​IDScan Confirms Cloud Cyberattack Exposing Over 150 Million Driver Records

Rinky Rai
By Rinky Rai - A freelance journalist
3 Min Read

Identity verification firm IDScan has confirmed a major cyberattack on its cloud systems that led to the theft of personal records, including driver’s license numbers and passport identification details. The Louisiana-based firm, which holds over 150 million driver’s license records, confirmed the breach in a recent website notice after initially stating that it was investigating an unresolved security incident. The company provides identity verification services to venues and commercial clients, meaning the compromised data includes records of individuals who simply verified their identities through third-party businesses.

Dark Web Database Exposed to the Public

​The firm first learned of claims regarding an intrusion around September 1, coinciding with reports of an illicit website offering searchable driver’s license records covering more than 150 million residents across the United States and Canada. The illicit repository reportedly included associated photographs alongside names and identification numbers. Independent verification of the database confirmed the presence of valid personal information, including the records of high-profile public figures, suggesting a broad compromise rather than a targeted incident against selected accounts.

Federal Agencies Step In as Extortion Fears Mount

​The exposure has prompted active investigations by the Federal Bureau of Investigation, with the United States Department of Defense also monitoring the breach. While investigators have yet to name the perpetrators or clarify their ultimate motive, full access to the stolen data cache was reportedly offered online in exchange for financial payment. IDScan has stated that its internal review is ongoing, though it has not formally confirmed whether it received a direct ransom demand from the intruders.

Escalating Threats of Synthetic Identity Fraud

​Cybersecurity specialists caution that the simultaneous loss of driver’s license numbers, full names, passport details, and photos substantially elevates the danger of identity theft and illicit account creation. Because these combined data points allow bad actors to construct persuasive fraudulent profiles, the breach underscores systemic risks tied to third-party verification platforms that aggregate government-issued credentials. IDScan has begun notifying individuals who may be affected as law enforcement agencies trace how widely the illicit records have circulated.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected