News

IDScan confirms breach of 150M-plus driver licenses

IDScan.net's September 4, 2026 website notice says an unauthorized party may have accessed customer cloud data after a September 1 tip. The company does not confirm a 153 million victim count. Free credit monitoring enrolls at 1-833-516-2980.

IDScan confirms breach of 150M-plus driver licenses

IDScan.net posted a Notification of Data Security Incident on 4 September 2026. The Louisiana identity-verification vendor said that on or around 1 September 2026 it received information indicating certain data may have been accessed without authorization.

This is a company website incident notice plus later confirmation in the trade press. It is not a CISA advisory, not a DOJ charging document, and not a company-stated headcount of affected people.

The notice says IDScan secured systems and hired third-party specialists. The investigation is still open. An unauthorized third party may have accessed or copied certain customer information stored in IDScan.net cloud accounts. Fields that may be in that set include full names and driver's license or other government-issued identification numbers.

TechCrunch (Zack Whittaker, 10 September 2026) and BleepingComputer (Lawrence Abrams, 10 September 2026) tie the notice to Brian Krebs's dark-web reporting of a searchable cache of about 150 million to 153 million US and Canadian licenses, including photos. The FBI is investigating. The Pentagon has said it is aware of the suspected breach. TechCrunch notes the company holds over 150 million driver's license records and still does not say how many individuals were affected.

The company notice never confirms a hard 153 million victim count. Krebs verified samples from the Nexus dark-web service, including his own record. That reporting is separate from IDScan's "may have accessed" wording.

The notice also says full access to the information required payment. In an abundance of caution, IDScan is notifying potentially impacted people and offering free credit monitoring and identity protection. Enrollment is at 1-833-516-2980, Monday through Friday, 8 AM to 8 PM ET, excluding holidays. Written questions go to 8814 Veterans Memorial Blvd, Suite 3-124, Metairie, LA 70003.

Related vendor and incident coverage on Cyberpresso includes the ChatGPT sandbox cross-account leak, OpenAI's Hugging Face incident report, WatchGuard Firebox ransomware use in KEV, and the Telerik UI padding-oracle RCE.

If you scanned licenses through IDScan or a customer of theirs, call 1-833-516-2980 this week to enroll in the free monitoring, treat 153 million as Krebs and wire reporting rather than a company-confirmed victim count, and put every ID-verification vendor on the record for retention and current incident status.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free