IDScan.net driver's license incident: what is confirmed and what you should do
If you are a customer of IDScan.net driver's license, here’s what is being claimed, and what it would mean for you.
In early September 2026, IDScan.net said someone unauthorized may have accessed full names and driver’s license or other government ID numbers from customer accounts on its systems. The FBI in New Orleans confirmed it is looking into the incident. The company has not confirmed reports of 153 million scans, or that photos, addresses, or dates of birth were taken.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
IDScan.net driver's license customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On or around September 1, 2026, IDScan.net said it received information that some data may have been accessed without permission. The company makes tools that businesses use to scan driver’s licenses and other IDs at ordinary counters — rental desks, door checks, and similar spots. In its own statement, it said it moved to secure its systems, brought in outside experts, and is working with law enforcement. It also said an unauthorized party may have accessed or copied certain information stored in customer accounts: full names, and driver’s license or other government-issued identification numbers.
The FBI’s New Orleans office has separately confirmed it is looking into “the incident,” with no further comment. IDScan.net says it is notifying people who may be affected and offering free credit monitoring and identity protection. It has not confirmed a widely repeated figure of 153 million scans, and it has not said that photos, addresses, dates of birth, or images of the cards themselves were taken.
The part that actually changes things for you
Most coverage of this story is either very loud or oddly soothing. The loud version treats “153 million driver’s licenses for sale” as a settled fact. The soothing version treats the company’s narrower statement as a reason to relax — as if “only names and license numbers” were leftover scraps. Neither version is written for the person who once handed a license to a clerk and went on with their day.
You did not open an account with IDScan.net. Its customers are the businesses that scanned you. When someone checked your ID, a record of that check could sit in that business’s account on IDScan.net’s systems — a copy you were never shown and never asked to store. The company now says those accounts may have been reached, and that what may have been taken includes your name and the number on your license or other government ID.
That pairing is the part that lasts. A bank card can be cancelled by morning. A driver’s license number is a long-lived government identifier. Next to your full name, it is the kind of information used to open accounts, file a tax return, or impersonate you. Whether the rumored full-color scans are real is a different question, and the company has not confirmed them. Those images would matter most to someone trying to forge a physical card. The name-and-number claim is already enough for remote fraud. A company does not notify people and offer monitoring as a hobby.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
You also cannot look yourself up in this incident. There is no public list, and no internet search can honestly tell you that your license was or was not involved. Some well-known companies named in coverage have said they were not involved, or that they had already stopped using the service. Seeing a familiar brand in a headline does not tell you whether a scan of your ID was sitting in an account.
What to actually expect
- You may get a notice from IDScan.net, or be pointed to its help line at [phone withheld], offering free credit monitoring and identity protection. A notice means the company thinks your information could be in the affected set. Getting no letter does not prove you were spared; these mailings run late and miss people.
- You will not get a reliable yes or no for your specific license. News stories will keep citing 153 million records. That number comes from reporting about an online service that advertised scanned licenses; the company has not confirmed it, and some outlets could not re-check that service after it went offline.
- The fraud to watch for is someone opening credit, filing a tax return, or using your license number as if they were you — not a sudden login to your email or bank app.
- Lawsuits have been filed. Those are allegations, not a finding, and they will not tell you whether you were included or get the data back.
What you can and cannot fix
If your name and driver’s license or ID number were copied, that copy cannot be taken back. It cannot be deleted from whoever has it. Replacing the physical card does not reliably change the number, and a new number does not erase the old one. Treat that identifier as permanently known to someone who should not have it.
What still helps, in this order:
- Freeze your credit with Equifax, Experian, and TransUnion. The free monitoring the company is offering will warn you after someone tries to open an account. A freeze is what actually blocks the account from opening. That matters here because a name plus a government ID number is raw material for new-account fraud — even though a Social Security number was not listed in the company’s statement.
- Get an IRS Identity Protection PIN so a tax return is harder to file in your name. License data is useful for impersonation; a fake tax filing is one of the ways that shows up.
- Do not pay anyone who calls you about this. Use a written notice you can verify, or the company’s published line, [phone withheld]. Scammers ride events like this and will pretend to be the company, a bank, or the government.
- Take down the extra file the internet already keeps on you. A leaked name and license number becomes far more useful when it can be matched to relatives, phone numbers, employers, and old addresses. People-search listings add those pieces. Unlike the stolen records, those listings can actually be removed. That is the lever you still have: not recalling what left IDScan.net, but starving a stranger of the rest of the picture they would build around it.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on IDScan.net driver's license.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…
Malaysia National Registration Department 22.5 Million — May 2022
A breach of Malaysia's National Registration Department exposed ~22.5 million citizen records, inclu…