Skip to content
Tech News
← Back to articles

IDScan confirms breach tied to 153 million stolen driver’s licenses

read original get Amazon Basics 12-Sheet Micro-Cut Shredder → more articles
Why This Matters

IDScan's breach shows how identity-verification vendors have become high-value single points of failure: one compromised cloud platform reportedly exposed scans and numbers from more than 153 million driver's licenses, data that can't be reset like a password. The company also only confirmed the incident after journalists and lawsuits forced the issue, and published its notice with a noindex tag that kept it out of search results.

Key Takeaways
Worth a Look

Amazon Basics 12-Sheet Micro-Cut Shredder — When breaches like IDScan's put license numbers and ID scans into criminals' hands, the least you can do is stop leaking your own paper trail. This micro-cut shredder turns old IDs, expired cards, bank statements and mail into confetti-sized bits, and it handles credit cards too. A simple desk-side habit that makes dumpster-diving identity thieves' work useless.

See Amazon Basics 12-Sheet Micro-Cut Shredder on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans.

IDScan disclosed the incident in a September 4 security notice, saying it learned on or around September 1 that certain data may have been accessed without authorization.

"Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident," IDScan said.

The company says its investigation remains ongoing but has determined that an unauthorized third party "may" have accessed or copied customer information stored within accounts on the IDScan.net cloud.

The exposed information can include customers' full names, and driver's license or other government-issued identification numbers. While not mentioned in the notification, the breach reportedly also allowed threat actors to steal scans of driver's licenses.

TechCrunch spotted IDScan's breach notification, which was published on September 4 but configured with a noindex directive that instructed search engines not to index the page.

BleepingComputer previously reported on September 4 that multiple lawsuits had been filed against IDScan after hackers allegedly breached the company and offered access to a database containing more than 153 million driver's licenses.

At the time, IDScan had not publicly acknowledged the incident or responded to BleepingComputer's requests for comment.

The company said that although full access to the exposed information required payment, it is notifying potentially impacted individuals "in an abundance of caution" and providing free credit monitoring and identity protection services.

Massive ID database linked to IDScan

... continue reading