ID verification company IDScan disclosed that hackers accessed its systems without authorization, a breach later linked to a criminal marketplace called Nexus selling scans of over 170 million identity documents. Security researcher Brian Krebs verified the stolen trove includes 153 million driver's licenses, 10 million ID cards, 3 million passports and travel documents, and hundreds of thousands of medical cards, mostly belonging to US residents with some Canadian records included. The attackers claimed to have quietly siphoned data from IDScan's systems for more than a year before being detected.
cnet.com
· 2026-09-10
IDScan.net, an identity verification company, disclosed that an unauthorized third party may have accessed customer accounts containing full names and government ID numbers. In response, the company is notifying affected customers and providing free credit monitoring and identity protection services while cooperating with federal law enforcement.
engadget.com
· 2026-09-10
Surfshark disclosed that hackers gained access to an internal engineering test server after a misconfiguration left it exposed to the internet, along with a separate proxy server used for content-accessibility optimization. The company says the exposed systems contained build credentials, code history and system binaries, but no user identities, IP addresses, encryption keys or browsing traffic were compromised. Suspicious activity was spotted on August 31, contained by September 2, and remediation finished three days later.
bleepingcomputer.com
· 2026-09-10
IDScan, a Louisiana-based identity verification firm used by venues and dispensaries, confirmed hackers stole driver's licenses and other government ID data from its cloud systems. The admission follows a report by cybersecurity journalist Brian Krebs that a dark web site allowed searches of over 150 million U.S. and Canadian residents' license records, including photos and data belonging to high-profile figures like Defense Secretary Pete Hegseth.
techcrunch.com
· 2026-09-10
Identity verification firm IDScan has acknowledged that hackers accessed customer data stored on its IDScan.net cloud platform, days after reports tied the company to a leaked database of over 153 million driver's license scans being sold on the dark web. The company said it discovered the unauthorized access around September 1 and is still investigating the scope, but confirmed exposed data can include names and government ID numbers.
bleepingcomputer.com
· 2026-09-10
AdaptHealth has confirmed that a cyberattack discovered in July, linked to the ShinyHunters group, exposed personal and health data belonging to about 4.1 million patients. The company says attackers gained access on June 5 through a social engineering attack that compromised a third-party contractor's privileged account, reaching cloud-based patient management and record systems. Exposed data includes names, contact and demographic details, health insurance information, and health records.
bleepingcomputer.com
· 2026-09-09
Veradigm, the Chicago-based healthcare technology firm formerly known as Allscripts, disclosed in an SEC filing that an attacker used stolen credentials from a third-party vendor to access a customer-service API and copy patient data. The exposed information includes personal details and Social Security numbers for a limited number of patients, though clinical records were not accessed. The Gentlemen ransomware group has claimed responsibility for the attack.
bleepingcomputer.com
· 2026-09-09
The ShinyHunters extortion group says it broke into Florida's DAVID driver database used by law enforcement, allegedly exploiting a password-reset weakness to hijack multiple accounts, including one belonging to an FBI agent. The hackers claim to have exfiltrated over 200,000 driver records and posted Jeffrey Epstein's DMV file—complete with his address, Social Security number, and vehicle history—as proof, while listing the Florida Highway Safety and Motor Vehicles agency on their leak site to pressure payment.
bleepingcomputer.com
· 2026-09-08
Mathspace, an online maths learning platform used in thousands of schools, revealed that hackers breached its self-hosted Metabase reporting tool and stole personal data on students, parents, guardians and staff. The company said attackers first gained access on August 10, extracted data on August 27, and the breach was confirmed on September 3, affecting 1,079,819 people in Australia and New Zealand. Mathspace stated that passwords, academic records and authentication credentials were not compromised.
bleepingcomputer.com
· 2026-09-07
Trezor has revised the scope of its August data breach, now saying 81,000 customers were affected instead of the roughly 14,000 first reported. The increase stems from logistics partner ShipMonk failing to delete older records as its contract required, exposing details of 67,000 additional U.S. customers who ordered between November 2019 and August 2021.
bleepingcomputer.com
· 2026-09-07
A dark web identity-theft service is selling scans of more than 153 million U.S. and Canadian driver's licenses, apparently sourced from a Louisiana-based identity verification company that supplies age- and ID-checking services. Investigator Brian Krebs found the site was still adding hundreds of thousands of new records daily, including 400,000 added the day the breach was exposed, before the service was finally taken offline.
techdirt.com
· 2026-09-04
A trove of roughly 153 million scanned driver's licenses, reportedly stolen from an identity verification company, has surfaced for sale online. The leak underscores how centralized repositories of scanned IDs, built to confirm users' identities, have themselves become prime targets for hackers.
gizmodo.com
· 2026-09-02