Identity-verification provider IDScan confirmed that attackers stole data from its cloud systems during a reportedly year-long intrusion. The compromised dataset includes full names, driver’s-license numbers, and identification numbers from other government documents, including passports; IDScan holds more than 150 million driver’s-license records.
The records were advertised on a dark-web marketplace and reportedly searchable for more than 150 million people in the United States and Canada, potentially including photographs. The seller and breach method have not been publicly identified, while IDScan continues its investigation and the FBI is investigating; the Pentagon said it was aware of reports that Defense Secretary Pete Hegseth’s information appeared in the database.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
A database purportedly containing records from 153 million driver's licenses was advertised for sale on a dark-web marketplace. The listing did not identify the seller, the source organization, or independently verify the claimed record count.
In its September 4 breach notice, IDScan said it would notify potentially impacted individuals and provide free credit-monitoring and identity-protection services following the possible copying of customer information from IDScan.net cloud accounts.
IDScan said it received information about a claim that it had been hacked on or around September 1. The company later began investigating the alleged compromise.
The Nexus marketplace, which reportedly offered access to the exposed driver's-license database, disappeared from the dark web shortly after reporting on the breach was published.
The FBI said it was investigating the suspected IDScan breach, while the Pentagon said it was aware of the incident because information associated with U.S. Secretary of Defense Pete Hegseth was reportedly present in the exposed database.
Independent reporting found that a dark-web site allowed searches of driver's-license data for more than 150 million people in the United States and Canada, including photographs. Brian Krebs verified apparent authenticity using his own record; the reported data also included records associated with Defense Secretary Pete Hegseth and a security researcher.
IDScan acknowledged that hackers stole driver's-license data from its cloud environment, in what its website notice described as the company's first acknowledgement of a hack. The company said the stolen information included full names, driver's-license numbers, and identification numbers from other government documents, including passports.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcetherecord.media
Open sourcetechcrunch.com
Open sourceschneier.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.