Never lose a customer to a missed message
An AI agent trained on your own business, replying in seconds, in any language, on every channel your customers already use.
Identity verification firm IDScan confirmed on 10 September 2026 that attackers took data from its cloud systems. The IDScan data breach involves scans of more than 150 million driver’s licences, alongside millions of other government-issued documents. Reports put the figure at 153 million US and Canadian licences.
The stolen records include full names, driver’s licence numbers and identity numbers taken from documents such as passports. The company is notifying affected people and offering free credit monitoring and identity protection.
The FBI’s New Orleans field office opened an investigation. IDScan operates from Louisiana.
How the IDScan data breach came to light
The public trail started before the company confirmed anything. A dark web platform appeared advertising a searchable database of identity documents for sale.
That listing claimed more than 153 million driver’s licence records, over 10 million ID cards, and millions of further documents including medical cards and travel documents. The FBI began probing the reported breach in early September.

IDScan said it received information around 1 September indicating that data may have been accessed without authorisation. Its confirmation followed on 10 September.
The breach operators say they pulled data continuously over a year into their private database. That claim comes from the people selling the records, and no independent source confirms it.
The gap between the first public listing and the company’s confirmation ran roughly ten days. Victims therefore learned of the sale before they learned whose systems it came from.
Why an ID verification vendor holds this much
IDScan’s corporate customers range from entertainment venues to cannabis dispensaries. Those businesses check identity documents at the door or at the point of sale.
Verification services sit in the middle of that check. They receive the document image, confirm it, and return a result. Retaining the scan afterwards turns a transaction into a stored record.
That accumulation is what makes vendor breaches different from breaches at any single venue. One compromised supplier exposes every customer that supplier served.
We saw the same structural problem in our coverage of the American Tower data breach and in our report on the TruStage outage lawsuits.
What a stolen licence scan can actually do
A driver’s licence image is more dangerous than a stolen password. Anyone can change a password in seconds. Licence numbers do not work that way.
Document images are the raw material for account takeover at services that verify identity by photo. They also support synthetic identity fraud, where real details from several people are combined into a new profile.
Credit monitoring helps with the visible part. It flags new accounts opened in a person’s name. It does nothing about a document image circulating indefinitely.
Replacing a licence is possible in most jurisdictions but rarely quick. The number often stays the same.
Why this lands differently in each country
The records span both the United States and Canada. Remedies differ across that border and across individual states and provinces.
Most US states let residents freeze credit files with each of the three national bureaus at no cost. Canada operates a smaller bureau market, and the equivalent alert process varies by province.
Replacing a licence also differs. Some jurisdictions issue a fresh number after documented fraud. Others reissue the same number on a new card.
Anyone outside North America is not automatically clear either. The advertised database included travel documents, and passport details travel across borders in a way licence numbers do not.
A researcher from Hanoi who once showed a passport at a venue using this vendor sits in a different position from a local resident. The document she presented carries weight anywhere, and no single agency can reissue confidence in it.
Steps worth taking now
Place a credit freeze rather than relying on monitoring alone. A freeze blocks new accounts instead of reporting them after the fact.
Accept the identity protection if the company notified you. It costs nothing and creates a paper trail if disputes follow.
Treat unexpected identity-verification prompts with suspicion. An attacker holding a document image may attempt verification in your name.
Check statements more often for the next few months. Fraud from bulk data sales often surfaces well after the sale.
Keep the notification letter if one arrives. Banks and insurers frequently ask for proof of the underlying breach before they write off a disputed charge, and a dated letter settles that question faster than a news article does.
Points readers keep raising about the leak
- How many records were taken? Reports describe scans of more than 153 million US and Canadian driver’s licences, plus over 10 million ID cards and further documents.
- What data was in them? Full names, driver’s licence numbers and identity numbers from other government-issued documents such as passports.
- When did IDScan find out? The company said it received information around 1 September and confirmed the breach on 10 September 2026.
- Is law enforcement involved? Yes. The FBI’s New Orleans field office opened an investigation.
- What is IDScan offering? Notification of affected individuals plus free credit monitoring and identity protection.
- How long was data being taken? The breach operators claim exfiltration ran continuously over a year. That claim is theirs and is unverified.
More security reporting on Tamara News
Read our coverage of the American Tower data breach, the Berlin ransomware attack and the TruStage outage lawsuits.
Sources
- TechCrunch — ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen. techcrunch.com
- Krebs on Security — FBI Probes Service Selling 153M+ Drivers Licenses. krebsonsecurity.com
- TIME — FBI Probes Report of Breach Exposing 153 Million Driver’s License Scans. time.com
Verification your users actually receive.
Send one-time passcodes over WhatsApp with a single API call. Replio can generate, hash and verify the code for you.

