DrafterDaily
AIBusinessCryptoFinanceSportsTechnology
Home/Technology/IDScan Confirmed the Breach. The Number 153 Million Came From the People Selling the Data.
Technology

IDScan Confirmed the Breach. The Number 153 Million Came From the People Selling the Data.

IDScan.net confirmed a breach that ran for roughly a year before discovery around 1 September 2026. The company has not published a count of affected records. The widely reported figure of 153 million driver's licences originates with the criminal marketplace that listed the data, and became the consensus number during the eight days before the company spoke. The structural half of the story is why identity-verification mandates concentrate document images in a handful of vendors that individuals never chose.

DrafterDaily Editorial·September 11, 2026·7 min readTechnologyEnterprise

In this article

  1. What is actually established
  2. How a criminal's marketing copy became the consensus figure
  3. Why one Louisiana company had nine figures of anything
  4. The case that the silence is normal and the number is fine
  5. What actually changes for a person in the file

IDScan.net, a Louisiana identity-verification company most people have never heard of and many have unknowingly used, has confirmed that it was breached. TechCrunch reported the company's breach notification on 10 September 2026. The intrusion ran for roughly a year before it was discovered around 1 September, and the stolen data includes full names and driver's licence numbers together with identity numbers from other government documents, including passports. The FBI's New Orleans field office has opened an investigation.

Every account of this breach leads with a number: more than 150 million driver's licences, usually rendered as 153 million, sometimes as more than 170 million identity documents in total. That number did not come from IDScan. It did not come from the FBI. It came from the dark-web marketplace that listed the records for sale, which is to say it came from the party with the strongest possible commercial interest in it being large.

What is actually established

The confirmed facts are short. A breach happened. It persisted for about a year. IDScan discovered it at the start of September, has moved to secure its systems, is cooperating with federal law enforcement, and is notifying affected individuals and offering credit monitoring. The categories of data taken are known and are unusually sensitive, because a scanned identity document carries a name, a number, a date of birth, an address and a photograph in one artefact.

The count is not established. IDScan has not published a figure for how many records were exposed. As of its confirmation, the only quantity in public circulation is the sellers' inventory claim, as reported by the security journalists who saw the listing: roughly 153 million driver's licences, around 10 million ID cards, about 3 million international travel documents, and several hundred thousand medical cards, including cannabis dispensary cards. The marketplace went offline shortly after the first reporting.

Throughout this article, 153 million is treated as a seller's claim, not a finding. No party under any obligation to be accurate has confirmed it.

How a criminal's marketing copy became the consensus figure

The mechanism is not mysterious, and it is not really a failure by the reporters who broke it. A breach story needs a magnitude. Readers want one, editors want one, and search ranking rewards one. When the breached company says nothing and law enforcement says nothing, and neither will say anything early for reasons covered below, the only entity that has published a number is the criminal vendor. So the vendor's number gets reported, correctly attributed in the fourth paragraph of the original story, and then repeated without attribution by everyone downstream until it reads as an established fact.

The eight-day gap here is the whole demonstration. The first credible public reports appeared on 2 and 3 September. IDScan's confirmation surfaced on 10 September. By the time the company spoke, its own breach already had an agreed size, and the company had played no part in setting it.

This matters beyond pedantry, because the number is doing real work. It anchors the class-action damages framing, the regulatory temperature, and the public sense of whether this was a historic catastrophe or an ordinary bad breach. A seller advertising stolen data has an obvious incentive to inflate the inventory. It has a less obvious incentive to inflate the uniqueness of it, because duplicate scans of the same person are worth less to a buyer than distinct identities. The number of documents in a listing and the number of distinct affected humans are different quantities, and nobody has published the second one.

Why one Louisiana company had nine figures of anything

The structural half of this story is more durable than the count, and it will outlast this particular breach.

Over the past several years, identity verification has become mandatory in a widening set of places: buying alcohol or cannabis, renting a vehicle, entering certain venues, opening financial accounts, and increasingly accessing online services under age-assurance laws. The businesses subject to these obligations are mostly small. A dispensary in one state and a bar in another are not going to each build document authentication, liveness checking and jurisdiction-specific barcode parsing.

So they buy it. The verification vendor supplies the scanner at the door or the SDK in the app, and the document image and its parsed fields travel from that door into the vendor's cloud. Repeat that across an entire sector, over years, and one company ends up holding a document set assembled from thousands of unrelated businesses that have no relationship with each other.

IDScan's reported customer base runs from entertainment venues and dispensaries up to large corporates, and Hertz and FedEx have been named in the reporting as customers. It is important to be precise about what that does and does not mean. Being named as a customer of a verification vendor is not evidence that a given company's own customer records were in this breach, and nothing published so far establishes that they were.

The consequence for the individual is that the counterparty and the custodian are different entities. You handed your licence to a bouncer. The company that lost it is one you have never transacted with, could not name from memory, and had no opportunity to evaluate or refuse. Concentration of this kind is not a failure of the model. It is the model working as designed, because the mandates create demand for precisely the intermediary that then becomes the single point of failure.

The case that the silence is normal and the number is fine

There is a serious argument on the other side, and it deserves stating rather than caricaturing.

First, corporate silence during the early weeks of a breach is standard and largely compelled. An active federal investigation, state-by-state notification statutes with their own rules on timing and content, and the certainty of litigation all push counsel toward saying nothing quantitative until the forensic work is finished. A company that publishes a count on day three and revises it upward on day thirty is worse off, legally and reputationally, than one that waits. Measured against that, IDScan's conduct so far is unremarkable.

Second, the sellers' figure may well be approximately right. A vendor operating at IDScan's apparent scale, across that many venues, with a year of undetected access to its cloud storage, could plausibly hold document images in the nine figures. Nothing about 153 million is intrinsically absurd. The objection here is not that the number is wrong. It is that the number is unverified, that its provenance is being laundered by repetition, and that a figure originating in criminal sales copy is now the organising fact of the public record.

What would settle it is specific and checkable. State attorney-general breach notification filings carry per-state affected counts and become public on statutory schedules. Summing those produces an independent total that does not depend on the seller at all. That is the document set to watch over the coming weeks, and it is the point at which this story either becomes one of the largest government-ID breaches on record or turns out to have been smaller than its headline.

What actually changes for a person in the file

The practical asymmetry of this breach is that a driver's licence number is not a password.

A compromised password is rotated in a minute. A licence number is a state-issued identifier with a multi-year lifespan, tied to a physical document, replaceable in most jurisdictions only through a process that is deliberately inconvenient and in many cases only for cause. The full name, the licence number and the document image together are close to the exact evidence package that the verification industry itself accepts as proof of identity. Material stolen from a KYC vendor is therefore unusually well suited to defeating KYC vendors.

Credit monitoring, which is what is on offer, watches for new credit accounts opened in your name. It does not watch for someone using your identity to pass an age check, open a gambling account, rent a vehicle, or clear a document scan at a venue. Those are the uses this particular data set fits best, and they are largely unmonitored by the remedy being provided.

The honest summary is that individuals have very little direct remedy here, and that the remedies which would matter are structural rather than personal: short mandatory retention periods for document images, a requirement that a verification check return a yes or a no rather than store the scan that produced it, and notification rules fast enough that a defensible count reaches the public before the sellers get to set one.

Frequently Asked Questions

IDScan has said it is notifying affected individuals and offering credit monitoring, so direct notification is the primary route. There is no self-service lookup, and because the company has not published a count or a scope, there is currently no public list of affected venues to check against. If you have presented a driver's licence to a scanner at a venue, dispensary, rental counter or similar business in the United States or Canada in the past few years, you cannot rule yourself out, but you also cannot confirm inclusion until a notification arrives or state attorney-general filings are published.

Follow the data, not the headline number

DrafterDaily covers security incidents by mechanism and provenance rather than by press release.

More Technology coverage

Related Articles

Technology

Apple Priced Its Foldable at $1,999. The Number That Carries Information Is October 23.

The iPhone Duo costs $800 more than an iPhone 18 Pro and arrives five weeks later. Apple also pushed three other iPhones to spring 2027. Only one of those facts is about the hinge.

Sep 10, 20267 min read
Technology

Four Outlets Counted the Same Patch Tuesday. They Got 966, 973 and 974.

Microsoft's September release is the largest on record by any of the competing counts. Both of the flaws confirmed under active exploitation are rated Important, not Critical — which means a patch policy that triages on severity ships neither of the two vulnerabilities anyone is actually being attacked with.

Sep 9, 20267 min read
Technology

Four AI Coding Agents Still Run Attacker Code Before You Type a Prompt

Manifold Security's GitSpawn disclosure hit seven coding agents at once. That is not seven bugs — it is one shared assumption about where an agent's permission boundary sits, and the approval dialog is on the wrong side of it.

Sep 8, 20267 min read
DrafterDaily

One story a day, explained properly.

Topics

  • AI
  • Business
  • Crypto
  • Finance
  • Sports
  • Technology

Company

  • About
  • Contact
  • Editorial Policy
  • Corrections
  • Affiliate Disclosure
  • Privacy Policy
  • Terms of Service

Contact

Corrections, story tips and enquiries. Every message is read.

drafterdaily@gmail.com

© 2026 DrafterDaily. All rights reserved.

Independent editorial analysis. Advertising and affiliate funded — never paid coverage.