BREACH

IDScan confirms the driver-license breach. Company count of victims: Undisclosed.

Louisiana ID-verification vendor says hackers stole licenses from its cloud after Krebs flagged a dark-web search of 150M+ U.S./Canada records. Exact affected total still Undisclosed.

Sep 10, 2026 · 3 min read

TechCrunch reports that IDScan (IDScan.net) posted a website notice confirming hackers stole driver licenses from the company’s cloud — the firm’s first clear acknowledgement it had been hacked, after saying last week it was only investigating. Data types cited from the company notice: full names, driver-license numbers, and identity numbers from other government-issued documents such as passports. IDScan has not published how many people are affected. The company-stated victim total is Undisclosed.

Context that is public and sourced: the company notes it holds over 150 million driver-license records. Brian Krebs reported on or around September 1 that a dark-web identity service (Nexus) offered searchable driver-license data on more than 150 million people in the United States and Canada, including photos — and that the New Orleans FBI field office opened an inquiry. TechCrunch says the Pentagon was aware of the suspected breach and an FBI spokesperson confirmed the bureau was investigating. Ransom figure and company-confirmed headcount: Undisclosed.

Underwrite sheet — sourced only: company confirmation of cloud theft (TechCrunch Sep 10); discovery window ~Sep 1; types = names / DL numbers / other gov IDs; holds 150M+ DL records (company); Krebs 150M+ searchable dark-web set; FBI investigating; exact affected count Undisclosed. Credit monitoring offered to potentially impacted individuals per secondary coverage of the company statement. Primary action for enterprises using VeriScan / IDScan: assume exposure, rotate vendor risk, and wait for customer-specific notices — not a guessed victim number.

Sources