ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
- ID
- 23168
- Status
- summarized
- Published
- 10 Sep 2026, 9:21 PM
- Fetched
- 10 Sep 2026, 10:16 PM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 4.5
- Created
- 10 Sep 2026, 10:17 PM
- Tags
- Audience
- developerssaas_founders
What happened
IDScan, a Louisiana-based identity verification service used by venues and dispensaries, confirmed that hackers stole driver's licenses from its cloud, exposing full names, license numbers, and other government ID numbers for over 150 million people in the US and Canada. The breach was first reported by journalist Brian Krebs on September 1, 2026, after a dark web site allowed anyone to search the stolen records, including photos. IDScan's confirmation comes a week after its initial investigation announcement.
Why it matters
If you integrate third-party KYC or ID verification APIs into your product, this breach is a concrete reminder to audit what PII your vendors store, where it lives (IDScan's data was in their cloud), and what your contractual disclosure obligations are. Founders shipping identity checks should verify whether their provider stores document images by default and whether they can disable retention, since 150M+ records sat exposed for an estimated year.
Discussion angle
What questions should you ask an ID verification vendor before integrating—data residency, retention policy, breach notification timelines—and how do you communicate a vendor breach to your own users if your product passed their data through?