over 150 million driver’s license records. The breach was publicly reported on September 1 by cybersecurity journalist Brian Krebs, who found that hackers had posted a searchable database containing driver’s licenses from the U.S. and Canada on the dark web. The exposed data includes full names, driver’s license numbers, and other government-issued identification details such as passport numbers.
The breach affects a wide range of IDScan’s corporate clients, which span sectors like entertainment venues and cannabis dispensaries, all of which rely on the company’s verification services to authenticate identity documents. Although the company initially only acknowledged investigating the incident, it later confirmed the hack through a notice posted on its website, stating the information was stolen from its cloud storage. IDScan has yet to disclose the exact number of individuals impacted but noted it holds records for more than 150 million people.
High-profile individuals were among those whose information was exposed, including U.S. Secretary of Defense Pete Hegseth, highlighting the sensitive nature of the data compromised. The FBI and Pentagon stated they are aware of the breach and have launched investigations. IDScan also revealed that full access to the stolen data on the dark web required payment, indicating possible ransom demands by the hackers, though the company has not confirmed if a ransom was paid.
IDScan continues to investigate the security incident and is notifying those who may be affected. The breach raises serious concerns about the security of personal data held by verification services that many businesses depend on, given the breadth and sensitivity of the information stolen. The incident underscores ongoing vulnerabilities in data protection for identity verification providers amidst rising cyberattacks.
Start the discussion with a take, question, or market read.