IDScan Confirms License Data Theft as 150 Million Records Surface
IDScan confirms hackers stole driver’s license data from its cloud as a dark web database exposes records for over 150 million Americans and Canadians.
Summary
IDScan confirmed on September 10, 2026, that hackers stole driver’s licenses from its cloud, including full names, license numbers and numbers from other government documents such as passports. The Louisiana identity verification provider, used by corporate customers including entertainment venues and cannabis dispensaries, said it learned around September 1 of a breach claim and is still investigating. It has not confirmed a report that the intrusion lasted a year.
Brian Krebs found a dark web site allowing anyone to search records and photos for over 150 million people in the United States and Canada, while full access required payment. He authenticated his own record; the database also included U.S. Secretary of Defense Pete Hegseth and a security researcher who separately verified their data. IDScan has not disclosed the affected population, though it says it holds over 150 million driver’s license records, or whether hackers demanded ransom to prevent release. The FBI is investigating, the Pentagon is aware, and IDScan has posted notice for potentially affected individuals while its inquiry continues.
Positives
- IDScan publicly confirmed the cloud data theft and posted notice for potentially affected individuals.
- Brian Krebs authenticated his own record, while a security researcher separately verified data in the exposed database.
- The FBI is investigating the breach, adding federal scrutiny to IDScan’s continuing inquiry.
- The Pentagon confirmed awareness after Defense Secretary Pete Hegseth’s information appeared in the database.
Risks & concerns
- Over 150 million U.S. and Canadian driver’s license records and photos were searchable through a dark web site.
- Full names, license numbers and numbers from other government documents, including passports, were stolen from IDScan’s cloud.
- IDScan has not disclosed how many people were affected or whether hackers demanded ransom to prevent the data’s release.
- A reported year-long intrusion remains unconfirmed, leaving the breach duration and full scope unresolved.
- Entertainment venues, cannabis dispensaries and other IDScan customers submitted identity documents now potentially included in the breach.