Identity verification firm IDScan has acknowledged that hackers accessed customer data stored on its IDScan.net cloud platform, days after reports tied the company to a leaked database of over 153 million driver's license scans being sold on the dark web. The company said it discovered the unauthorized access around September 1 and is still investigating the scope, but confirmed exposed data can include names and government ID numbers.
AdaptHealth has confirmed that a cyberattack discovered in July, linked to the ShinyHunters group, exposed personal and health data belonging to about 4.1 million patients. The company says attackers gained access on June 5 through a social engineering attack that compromised a third-party contractor's privileged account, reaching cloud-based patient management and record systems. Exposed data includes names, contact and demographic details, health insurance information, and health records.
Veradigm, the Chicago-based healthcare technology firm formerly known as Allscripts, disclosed in an SEC filing that an attacker used stolen credentials from a third-party vendor to access a customer-service API and copy patient data. The exposed information includes personal details and Social Security numbers for a limited number of patients, though clinical records were not accessed. The Gentlemen ransomware group has claimed responsibility for the attack.
The ShinyHunters extortion group says it broke into Florida's DAVID driver database used by law enforcement, allegedly exploiting a password-reset weakness to hijack multiple accounts, including one belonging to an FBI agent. The hackers claim to have exfiltrated over 200,000 driver records and posted Jeffrey Epstein's DMV file—complete with his address, Social Security number, and vehicle history—as proof, while listing the Florida Highway Safety and Motor Vehicles agency on their leak site to pressure payment.
Mathspace, an online maths learning platform used in thousands of schools, revealed that hackers breached its self-hosted Metabase reporting tool and stole personal data on students, parents, guardians and staff. The company said attackers first gained access on August 10, extracted data on August 27, and the breach was confirmed on September 3, affecting 1,079,819 people in Australia and New Zealand. Mathspace stated that passwords, academic records and authentication credentials were not compromised.
Trezor has revised the scope of its August data breach, now saying 81,000 customers were affected instead of the roughly 14,000 first reported. The increase stems from logistics partner ShipMonk failing to delete older records as its contract required, exposing details of 67,000 additional U.S. customers who ordered between November 2019 and August 2021.
IDScan, an identity verification firm used by rental car companies, retailers and other businesses, faces multiple lawsuits after a dark-web service called Nexus allegedly offered access to over 153 million U.S. and Canadian driver's licenses along with millions of other ID documents. Journalist Brian Krebs traced the leaked data back to IDScan, and the FBI's New Orleans office has reportedly opened an investigation. IDScan has not confirmed a breach occurred or commented publicly on the allegations.
A dark web identity-theft service is selling scans of more than 153 million U.S. and Canadian driver's licenses, apparently sourced from a Louisiana-based identity verification company that supplies age- and ID-checking services. Investigator Brian Krebs found the site was still adding hundreds of thousands of new records daily, including 400,000 added the day the breach was exposed, before the service was finally taken offline.
A trove of roughly 153 million scanned driver's licenses, reportedly stolen from an identity verification company, has surfaced for sale online. The leak underscores how centralized repositories of scanned IDs, built to confirm users' identities, have themselves become prime targets for hackers.
A dark web marketplace called Nexus emerged this week claiming to sell searchable access to over 150 million U.S. and Canadian driver's licenses and passports, with roughly half a million new records added daily. Security journalist Brian Krebs and researcher Zach Edwards traced the likely source to IDScan, a Louisiana-based identity verification firm used by major consumer brands to check tens of millions of IDs monthly. Both researchers confirmed their own personal documents appeared in the database, and Defense Secretary Pete Hegseth's photo was also reportedly found among the listings.
A criminal hacking group has published personal data belonging to nearly 8.7 million customers of Manchester, London Stansted and East Midlands airports after breaching Manchester Airports Group's systems. The attackers had demanded a ransom, which MAG did not pay, and have now released roughly half a terabyte of stolen information—including contact details, vehicle registrations and postcodes—free of charge to other criminals via their own website.
Aesto LLC, which runs Aesto Health's data migration and archiving service for healthcare providers, revealed that an unauthorized actor accessed its AWS infrastructure between December 2 and 18, 2025. The breach, confirmed internally on May 26 after forensic review, exposed sensitive records for over 9.5 million people including Social Security numbers, driver's license numbers, and medical information tied to 29 healthcare clients such as VillageMD and Together Women's Health.