IDScan Sued Over Breach of 153M Driver Licenses
Multiple lawsuits target identity verification firm IDScan after hackers allegedly accessed and offered to sell more than 153 million driver records.

Identity verification firm IDScan is facing multiple lawsuits after hackers allegedly breached its systems and offered to sell the data of more than 153 million drivers, BleepingComputer reported Thursday.
The claimed scale is notable. Approximately 230 million Americans hold driver’s licenses, so 153 million would represent roughly two-thirds of that total. Driver’s license records typically include name, address, date of birth, and license number: exactly the combination identity thieves use to open credit lines, file fraudulent tax returns, or defeat identity verification checks.
IDScan’s business is providing those identity verification checks to other organizations. A breach at an ID verification provider compounds the usual exposure in a specific way. The stolen records do not only expose the individuals on them directly; they can also be used to circumvent the very verification workflows that IDScan’s clients rely on to screen fraudsters. A provider holding IDs for a significant fraction of the licensed population becomes a single point of failure for any organization downstream that trusts its outputs.
IDScan had not publicly confirmed the breach as of this writing. The lawsuits allege negligence in data protection. Whether the 153 million figure reflects IDScan’s actual stored records or was inflated by the threat actors to drive up sale value is not established in public reporting.
The pattern is not new. Organizations that aggregate identity data at scale are high-value targets because a single breach can be monetized in multiple directions at once. Earlier this year, attackers exploited vulnerabilities in cloud-hosted tools to steal credentials from AI development pipelines, and a separate incident saw sensitive nuclear records accessed through an unpatched ownCloud server. The targets differ; the principle behind targeting them does not.
What to do
If your organization uses IDScan for identity verification, treat records in that system as potentially exposed until IDScan issues a formal statement. Individuals who have submitted a government ID to an IDScan-integrated service should consider placing a credit freeze with the three major bureaus and monitoring for unusual account activity. The lawsuits are in early stages. 0dayNews will update this story as legal proceedings develop and IDScan responds formally.
Found this useful? Share it.


