The stolen data includes full names, driver's license numbers, and passport information belonging to individuals across the United States and Canada.
This breach is significant because it exposes the personal information of more than 150 million people, including high-ranking government officials such as the U.S.
Secretary of Defense.
The availability of these records on a searchable website allows bad actors to access photos and identifying details, creating long-term risks for identity theft and fraud.
The incident has drawn the attention of the FBI and the Pentagon, highlighting the vulnerability of centralized identity databases used by the private sector to verify customer age and credentials.
The company stated that its investigation is ongoing and that it issued a public notice after learning of claims regarding the hack around September 1.
While IDScan has not specified the exact number of victims, its own records indicate the firm holds over 150 million driver's license entries.
According to the company's notice, the hackers required payment for full access to the stolen cache, though it remains unclear if a specific ransom demand was made to the firm to prevent the data's release.