IDScan data breach 2026: 153 million US/Canadian drivers' licenses exposed. Krebs reported September 2; FBI investigating September 3. Class action filed. Exposed: name, DOB, address, license number, photos. Live breach (real-time database updates) — unprecedented scale (KrebsOnSecurity, Reuters, 2026).
Data last verified September 2026 from KrebsOnSecurity, Reuters, and FBI statements.
IDScan data breach — what we know
| Field | Detail |
|---|---|
| Company | IDScan.net (ID scanning and verification service) |
| Records exposed | ~153 million drivers' licenses (US and Canada) |
| First reported | September 2, 2026 (KrebsOnSecurity) |
| FBI investigation | September 3, 2026 (confirmed) |
| Class action | Filed September 2026 in WD Texas |
| Exposed data | Name, address, DOB, license number, photos, issue/expiration dates |
| Threat actor | Unknown (investigation ongoing) |
| Live status | Database appears to be actively updating in real time |
Source: KrebsOnSecurity, Reuters, FBI statements (September 2026).
Why the IDScan breach is unprecedented
The IDScan breach is unprecedented in three ways: (1) Scale — 153 million records is more than half the US adult population; (2) Live status — KrebsOnSecurity reported the dark web site appeared to be updating its database in real time, indicating an active ongoing breach; (3) Data type — drivers' licenses are a primary government-issued identity document, so the breach exposes more than just financial risk (Zach Edwards, threat researcher at Infoblox, said: 'the incident is unprecedented in terms of its sweep') (KrebsOnSecurity, 2026).
Why this is worse than a typical data breach
Unlike credit card numbers or passwords, drivers' license numbers cannot be easily changed. A breached driver's license number can be used to: (1) Open fraudulent credit cards and loans, (2) Apply for government benefits (unemployment, healthcare), (3) Pass identity verification checks at banks and other institutions, (4) Create fake IDs for use in person, (5) Conduct SIM-swapping attacks to take over phone numbers, (6) Apply for rental housing or utilities in the victim's name (Federal Trade Commission, 2026).
What is IDScan and how was it compromised?
IDScan is a vendor of identity verification services used by retailers, banks, hotels, and car rental agencies. The company uses scanners to read driver's license data for age verification and customer onboarding. The breach is believed to be a compromise of IDScan's customer data repository, not a state DMV breach. The breach may be linked to a cloud storage misconfiguration, a third-party software vulnerability, or a credential compromise. The FBI investigation is ongoing (KrebsOnSecurity, 2026).
What to do if your driver's license is exposed
- Place a fraud alert with the three credit bureaus (Equifax, Experian, TransUnion).
- Consider a credit freeze for maximum protection (free, prevents new account opening).
- Check your credit reports weekly at annualcreditreport.com.
- Watch for phishing emails and calls referencing your personal information.
- Monitor your Explanation of Benefits (EOB) from your health insurer.
- Monitor your bank and credit card statements for unusual activity.
- Consider applying for a new driver's license number if your state allows it (a few states, like Arizona, allow number changes for identity theft victims).
- File a complaint with the FTC at identitytheft.gov if you detect fraud.
- Consider joining the class action lawsuit if you receive notice of eligibility.
What the FBI recommends
The FBI recommends that affected individuals: (1) Be cautious of any unsolicited contact requesting personal information, (2) Monitor credit reports and financial accounts, (3) Consider a credit freeze, (4) Use strong, unique passwords for all online accounts, (5) Enable multi-factor authentication (MFA) on all financial and email accounts, (6) Report suspected identity theft to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov (Federal Bureau of Investigation, 2026).
Class action lawsuit details
A class action lawsuit was filed in the US District Court for the Western District of Texas. The lawsuit alleges: (1) negligence for failure to implement reasonable security measures, (2) breach of contract for failing to protect customer data, (3) violation of state consumer protection laws. The lawsuit seeks: (a) compensatory damages, (b) credit monitoring services for affected individuals, (c) injunctive relief requiring IDScan to improve security, (d) attorney's fees. Affected individuals may be eligible to join the class action. A class certification hearing is expected in early 2027 (Reuters, 2026).
Drivers' license data breach history
Drivers' license data has been breached in several major incidents: (1) Equifax 2017 — driver's license numbers of 147 million Americans were exposed; (2) T-Mobile 2021 — driver's license data of 76.6 million customers; (3) IDScan 2026 — 153 million records. These breaches have made drivers' license numbers a high-value target for identity thieves (Privacy Rights Clearinghouse, 2026).
What is the dark web marketplace for driver's licenses?
Drivers' license data is sold on dark web marketplaces for $20-$100 per record (compared to $5-$15 for credit card numbers). A full identity package (name, SSN, DOB, driver's license, financial data) can sell for $1,000 or more. The IDScan data is being sold in bulk at significantly lower per-record prices due to the volume, making it accessible to a wider range of criminals (Privacy Rights Clearinghouse, 2026).
Resources and next steps
Visit identitytheft.gov for free identity theft recovery resources. Monitor your credit reports at annualcreditreport.com (free weekly). For ongoing investigation updates, monitor KrebsOnSecurity and FBI IC3 at ic3.gov. For the class action lawsuit, consult an attorney or visit the plaintiff's website (when available). For the IDScan-specific data breach, monitor the IDScan website and the Texas Attorney General's office.






