IDScan.net Data Breach Exposes Government ID and Biometric Data
IDScan.net reported a data breach to the Oregon Attorney General on September 18, 2026, involving highly sensitive identity verification data. Exposed information includes full names, dates of birth, government ID numbers, driver's license numbers, scanned identification images, and biometric metadata, posing significant risks for identity fraud.
- State
- Oregon
- Breach date
- April 1, 2026
- Reported
- September 18, 2026
What may have been exposed
- Full Name
- Date of Birth
- Mailing Address
- Government ID Number
- Driver's License Number
- Scanned Identification Document Images
- Biometric Metadata
- Email Address
- Phone Number
IDScan.net, a provider of identity verification and age validation technology, disclosed a data breach to the Oregon Attorney General on September 18, 2026. The incident, which IDScan.net indicated occurred on April 1, 2026, is currently under monitoring, according to public filings. The company specializes in processing and authenticating government-issued identification, meaning its systems contain significant volumes of sensitive personal information.
The reported exposure includes Full Name, Date of Birth, Mailing Address, Government ID Number, Driver's License Number, Scanned Identification Document Images, Biometric Metadata, Email Address, and Phone Number. This comprehensive set of identity credentials, originating from an identity verification service, is particularly sensitive as it includes foundational elements used for establishing and proving identity.
The exposure of such a wide range of identity data, particularly government identification numbers and scanned document images, carries elevated risks for affected individuals. Unlike typical compromises, these details are difficult to change and can be leveraged for sophisticated identity theft, creation of synthetic identities, or to bypass security protocols. Malicious actors could use this information to open fraudulent accounts or engage in impersonation.
Individuals who receive a breach notification from IDScan.net should consider immediately reviewing their financial statements and credit reports for any suspicious activity. Placing a fraud alert or instituting a credit freeze with the major credit bureaus can help prevent new accounts from being opened in their name. Additionally, remaining vigilant against unsolicited communications, particularly those asking for personal information, is a critical protective measure.
This incident highlights the challenges in securing extensive databases of identity credentials. Details surrounding the breach are based on information publicly filed by IDScan.net with regulatory authorities. Organizations that process and store government identification data are expected to maintain stringent security protocols to safeguard this high-value personal information.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Oregon Attorney General filing
Related data breach cases
- OneMain Financial
- Upbound Group, Inc.
- MedImpact Healthcare Systems, Inc.
- Call-On-Doc, Inc.
- Ridgeway Pharmacy Ltd
- Kaniksu Community Health
- Craneware, Inc.
- See's Candies - Corporate Office
- Cornerstone Staffing Solutions, Inc.
- zHealth, Inc.
- Greenberg Traurig, LLP (“GT”)
- Northwest Paper Box Manufacturers
- Quatrro Business Support Services, Inc.
- ASOS US Sales LLC