ID verification service IDScan has confirmed a data breach exposing 153 million driver's licenses after hackers placed them up for sale. The stolen credentials pose significant identity theft risks to affected individuals.
IDScan, a provider of identity verification services, disclosed the breach following reports that threat actors were offering the compromised driver's license data on the dark web.
The scope of the incident is substantial. The 153 million stolen licenses represent a massive trove of personal identification documents that typically contain names, addresses, dates of birth, and license numbers—core data points used for identity theft and fraud.
The company's confirmation came after security researchers and journalists identified the breach through underground marketplaces where hackers advertised the stolen dataset. IDScan's public acknowledgment followed mounting pressure and media scrutiny over the incident.
Driver's license data is particularly valuable to criminals. Beyond standard identity theft, the information can be used for account takeovers, financial fraud, and creating synthetic identities. The sheer volume of records—153 million licenses—suggests potential exposure across multiple jurisdictions and customer bases.
IDScan has not yet released comprehensive details about the breach timeline, how attackers gained access, or what specific security lapses led to the theft. The company also has not disclosed the full scope of affected customers or provided guidance on remediation steps.
The incident underscores ongoing security challenges in the identity verification industry, where companies store sensitive personal documents as part of their core business operations. Previous breaches at similar services have exposed millions of identity documents, creating systemic risks across financial services, government agencies, and other sectors that rely on third-party verification.
Individuals affected by the breach face potential exposure to fraud and should monitor financial accounts and credit reports closely. The incident also raises questions about data retention policies at ID verification firms and whether storing full-resolution license images and complete personal details remains necessary.
Japan's Digital Agency confirmed unauthorized access to its servers, with personal data on approximately 246,000 individuals potentially compromised. The breach marks a significant security incident for the government body overseeing the nation's digital transformation.
Trezor alerted customers Wednesday that attackers exploited a breach at its third-party email provider to launch phishing campaigns. The cryptocurrency hardware wallet maker urged users to remain vigilant against fraudulent communications.
Forgejo, a self-hosted Git service, released version 16.0.4 to address a critical remote code execution vulnerability affecting all versions up to 16.0.3. Users should upgrade immediately.
Microsoft's September 2026 security patches are disabling Remote Desktop Services across Windows Server 2019, 2022, and 2025, leaving administrators unable to access systems and requiring hard resets in some cases.