IDScan confirms breach involving driver's licenses of more than 150 million people
IDScan has confirmed that hackers stole driver's licenses and other government identity documents from its cloud, a week after a report described a dark web database searchable for records on more than 150 million people in the U.S. and Canada.
The Louisiana-based company said in a notice posted on its website that the stolen information includes people's full names and driver's license numbers, along with identity numbers from other government documents such as passports. Its customers range from entertainment venues to cannabis dispensaries, which use the service to verify the identity documents of their customers. IDScan said its investigation is ongoing. The company has not said how many individuals are affected, and its website notes that it holds more than 150 million driver's license records.
According to the notice, IDScan received information on or around September 1 about a claim of a hack. That was the same day Brian Krebs, an independent cybersecurity journalist, first reported a data breach at the company, which had said a week earlier that it was investigating an incident but had not yet confirmed an intrusion.
Krebs reported that he was alerted to a website on the dark web that allowed anyone to search the driver's license information of more than 150 million people living in the United States and Canada, including access to their photos. He verified the authenticity of the data by examining his own record. According to his report, the database also contained records for high-profile individuals, including U.S. Secretary of Defense Pete Hegseth, and a security researcher who also verified his data for the report.
The Pentagon told TechCrunch last week that it was aware of the suspected breach, and a spokesperson for the FBI said the bureau was also investigating the incident.
In its statement, IDScan said that "though full access to the information required payment" — an apparent reference to a demand by the hackers for money to reach the full cache of stolen data — the company was providing notice on its website to alert potentially affected individuals. IDScan did not respond to TechCrunch's request for comment about the incident, including whether the hackers contacted the company with a ransom demand not to release the data.