Investigative journalist Brian Krebs traced the source to IDScan.net, a New Orleans‑based vendor whose scanners are installed at car‑rental counters, retail outlets, and cannabis dispensaries, according to BleepingComputer.
What makes the exposure unusual is not just its size but its composition.
What a document-authentication vendor actually holds
IDScan.net's business, per its own marketing quoted by Malwarebytes, is to let a business validate a customer's ID and age "in a matter of seconds." To do that, its scanners capture more than a picture. Standard visible-light images establish what a license looks like; infrared and ultraviolet captures reveal whether the embedded security features respond the way a genuine state or provincial document would.
IDScan.net's reported client roster includes Hertz, Target, and FedEx, according to Startup Fortune's report on the breach, spanning car rental counters, retail registers, and points of sale in financial services and cannabis dispensaries. Our read is that a vendor sitting behind that many separate businesses' age and identity checks is largely invisible to the customers those businesses serve, which means a single backend compromise can surface simultaneously across industries that share no other technology, no other regulator, and no obvious reason to imagine themselves connected.
Those are claims made by a party selling stolen data, not a forensic finding, and no source describes the technical entry point — credential theft, an exposed API, a misconfigured database — that let it happen.
The numbers, and where they disagree
| Category | Reported volume | Source |
|---|---|---|
| Driver's licenses (US & Canada) | 153+ million | BleepingComputer |
| ID cards | 10+ million | BleepingComputer |
| Travel/international documents | 3+ million | BleepingComputer |
| Medical cards (incl. dispensary cards) | 579,000+ | Malwarebytes |
| Total individuals claimed | Up to 170 million | CyberPress |
IDScan.net has not confirmed the breach occurred on its own systems, and multiple outlets covering the story have noted it remains unclear whether the compromise sits inside IDScan's own infrastructure or somewhere in the chain of businesses that send it data. The company's own statement, as relayed by Malwarebytes, was limited to saying it was investigating.
Unlike a stolen password, none of this data can be reissued. A date of birth, a license number, a home address, a face — these are fixed attributes, and a MSSP Alert brief on the FBI probe noted that compromised identity documents "cannot be changed like passwords, posing a lifelong exposure risk," per MSSP Alert's coverage. That distinction matters for how the breach compares with other recent incidents. TransUnion disclosed in August 2025 that a breach of a third-party application exposed 4.4 million Americans, a fraction of the volume claimed here but drawn from a company whose entire business is holding exactly this kind of static identity data, according to CNBC's report on the TransUnion breach. Each incident involves a different vendor, a different regulator, and by the available reporting a different technical cause — a pattern across companies, not a single documented mechanism.
None of these comparisons establishes that IDScan.net's own systems were the point of failure, and no source in this record supplies a root-cause finding: no confirmation of whether the access point was a leaked credential, an exposed interface, or something inside a downstream client's integration. What is established is narrower and still consequential — that a marketplace advertised a trove consistent in scale and detail with the output of a document-authentication vendor, that Krebs's sample checks returned real records belonging to real people, and that the FBI is now investigating a company whose product exists specifically to prove, in seconds, that an ID is not fake. Whether that investigation confirms the breach occurred inside IDScan.net's own infrastructure, or somewhere else in the chain of businesses it serves, is the fact the rest of the story depends on.