01Summary
KrebsOnSecurity broke the story around 1–2 September 2026. On 4 September IDScan.net confirmed that an unauthorised third party "may have accessed and/or copied certain customer information", including full names and driver's licence and government ID numbers. A dark-web marketplace listing claimed more than 153 million driver's licence scans plus about 10 million ID cards, 3 million travel documents and 579,000 medical cards. TechCrunch reported the data included photos of about 150 million drivers and was being held for ransom. USA Today reported an FBI investigation. IDScan has not published a verified count.
02Key revelations
- 01Businesses' ID-scanning at the door fed a single centralised store of identity documents.
03Technical analysis
- Attack vector
- Unauthorised access to a cloud environment
04Victims and impact
Additional victims
- Business customers of IDScan.net
Countries affected
- United States
- Canada
05Data exposed
Data types
- Full names
- Driver's licence numbers
- Government ID numbers
- ID document scans and photos
06Timeline
- 2026-09-01IDScan learns of the unauthorised access; KrebsOnSecurity reports.
- 2026-09-04IDScan publishes a security notice.
- 2026-09-10Wider mainstream coverage (TechCrunch).
07On the record
May have accessed and/or copied certain customer information.
08Legal
FBI investigation reported.
09Significance and legacy
Significance
Possibly the largest identity-document breach on record for North America.
10Disclosure and media
Publishing organisations
- KrebsOnSecurity
- TechCrunch
- BleepingComputer
- USA Today
11Sources
References
- [1]BleepingComputer: https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/
- [2]Tech Insider: https://tech-insider.org/idscan-breach-confirmed-enterprise-clients-2026/









