Home / Blog / IDScan sued over alleged data breach affecting 153 million…
Tech News

IDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153.

By Dillip Chowdary • Sep 06, 2026 • Source: BleepingComputer

IDScan sued over alleged data breach affecting 153 million drivers

What happened

Identity verification company IDScan is facing multiple lawsuits after hackers allegedly breached its systems and put more than 153 million driver's license records up for sale. The breach, reported by BleepingComputer, represents one of the largest alleged exposures of government-issued identity documents in recent memory, and the legal filings signal that plaintiffs believe the company failed to adequately protect a data set that is unusually difficult for affected individuals to replace or remediate.

This piece is for developers and security teams building on top of identity verification APIs, for businesses that use IDScan or any comparable age-verification or ID-scanning service in their customer workflows, and for consumers who may have had their driver's license scanned at a venue, retailer, or online onboarding portal that relies on third-party ID-check infrastructure.

Multiple civil lawsuits have been filed against IDScan, an identity verification company that processes driver's licenses on behalf of businesses in sectors ranging from retail to hospitality to regulated industries. Hackers reportedly broke into IDScan's systems and exfiltrated records covering more than 153 million driver's licenses. Those records were subsequently offered for sale, a discovery that BleepingComputer flagged as the basis for the legal action. The lawsuits allege that IDScan failed to implement adequate security controls to protect the personally identifiable information it collected, processed, and retained on behalf of its clients and, by extension, the millions of individuals whose documents passed through its platform.

How it works

The scale of 153 million records places this alleged breach in a category that dwarfs most corporate data incidents. Driver's license data is particularly sensitive because it bundles a physical address, date of birth, a government-issued identifier number, and in many cases a facial photograph into a single record. Unlike a compromised email address or even a credit card number, a driver's license number cannot simply be changed by a phone call to a bank, making the harm from exposure persistent and harder to contain.

IDScan sued over alleged data breach affecting 153 million drivers
Illustration · Pexels

The population at risk is anyone whose driver's license was scanned by a business or platform that integrated IDScan's verification service. That encompasses consumers who presented their license at a bar or nightclub using an electronic ID scanner, individuals who completed digital onboarding for an app or financial product that used IDScan in its KYC pipeline, and workers or visitors who had their credentials verified at access-controlled facilities. Because IDScan operates as a B2B vendor, the people most exposed may not even know that IDScan ever held their data.

Why it matters

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Businesses are exposed as well, though in a different way. Any organization that routed customer identity data through IDScan may face downstream regulatory scrutiny, particularly in states with broad biometric or personal data laws such as California, Illinois, and Texas. If a company collected and transmitted license data to IDScan under a terms-of-service clause that promised reasonable security, that company may also face its own contractual liability to customers, independent of whatever IDScan's legal outcome turns out to be.

If you are a developer or product team that integrated IDScan's API, the first step is to audit exactly which data fields you sent to the service and how long IDScan was configured to retain them. Review your data-processing agreement with IDScan and confirm whether that agreement includes a breach-notification obligation, then determine whether that notification window has already been triggered. Check whether your privacy policy accurately disclosed that a third-party identity verification processor held copies of user license data, because a mismatch between your disclosures and your actual data flows creates independent legal exposure regardless of the IDScan litigation.

For consumers, replacing a driver's license is an option in most jurisdictions but typically requires visiting a DMV in person and paying a replacement fee. The more immediate step is to place a fraud alert or credit freeze with the three major bureaus, since a full driver's license record contains enough information to open new lines of credit or commit synthetic identity fraud. Monitor accounts closely for unusual activity and consider whether any financial, medical, or utility accounts were opened in your name around the time the breach is alleged to have occurred, even if an exact date for the intrusion has not yet been confirmed publicly.

Who is affected

Identity verification services like IDScan sit at a structural chokepoint in digital and physical commerce. A single vendor may process tens of millions of scans per year on behalf of thousands of business customers, meaning that a breach at the vendor layer exposes records aggregated from every one of those downstream clients simultaneously. This aggregation risk is the same dynamic that made breaches at credit bureaus and background-check firms so damaging: the vendor accumulates far more data than any single business customer holds, creating a high-value target from the union of many individually modest data sets.

From an attacker's perspective, a database of 153 million driver's licenses is immediately monetizable. Each record contains multiple fields that support distinct fraud vectors: the license number alone can be used to impersonate someone in a government context, the address supports physical mail fraud and social-engineering calls, the date of birth confirms identity in phone-based account-recovery flows, and a photo enables potential deepfake or spoofing attacks against biometric checks. Selling the full database to multiple buyers, or selling subsets by state or demographic, extends the harm because each purchase is a new potential fraud campaign.

What to watch next

The public record as of the reporting by BleepingComputer does not include a confirmed date for when the breach occurred, how long the attacker had access to IDScan's systems, or how the initial intrusion was achieved. It is also not yet public whether IDScan itself has acknowledged the breach, issued formal notification to affected individuals or business customers, or disclosed the incident to state attorneys general as required by breach-notification statutes in most U.S. jurisdictions.

The total number of distinct individuals behind the 153 million records also remains unclear, since ID-verification logs can contain multiple scans of the same person across different venues or time periods. Whether law enforcement agencies have identified the actor who listed the data for sale, and whether the offered records have since been purchased or further redistributed, are also open questions that will shape how harmful this incident ultimately proves for the people whose information was taken.

Developer Action Items

  • Inventory whether IDScan sued alleged data runs in prod, CI, staging, or on laptops before you debate severity.
  • Confirm the vendor's fixed build for IDScan sued alleged data from BleepingComputer, then schedule the patch window.
  • If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
  • Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
  • Treat unexpected emails that mention IDScan sued alleged data (shipping, invoices, password resets) as phishing until verified.
Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →