IDScan, a US company specialising in identity document verification, has confirmed that it suffered a breach involving an archive containing over 150 million driver's license records. The admission follows the appearance online of a searchable database containing data on individuals in the United States and Canada.

The scale of the incident is not just due to the number of records held by the company. The exfiltrated information includes full names and driver's license numbers, as well as identifiers associated with other government-issued documents, including passports. According to reports that emerged in recent days, photographs from the documents were also accessible in the database.

This is a particularly sensitive set of data: a driver's license is not a credential that can be quickly replaced like a password, and it is often used as primary proof of an individual's identity. The leak of an archive of this size can therefore fuel identity theft, fraudulent attempts to open financial accounts, highly convincing phishing campaigns, and verification procedures bypassed using real information.

Confirmation following the discovery of an archive on the dark web

The story was made public in early September by cybersecurity journalist Brian Krebs, who identified a site on the dark web capable of searching through a vast collection of driver's licenses. Krebs verified the authenticity of at least part of the material by comparing his own record; an independent verification was also conducted by a security researcher. Furthermore, the archive reportedly contained data on high-profile individuals, including US Secretary of Defense Pete Hegseth.

Initially, IDScan had stated that it was investigating a potential incident without confirming unauthorised access. The notice now published on the company's website changes the picture: the company states that around September 1 it received information regarding a claim of an attack, and acknowledges that the perpetrators stole documents from its cloud environment.

IDScan has not specified the exact number of individuals affected. However, the company reports that it holds over 150 million driver's license records, which is the basis for the scale disclosed so far. Records and individuals are not necessarily equivalent, as the same person may appear multiple times or be associated with multiple documents, but the figure nonetheless reflects the size of the potentially exposed database.

Neither the technical intrusion vector nor the period during which the attackers had access to the systems has been made public. It also remains to be clarified what measures the company used to protect the cloud archive and whether any clients were affected by direct operational fallout. The internal investigation is described as still ongoing.

IDScan's role and why the archive was so large

IDScan is based in Louisiana and provides tools to read, check, and verify identity documents. Its clients operate in diverse sectors: venues and entertainment facilities, as well as cannabis dispensaries, use these services to verify patrons' age or identity. In these procedures, scanning a driver's license serves to reduce manual checks, log entries, and detect invalid documents.

This function turns the company into a central aggregation point for information that would normally remain distributed among businesses, users, and issuing authorities. When a verification provider collects copies or structured fields from documents, it becomes an attractive target: a single breach can place enough data into attackers' hands to reconstruct the identities of millions of people.

The incident also draws attention back to an increasingly common practice in everyday life: handing over a driver's license to enter a venue, buy age-restricted products, or complete an ID check required by a service. For the end user, the gesture takes only a few seconds; behind the scan, however, there may be the storage, transfer, and processing of personal information by multiple entities. Transparency regarding retention periods, purposes, and security measures is essential precisely because government-issued credentials are not easily revocable data.

Risks for affected individuals and the information still missing

The combination of name, driver's license number, photo, and other public or government identifiers is more dangerous than the exposure of an email address alone. It can assist those attempting to impersonate a victim before a human operator or a verification system that considers the document a trusted credential. It can also make fraudulent messages crafted with accurate personal details more effective.

At the same time, available information does not indicate that financial data, passwords, or access codes were stolen. Nor is it known whether the archive was leaked in its entirety, sold, or made accessible through paywalls. IDScan mentions that full access to the information required payment, but did not specify whether the attackers made a ransom demand or whether negotiations took place.

For potentially affected individuals, the most immediate practical consequence is heightened vigilance against communications that use real personal details to appear legitimate. Inquiries regarding banking, accounts, document renewals, or alleged identity verifications warrant verification through official channels, without using links or contact information provided in the message. It is also advisable to monitor unusual activity and requests tied to one's identity, as reissuing a driver's license does not necessarily eliminate the exposure of previously recorded data.

There is currently no detailed individual notification process or list of affected jurisdictions. IDScan opted to publish a notice on its website to inform potentially affected parties. The company did not respond to requests for comment regarding the circumstances of the incident reported in the press.

Growing pressure on vendors and authorities

The Pentagon stated it was aware of the suspected breach prior to formal confirmation from IDScan. The FBI also stated it is investigating. The involvement of federal authorities is understandable given the nature of the data and the reported presence of high-profile records in the archive, but it does not imply that attribution has been established or that the attackers' identities have been disclosed.

In the next steps, three elements will matter most: the exact extent of the extracted data, how access to the cloud systems occurred, and the protections that IDScan will make available to affected individuals. It will also be necessary to see whether the company will communicate directly with exposed individuals and with the clients who used the service to collect documents.

For the digital identity sector, the incident is a stark reminder. Document verification is presented as a tool for trust and fraud prevention, but that trust depends on the ability to protect the archives created throughout the process. If the very data used to prove who we are is compromised, the potential damage lingers over time and extends well beyond the single breached access.

Sources