IDScan Confirms Breach of Up to 170 Million Government Identity Documents
The theft of driver's licenses and passports from the Louisiana-based firm has triggered an FBI investigation after high-profile U.S. officials were targeted.
Identity verification service IDScan has confirmed a massive data breach involving the theft of millions of government-issued identity documents from its cloud systems. The incident represents one of the largest exposures of sensitive personal identification data in recent history, affecting citizens across the United States and Canada.
The breach first came to light on September 1, 2026, after journalist Brian Krebs reported that a dark web service had begun selling access to the stolen data. Reports on the scale of the exposure vary, with estimates placing the theft between 150 million, 153 million, and up to 170 million identity documents. The stolen records include full names, driver's license numbers, and photos of individuals, as well as identity numbers from other government documents such as passports.
The Target and the Leak
IDScan, a Louisiana-based firm, provides identity verification services to a diverse array of corporate clients, including cannabis dispensaries and entertainment venues. By acting as a central repository for millions of government ID scans, the company became a high-value target for cybercriminals.
The severity of the leak was highlighted when the dark web marketplace 'Nexus' used the driver's license of U.S. Secretary of Defense Pete Hegseth as a marketing hook to attract buyers. While IDScan noted in a website notice that full access to the information required payment, the presence of high-profile government officials in the database has escalated the incident into a national security concern. Consequently, the FBI is now investigating the breach.
Implications for Identity Security
The scale of this theft significantly elevates the risk of sophisticated identity fraud and the creation of synthetic identities. Because the breach includes high-resolution photos alongside government ID numbers, attackers possess the primary components needed to bypass many modern KYC (Know Your Customer) verification systems.
This incident reignites a critical industry debate regarding data minimization. Security experts argue that the breach underscores the danger of companies storing raw images of government IDs. The consensus among privacy advocates is that firms should instead utilize tokenized records or ephemeral verification processes that do not require the long-term storage of sensitive biometric and government data.
What Remains Unconfirmed
While the theft is confirmed, the exact timeline and method of the intrusion remain unclear. Some reports suggest the breach may have been the result of a year-long hack, though this claim has not been independently confirmed by IDScan or official investigators. Observers are now waiting to see if further government agencies will report compromises or if the stolen data will be used in a coordinated wave of financial fraud.