:

IDSCAN SUED OVER BREACH OF 153M DRIVER RECORDS

SECURITY DESK2 MIN READ
FRI, SEP 4, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.

IDScan, which provides identity verification services to businesses and government agencies, is defending itself against coordinated legal action stemming from the data breach. Hackers reportedly gained access to the company's database containing driver's license information and listed the stolen data for sale on the dark web. The scope of the breach—affecting 153 million drivers—represents one of the largest identity theft incidents in recent years. The lawsuits allege that IDScan failed to implement adequate security measures to protect sensitive personal information. Driver's license data is particularly valuable to criminals, as it typically includes names, addresses, dates of birth, and license numbers—details that can be used for identity fraud and financial crimes. IDScan has not yet made a public statement detailing when the breach occurred, how long unauthorized access persisted, or what specific security lapses led to the incident. The company has indicated it is investigating the matter. The plaintiffs are seeking damages for potential identity theft monitoring, credit monitoring services, and compensation for the risk of future fraudulent activity. Legal experts expect the case to address whether IDScan's security practices met industry standards and whether the company disclosed the breach in a timely manner. This incident adds to a growing list of major data breaches affecting U.S. consumer information. Identity verification services have become frequent targets for cyber criminals due to the high value and sensitivity of the data they store. Regulatory bodies may also investigate whether IDScan violated data protection regulations. Companies handling large volumes of personal identification data face increasing pressure to implement encryption, multi-factor authentication, and other security protocols. IDScan's clients—financial institutions, government agencies, and other businesses relying on its verification services—are reviewing their relationships with the company and assessing potential liability.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.

2H AGOIndustry Desk

A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.

4H AGOSecurity Desk

The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.

4H AGOIndustry Desk

Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.

6H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.