Written by Admin Alex · Fact-Checked by M.Ali · Info Verified September 2026
We review and update this article regularly as new information becomes available.
TL;DR: ID verification company IDScan has confirmed that hackers stole more than 150 million driver’s license records from its systems, covering nearly its entire U.S. and Canadian database. The stolen data includes names, license numbers, government ID numbers and photos. The FBI and Pentagon are both involved, and the company still hasn’t explained how the intrusion happened.

A quiet confirmation after a very loud tip
Security journalist Brian Krebs broke this story on September 2, and it took IDScan more than a week to actually confirm what he’d found. The Louisiana-based company verifies IDs for bars, cannabis dispensaries, concert venues and other businesses that need to check whether a customer is who they claim to be. That’s the irony here. A company built entirely around verifying identity just handed over the raw material for identity theft at a scale most breaches never reach.
By the time IDScan issued its statement on September 10, the number being reported by researchers and multiple outlets had already climbed past 150 million records, essentially the company’s entire archive.
What actually got taken
This wasn’t a partial scrape. The stolen dataset reportedly includes full names, driver’s license numbers, other government ID numbers pulled from passports and similar documents, and the photos attached to those licenses. Put those four things together and you have most of what a criminal needs to open a fraudulent line of credit, pass a shallow identity check, or build a convincing fake profile.
IDScan’s public statement included a strange detail: the company noted that “full access to the information required payment,” which reads a lot like an admission that whoever pulled the data is now trying to sell it or hold it for ransom. The company hasn’t responded to questions about whether it received a ransom demand directly.
Who’s caught up in this
Because IDScan works behind the scenes for so many venues and retailers, the exposure list reaches further than most people would expect. Reporting has named U.S. Secretary of Defense Pete Hegseth among the individuals affected, along with a security researcher who independently verified samples of the leaked data matched real records. Neither the Pentagon nor the FBI has said much publicly, but both have confirmed they’re investigating.
If you’ve had your ID scanned at a bar, a dispensary, or a ticketed event any time in the last few years, there’s a real chance your information sits somewhere in this dataset. IDScan hasn’t published a way for individual consumers to check.
Why this one is different from the usual breach story
Password leaks are annoying but fixable. You change the password. A driver’s license number doesn’t reset. Neither does your face. That’s what makes ID-verification breaches so much worse than the credential dumps we’ve all gotten numb to. The data is permanent, it’s tied directly to your legal identity, and there’s no “reset” button waiting on the other end.
Security researchers monitoring dark web marketplaces have already flagged listings selling chunks of the dataset, which suggests this is moving fast from breach to active exploitation rather than sitting dormant.
What to actually do about it
If you’ve interacted with a venue that uses ID scanning technology, it’s worth freezing your credit with the major bureaus and watching for new accounts you didn’t open. Fraud alerts are free and take about ten minutes to set up. Nobody enjoys doing this kind of maintenance, but a stolen driver’s license number is the kind of thing that can resurface in fraud attempts years after the initial breach, long after most people have stopped thinking about it.
Bottom Line: IDScan sat on a database that most consumers never even knew existed, and now more than 150 million of those records are loose. The company’s vague statements and lack of a real explanation aren’t reassuring. Assume your data could be in this one if you’ve ever had an ID scanned somewhere, and act accordingly rather than waiting for a notification that may never come.



