4 min read

IDScan confirms hackers stole millions of driver's licenses during data breach

The ID verification giant confirmed the breach lasted at least several months and implied that the hackers are extorting the company for a ransom.
a photo of a collection of U.S. fake driver's licenses scattered across a table randomly
A collection of fake driver's licenses. Photo via IDScan

Identity verification giant IDScan has confirmed that hackers stole at least 13 to 15 million driver's licenses during a cyberattack and data breach earlier this year, according to the company's notification to state authorities.

The number, which has not been previously reported, is the first time that IDScan has estimated the potential size and scale of the data breach, though the number may change as the company's investigation is ongoing.

Louisiana-based IDScan is an identity verification tech company that allows its corporate customers, like entertainment venues, car rentals, and weed stores, to check the government-issued identity documents of visitors to ensure they are who they say they are, and that they are legally old enough to enter. Someone scans the customer's ID at the door, which is then uploaded and stored in IDScan's cloud, and used to verify future ID scans.

News of a breach at IDScan first emerged in early September when cybersecurity reporter Brian Krebs revealed an ongoing massive theft of identity document scans after discovering a dark web search site that let anyone buy the driver's licenses of millions of people living in the U.S. and Canada. Krebs reported that the hackers claimed to have over 150 million driver's licenses, which they had scraped during an alleged year-long breach of an unspecified identity checking company's servers. Krebs verified his own driver's license record to prove that the data was real, and with the help of others linked the breach to IDScan, which confirmed an incident in a notice on its website soon after.

The dark web search site disappeared following the publication of Krebs' report.

Security and privacy expert Zach Edwards, who helped Krebs trace the leak to IDScan, told me that the breach is particularly damaging as the stolen data links the names, addresses, and photos of millions of people, putting people's privacy and anonymity at risk.

In a September 17 disclosure filed with Illinois' attorney general's office, IDScan said that the hackers had access to the company's systems for at least five months between April 1, 2026 and September 2, 2026, allowing the theft of people's personal information and identity documents from the company's servers.

The company said it learned of the breach around September 1 after receiving information, "including from the FBI," about a security incident involving data stored in its cloud.

"The types of information contained within the affected data may include full names in combination with dates of birth and driver’s license, passport, and/or other government-issued identification numbers," the company said. "IDScan continues to review the potentially impacted data, but preliminary estimates suggest that the total number of affected individuals ranges from 13 to 15 million across the various impacted entities."

IDScan said it's unable to determine how many people in Illinois are specifically affected.

The company reiterated that it has not seen the complete set of stolen data as "full access to the information required payment," implying that the hackers are holding the data hostage for a ransom. It's unclear who the hackers are or if they plan to publish or sell the data to other crime groups.

IDScan did not say how it reached the number of people it believes are affected, or say if it has the technical means, such as logs, to determine the total number of people whose information was stolen. The company did not respond to my request for comment on Saturday.

IDScan said it was continuing to work with the FBI and the U.S. Attorney's Office to investigate.

The company said it had taken steps to mitigate a potential future incident after it "further restricted access to its APIs, including for client accounts, or fully decommissioned them where appropriate," which may lend clues to how the hackers stole so much data to begin with.

A breach of over 150 million U.S. and Canadian driver’s license photos is an anonymity disaster
The breach links the names and photos of millions of people across North America. One expert said this is likely the largest database of facial images ever breached.
~ ~

Thanks for reading, and please share a link on your social media! Reach out with any feedback or comments about this article: this@weekinsecurity.com.