The scale of the IDScan.net data breach is becoming clearer.
A Texas breach filing reports that 13 million people were affected in total, providing a concrete figure for affected individuals that was missing from IDScan's initial notification. The disclosure comes weeks after a dark-web marketplace claimed to possess more than 153 million U.S. and Canadian driver's license records allegedly connected to the identity-verification company.
The two figures describe different things and should not be treated as interchangeable. The 13 million figure represents the number of people reported in connection with the breach, while the much larger 153 million figure originated from cybercriminals' claims about records allegedly offered through the Nexus dark-web marketplace.
New filing puts IDScan breach at 13 million people
A Texas breach listing dated Sept. 21 reports that 13 million people in total are affected by the IDScan incident. The listing also reports one affected resident in Texas.
IDScan previously said it received information around Sept. 1 indicating that certain data may have been accessed without authorization. According to a breach notification filed in Massachusetts, the company secured its systems and brought in third-party specialists to investigate the scope of the incident.
IDScan said an unauthorized third party may have accessed or copied customer information stored in accounts on the company's cloud platform. The affected information may include:
- Full names
- Driver's license numbers
- Other government-issued identification numbers
The company is offering potentially affected individuals complimentary credit monitoring and identity-protection services.
The Texas filing provides a concrete figure for the number of affected persons that was missing from IDScan's initial notification. It also adds another data point as regulators begin examining the incident.
Canada's privacy commissioner opened an investigation into IDScan on Sept. 21 following reports that an unauthorized third party accessed the company's database and stole personal information, including digital scans of driver's licenses and other identification. The investigation will examine IDScan's security safeguards at the time of the breach and the adequacy of its notifications to affected individuals to determine compliance with Canada's federal private-sector privacy law.
Large identity-data breaches can carry long-term risks because government-issued identification information cannot be changed as easily as a password. A recent AssuranceAmerica breach affecting nearly 7 million drivers similarly involved driver's license information alongside other personal and insurance data.
Why 13 million and 153 million are not the same number
The new filing should not be read as confirmation of the earlier claim that attackers obtained 153 million driver's license records.
Cybersecurity journalist Brian Krebs previously reported that a dark-web service called Nexus claimed to possess more than 153 million U.S. and Canadian driver's license records, along with more than 10 million identification-card records, more than 3 million travel documents or international IDs, and at least 579,000 medical-card records.
Recorded Future News subsequently reported that Krebs had authenticated samples from the dataset and connected the compromised information to IDScan. IDScan itself, however, has not publicly confirmed that 153 million driver's license records were stolen.
That distinction was central to eSecurity Planet's earlier coverage of four proposed class-action lawsuits against IDScan. At that point, the 153 million figure remained a dark-web claim, and IDScan had not disclosed an affected-person count.
The new filing fills in part of that gap: 13 million people are now reported to be affected by the breach, but that does not establish that the dark-web marketplace's claim of 153 million records was accurate.
A single person can also be associated with more than one record or document, making comparisons between the counts of people and records particularly difficult.
IDScan's role makes the exposed data especially sensitive
IDScan provides identity-verification technology for scanning, authenticating, and managing government-issued IDs. Its products are used for purposes including identity verification, age verification, and access management.
That makes the type of information involved particularly important.
Unlike a compromised password, a driver's license number or other government identifier may remain associated with a person for years. Stolen identity data can potentially be combined with information from other breaches to make phishing, impersonation, and account-recovery fraud more convincing.
That broader risk extends beyond any single breach. As eSecurity Planet previously reported, automated criminal tools can combine information from breached databases to build detailed profiles of potential targets from relatively small starting points such as an email address.
For organizations that use identity-verification providers, the incident also highlights how much sensitive information can accumulate within third-party platforms. Security teams should understand not only how vendors protect identity data, but how long that information is retained and what happens to it after verification is complete.
What potentially affected people should do now
Anyone who receives an IDScan breach notification should first determine which information the company says was associated with them.
IDScan is offering complimentary credit monitoring and identity-protection services to potentially affected individuals. People whose driver's license or other government identification information may have been exposed should also remain alert for suspicious attempts to use that information for impersonation or account recovery.
Useful precautions include:
- Enroll in the identity-protection services offered through the breach notification.
- Review credit reports and financial accounts for activity you do not recognize.
- Consider placing a credit freeze with the major credit bureaus if sensitive identity information was exposed.
- Treat unexpected messages referring to identity verification, driver's licenses, or breached accounts with caution.
- Avoid providing additional personal information in response to unsolicited calls, emails, or text messages.
- Keep a copy of the breach notification in case suspicious activity emerges later.
Other large breaches show why that vigilance can matter long after the initial disclosure. For example, an Aesto Health breach eventually grew to more than 9.5 million affected people as the scope of that incident became clearer.
For IDScan, the Sept. 21 filing answers one of the biggest outstanding questions by providing an affected-person count. It does not resolve exactly how those 13 million people relate to the far larger dataset advertised on the dark web, and the newly opened Canadian investigation means scrutiny of the incident is continuing.
Until the full scope becomes clearer, affected individuals should take advantage of the protections outlined in their breach notices, while organizations that use identity-verification providers should examine how much identity data their vendors retain and what safeguards protect it.
Read next: Infostealers are fueling enterprise identity attacks, as stolen credentials and active session data pose increasingly serious risks to enterprise systems.





