IDScan, which sells document-checking software used by bars, retailers, banks and other businesses to confirm that a customer's identity document is genuine, confirmed a data breach involving the theft of driver's licenses from its systems, TechCrunch reported on September 10, 2026. The confirmation came roughly a week after an initial report that the company had been compromised.

The number attached to the incident — more than 150 million driver's licenses, per TechCrunch's reporting — puts it among the larger identity-document exposures on record. DailyTech has not independently verified the count, and companies commonly revise breach totals as forensic work continues; treat the figure as the number reported at disclosure rather than a settled tally.

Why it matters

The value of a stolen credential depends on how easily it can be replaced. A password takes seconds to change. A driver's license number, expiry date, address and photograph stay valid for years, and they are precisely the inputs used to open accounts, pass remote onboarding checks and take over existing accounts by phone.

There is a structural point too. Verification vendors sit behind hundreds or thousands of businesses that never appear in the headline. Consumers whose licenses were scanned at a store or during an account signup generally have no relationship with the vendor, no notice from it, and no way to know their document was ever held there.

How it works

Document-verification services typically receive an image of an identity document, extract the machine-readable data, compare it against expected formats and known-good templates, and return a pass or fail signal to the business that asked. Retaining those images — whether for audit trails, dispute handling or model training — creates a concentrated store of exactly the material identity thieves want.

Public reporting has not detailed how the intrusion occurred, and this report does not speculate. What is established is the class of data involved: identity documents, not merely account metadata.

Evidence

TechCrunch reported IDScan's confirmation on September 10, 2026, describing the theft of driver's licenses from the company's systems and citing the figure of more than 150 million documents, and noting that its report followed an earlier account of the incident by about a week.

What defenders should do

Businesses that pass customer documents to a verification vendor should ask two specific questions in writing: what does the vendor retain after a check returns, and for how long. Where retention is not required by law or a demonstrable dispute process, the safest posture is to send the document, take the answer and keep nothing.

Fraud and support teams should also stop treating a matching license image as sufficient proof of identity on high-risk actions such as password resets, payout changes and SIM or account transfers. When document images circulate at this scale, a step that relies on possession of the document alone stops being a control.

What happens next

Expect state attorneys general to take an interest — driver's license numbers trigger breach-notification duties in most US states — and expect class-action filings, which follow large identity-document exposures almost automatically. The longer question is whether US regulators start treating identity-verification vendors as critical infrastructure for consumer finance rather than as ordinary software suppliers.