ID verification company IDScan has confirmed that hackers stole driver’s license records and other government-issued identity documents from its cloud systems, in what appears to be one of the largest identity document breaches on record.
The Louisiana-based company published a notice on its website acknowledging the intrusion, stating it “received information” on or around September 1, 2026 about a claim of a hack. That date coincides with a report by independent cybersecurity journalist Brian Krebs, who first alerted the public to a dark web site allowing anyone to search the driver’s license information — including photos — of more than 150 million people in the United States and Canada. IDScan notes on its website that it holds over 150 million driver’s license records but has not specified how many individuals are affected.
The stolen data includes full names, driver’s license numbers, and identity numbers from other government-issued documents such as passports. Krebs verified the authenticity of the database by examining his own record. The database also contained records for high-profile individuals, including U.S. Secretary of Defense Pete Hegseth, and a security researcher who independently confirmed his data for Krebs’ report.
IDScan provides identity document verification services to corporate customers including entertainment venues and cannabis dispensaries. The company said in its notice that “full access to the information required payment,” a reference that likely points to a demand by the hackers for money to access the full stolen dataset. IDScan did not respond to requests for comment on whether a formal ransom demand was made.
The Pentagon confirmed it was aware of the suspected breach, and an FBI spokesperson said the agency is also investigating. IDScan said its investigation remains ongoing.
For the tens of millions of people whose identity documents may have been exposed, this breach could make their personal information accessible to bad actors, potentially enabling identity fraud and other misuse of government-issued credentials.
Source: TechCrunch