IDScan.net, a New Orleans identity-verification company whose scanners and cloud service check driver’s licences for car-rental counters, retailers, dispensaries and bars, confirmed on 10 September 2026 that an unauthorised third party may have accessed and copied customer information stored in accounts on its cloud platform. The confirmation followed a KrebsOnSecurity report of 1 September describing a lookup service on a Russian-language forum offering more than 153 million United States and Canadian licence scans, 10 million identity cards, 3 million travel documents and at least 579,000 medical cards.
Brian Krebs authenticated the data by finding his own Virginia licence in it, front and back, in visible, infrared and ultraviolet captures, and watched about 400,000 new licences appear in 24 hours. IDScan’s own marketing says it holds more than 150 million licence records. The company has not published a count of affected people or customers, has not described how the access happened, and did not answer reporters’ questions. The FBI’s New Orleans field office is investigating and the first class action was filed on 4 September.
Nobody In The File Is A Customer
The people whose licences sit in IDScan’s cloud handed them to a rental agent or a doorman. Their relationship was with the bar, not the verification vendor behind it, and the vendor kept the scan. The corpus set out the position at 26-0111: a population with no account to close and no way to know it was held. This file is that position at the scale of the North American driving-age population, with three spectral captures of each document.
A Scan Is Worse Than A Number
The AssuranceAmerica exposure filed at 26-0726 involved 6.9 million licence numbers. A number can be reissued. A full-colour image of the card, with the infrared and ultraviolet security features captured, is the material a forger needs to pass the same scanner, and it does not expire when the state issues a new number. The corpus draws the reissuance line at 26-0324, and a document image sits on the far side of it.
What The Seller Claimed And What The Company Said
The seller claimed about a year of access. IDScan said it received information on or around 1 September and took immediate steps. The word may in the company’s notice covers both the access and the copying, nine days after a reporter had verified his own licence in the set. The gap between a seller’s dated inventory and a victim’s conditional language is the one this database records in most files, and here the seller had the exhibits.
Compiled from the KrebsOnSecurity report, IDScan’s security notice as quoted by press and contemporaneous coverage, listed below. The 153 million figure is the seller’s listing as verified in samples by Krebs; the company has published no count. Duration of access is the seller’s claim. Graded high on the confirmed facts. Corrections: corrections@forensicpost.com.
- ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolenTechCrunch
- IDScan confirms breach tied to 153 million stolen driver’s licensesBleepingComputer
- IDScan confirms breach after hackers offer 153 million driver’s licensesThe Record
- IDScan confirms breach after 153 million driver’s licenses leakHelp Net Security