ID verification company IDScan confirmed a major data breach compromising over 150 million driver's licenses and government-issued identity documents. The stolen data includes full names and personal identification information.
IDScan, a prominent player in identity verification services, disclosed the security breach affecting a massive tranche of personal identification records. The compromised dataset contains driver's licenses and other government-issued IDs linked to millions of individuals.
According to the company's confirmation, the breach included full names alongside driver's license information and additional identity documents. The scale of the incident—exceeding 150 million records—ranks among the largest identity data breaches in recent years.
The company has not yet disclosed the full timeline of the breach, including when the unauthorized access occurred or when it was discovered. Details regarding the method of compromise and identity of the threat actors remain unclear.
IDScan provides identity verification services to various sectors, authenticating individuals through document scanning and verification processes. The company processes sensitive personal data as part of standard operations, making it an attractive target for cybercriminals and bad actors seeking to obtain identification information at scale.
Driver's license data carries particular value in criminal markets. Stolen licenses can be used for identity theft, fraud, creating fraudulent documents, or gaining unauthorized access to services and accounts that rely on identity verification.
The breach raises questions about data retention practices and security protocols at identity verification firms. Organizations handling government-issued identification information face regulatory scrutiny and potential legal liability depending on applicable data protection laws in affected jurisdictions.
IDScan has not announced comprehensive details about notification procedures for affected individuals or steps being taken to mitigate potential harm. The company's next statements are expected to address remediation efforts and enhanced security measures.
This incident underscores ongoing vulnerabilities in centralized databases storing sensitive identification information and highlights risks for individuals whose data passes through third-party verification services.
Cisco Talos has confirmed that two recently patched vulnerabilities in Secure Firewall Management Center (FMC) are being actively exploited by three separate threat groups linked to ransomware operations and state-sponsored attacks.
Clearview AI is testing InquiryIQ, a prototype that uses xAI's Grok model to help law enforcement surface associates, social accounts, and personal information about individuals identified through Clearview's facial recognition database.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a critical remote code execution vulnerability in WatchGuard Firebox firewalls. The flaw was previously flagged as under active exploitation in December.
Security researchers identified four separate threat groups exploiting an identical vulnerability affecting Chrome and Windows. The shared exploit kit suggests a widening security gap in patch deployment.