IDScan confirms hackers stole millions of driver's licenses during data breach
Identity verification giant IDScan has confirmed that hackers stole at least 13 to 15 million driver's licenses during a cyberattack and data breach earlier this year, according to the company's notification to state authorities.
The number, which has not been previously reported, is the first time that IDScan has estimated the potential size and scale of the data breach, though the number may change as the company's investigation is ongoing.
Louisiana-based IDScan is an identity verification tech company that allows its corporate customers, like entertainment venues, car rentals, and weed stores, to check the government-issued identity documents of visitors to ensure they are who they say they are, and that they are legally old enough to enter. Someone scans the customer's ID at the door, which is then uploaded and stored in IDScan's cloud, and used to verify future ID scans.
News of a breach at IDScan first emerged in early September when cybersecurity reporter Brian Krebs revealed an ongoing massive theft of identity document scans after discovering a dark web search site that let anyone buy the driver's licenses of millions of people living in the U.S. and Canada. Krebs reported that the hackers claimed to have over 150 million driver's licenses, which they had scraped during an alleged year-long breach of an unspecified identity checking company's servers. Krebs verified his own driver's license record to prove that the data was real, and with the help of others linked the breach to IDScan, which confirmed an incident in a notice on its website soon after.
The dark web search site disappeared following the publication of Krebs' report.
Security and privacy expert Zach Edwards, who helped Krebs trace the leak to IDScan, told me that the breach is particularly damaging as the stolen data links the names, addresses, and photos of millions of people, putting people's privacy and anonymity at risk.
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent stories include: A breach of over 150 million U.S. and Canadian driver's license photos is an anonymity disaster | Apple opens the door to a nightmare world of always-listening tech | How residential proxy networks are hiding hackers in your home | The top highlights from Black Hat, Def Con, and BSides Las Vegas 2026 | When AI chatbots and LLMs get legal, check your privilege | Vigilantism comes for Flock
In a September 17 disclosure filed with Illinois' attorney general's office, IDScan said that the hackers had access to the company's systems for at least five months between April 1, 2026 and September 2, 2026, allowing the theft of people's personal information and identity documents from the company's servers.
The company said it learned of the breach around September 1 after receiving information, "including from the FBI," about a security incident involving data stored in its cloud.
"The types of information contained within the affected data may include full names in combination with dates of birth and driver’s license, passport, and/or other government-issued identification numbers," the company said. "IDScan continues to review the potentially impacted data, but preliminary estimates suggest that the total number of affected individuals ranges from 13 to 15 million across the various impacted entities."
IDScan said it's unable to determine how many people in Illinois are specifically affected.
The company reiterated that it has not seen the complete set of stolen data as "full access to the information required payment," implying that the hackers are holding the data hostage for a ransom. It's unclear who the hackers are or if they plan to publish or sell the data to other crime groups.
IDScan did not say how it reached the number of people it believes are affected, or say if it has the technical means, such as logs, to determine the total number of people whose information was stolen. The company did not respond to my request for comment on Saturday.
IDScan said it was continuing to work with the FBI and the U.S. Attorney's Office to investigate.
The company said it had taken steps to mitigate a potential future incident after it "further restricted access to its APIs, including for client accounts, or fully decommissioned them where appropriate," which may lend clues to how the hackers stole so much data to begin with.

Thanks for reading, and please share a link on your social media! Reach out with any feedback or comments about this article: this@weekinsecurity.com.
