IDScan Confirms Data Breach Linked to 153 Million Stolen Driver's Licenses
Identity verification firm says hackers accessed customer data in its cloud platform, raising identity theft risks.

Key Takeaways
- IDScan confirmed a data breach involving unauthorized access to customer data in its cloud platform.
- The breach is linked to a reported database of over 153 million driver's license scans, though this figure is unverified.
- Exposed driver's license data poses significant identity theft and fraud risks.
- IDScan has not yet disclosed the attack vector or full scope of the breach.
- Affected individuals should monitor for official guidance and consider credit monitoring.
Quick answers
- What happened?
- IDScan, an identity verification company, has confirmed that hackers accessed customer data stored in its cloud platform, following reports linking the company to a massive database containing over 153 million driver's license scans. The breach potentially exposes sensitive personal information, and the full scope remains under investigation.
- Which products are affected?
- cloud platform
- What should defenders do?
- IDScan has not provided specific mitigation steps. Affected customers should monitor official communications from IDScan, consider credit monitoring and identity theft protection, and remain vigilant for suspicious activity. Organizations using IDScan services should review their security posture and consider additional safeguards.
Identity verification company IDScan has confirmed a data breach in which unauthorized individuals accessed customer data stored in its cloud platform. The confirmation comes days after reports linked the company to a database containing more than 153 million driver's license scans, raising concerns about the scale of the exposure.
According to IDScan, the breach involved unauthorized access to customer data, but the company has not yet disclosed the specific method of intrusion or the exact types of data compromised. The reported figure of 153 million records is based on external reports and has not been independently verified by IDScan.
The breach could have significant implications for individuals whose driver's license scans were exposed, as such data can be used for identity theft, financial fraud, and other malicious activities. The full impact, including which customers and regions are affected, remains unclear.
IDScan has not yet provided specific mitigation steps or patch information. Affected customers are advised to monitor official communications from IDScan and consider protective measures such as credit monitoring and identity theft protection services.
This incident underscores the critical importance of securing identity verification platforms, which hold highly sensitive personal data. Organizations that rely on such services should assess their exposure and ensure robust security measures are in place.
Security Details
IDScan confirmed that hackers accessed customer data stored in its cloud platform. The exact intrusion method is undisclosed. The reported database contains over 153 million driver's license scans, but this number is based on external reports and not yet verified by IDScan. The types of data compromised and the full list of affected customers are not yet public.
Affected products
cloud platform
Mitigation
IDScan has not provided specific mitigation steps. Affected customers should monitor official communications from IDScan, consider credit monitoring and identity theft protection, and remain vigilant for suspicious activity. Organizations using IDScan services should review their security posture and consider additional safeguards.
Sources
BleepingComputer
IDScan confirms breach tied to 153 million stolen driver’s licenses
Sep 10, 2026 · 14:55
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

Bitget Reports $388M Loss Following Exploitation of Third-Party Security Product Flaw
Bitget disclosed that an attacker stole approximately $388 million by exploiting a vulnerability in a third-party security product integrated into the exchange's infrastructure. The threat actor used the flaw to obtain high-level internal credentials, which were subsequently used on September 24 to issue fraudulent withdrawal commands to Bitget's wallet system. The exchange confirmed that most user funds remain secure, though the full extent of exposure is under investigation.



