HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

IDScan Breach Exposes 153 Million Driver’s Licenses on Dark Web

IDScan.net confirmed that an unauthorized party accessed its cloud platform and extracted over 153 million driver’s‑license scans, which later appeared for sale on a dark‑web marketplace. The breach highlights the need for continuous access‑control monitoring and defensible audit evidence for data‑protection controls.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

IDScan Breach Exposes 153 Million Driver’s Licenses on Dark Web

What Happened – On or around September 1 2026, IDScan.net disclosed that an unauthorized party accessed its cloud platform and copied customer records. The stolen data, later found for sale on a dark‑web marketplace, includes more than 153 million driver’s‑license scans, 10 million ID cards, 3 million travel documents, and 579 000 medical cards.

Why It Matters for Trust & Control Assurance

  • The incident illustrates a failure to enforce strict access controls and continuous monitoring over highly sensitive personal identifiers.
  • A robust control‑assurance program would require real‑time evidence that privileged access is limited, logged, and reviewed, providing a defensible audit trail.
  • Continuous third‑party oversight (e.g., independent security assessments) helps verify that cloud‑hosted data stores remain protected against unauthorized extraction.

Who Is Affected – Car‑rental firms, retailers, cannabis dispensaries, and any organization that relied on IDScan’s identity‑verification API to validate government‑issued IDs.

Recommended Actions

  • Map the incident to the “access control and monitoring of sensitive data” control objective and collect evidence of current IAM policies, privileged‑access logs, and segmentation measures.
  • Conduct an immediate gap analysis of cloud‑storage permissions and implement multi‑factor authentication for all privileged accounts.
  • Engage a third‑party assessor to validate that remediation steps meet the evidentiary standards required for audit readiness. Source: https://www.helpnetsecurity.com/2026/09/11/idscan-net-data-breach-153-million-drivers-licenses/

Technical Notes – The breach appears to stem from an unknown attack vector (potential credential compromise or mis‑configuration) that allowed bulk extraction of scanned IDs stored on IDScan’s cloud platform. Data types exposed include full‑name, driver’s‑license number, and other government‑issued identifiers. Source: https://www.helpnetsecurity.com/2026/09/11/idscan-net-data-breach-153-million-drivers-licenses/

📰 Original Source
https://www.helpnetsecurity.com/2026/09/11/idscan-net-data-breach-153-million-drivers-licenses/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →