Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. IDScan disclosed the incident in a September 4 security notice, saying it learned on or around September 1 that certain data may have been accessed without authorization. "Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident," IDScan said.
The company says its investigation remains ongoing but has determined that an unauthorized third party "may" have accessed or copied customer information stored within accounts on the IDScan.net cloud. The exposed information can include customers' full names, and driver's license or other government-issued identification numbers. While not mentioned in the notification, the breach reportedly also allowed threat actors to steal scans of driver's licenses.
Spotted IDScan's breach notification, which was published on September 4 but configured with a noindex directive that instructed search engines not to index the page. BleepingComputer previously reported on September 4 that multiple lawsuits had been filed against IDScan after hackers allegedly breached the company and offered access to a database containing more than 153 million driver's licenses. At the time, IDScan had not publicly acknowledged the incident or responded to BleepingComputer's requests for comment.
The company said that although full access to the exposed information required payment, it is notifying potentially impacted individuals "in an abundance of caution" and providing free credit monitoring and identity protection services. Massive ID database linked to IDScan The incident first came to light after Brian Krebs reported on September 1 that a dark-web platform called "Nexus" was advertising access to more than 153 million U.S. And Canadian driver's license scans.
The ID checking company said the data breach included people's full names and driver's licenses and other government-issued identity documents. ID verification service IDScan has confirmed that a data breach involved the theft of driver’s licenses from its systems, a week after a report said the identity document checker had been breached during a year-long hack.
The company said in a website notice that hackers stole the driver’s licenses from the company’s cloud; the stolen information includes people’s full names and driver’s license numbers, along with identity numbers from other government-issued documents, such as passports. The Louisiana-based firm is used by corporate customers from entertainment venues to cannabis dispensaries to check and verify the identity documents of their customers.
The notice is the company’s first acknowledgement that it had been hacked. The company said last week that it was investigating an incident, but had not yet confirmed an intrusion.
IDScan said in its notice that it “received information” on or around September 1 about a claim of a hack, on the same day that independent cybersecurity journalist Brian Krebs first reported a data breach at IDScan. Krebs reported that he was alerted to a website on the dark web that allowed anyone to search the driver’s license information of over 150 million people living in the United States and Canada, including accessing their photos.
Krebs verified the authenticity of the data by examining his own record. The database also contained high-profile individuals, including the U.S.
Secretary of Defense Pete Hegseth, and a security researcher who also verified his data for Krebs’ report. The Pentagon told last week that it was aware of the suspected breach, and a spokesperson for the FBI said it was also investigating the incident.
IDScan said on its website its investigation was ongoing. The company’s statement said that, “though full access to the information required payment” — likely referring to a demand for money made by the hackers to access the full cache of stolen data — the company was providing notice on its website to notify potentially affected individuals.
IDScan has not said how many individuals are affected but notes on its website that it holds over 150 million driver’s license records. IDScan did not respond to ’s request for comment about the incident, such as whether the hackers contacted the company with a ransom demand not to release the data.
Topics cyberattack, cybersecurity, data breach, driver’s license, Government & Policy, Security When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker Security Editor Zack Whittaker is the security editor. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@ com.
View Bio October 13 – 15 San Francisco Don’t miss out. The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era?
REGISTER NOW Most Popular Automattic’s board forces CEO Matt Mullenweg into leave of absence Julie Bort Sarah Perez Apple unveils its first foldable, the iPhone Duo Ivan Mehta OpenAI fought dirty on career-making math problem, says NYU mathematician Russell Brandom A secret new Elizabeth Holmes documentary stuns Telluride Connie Loizos Mobility: Tesla Cybercab hits the road — and a snag Kirsten Korosec Hikers rescued after using Google Gemini for planning Anthony Ha Feds launch investigation into Tesla’s Cybercab deployment Sean O'Kane Kirsten Korosec.
The service also allegedly contained 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified samples from the database by searching for records belonging to himself and others who consented to the searches and traced the exposed information back to IDScan.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
