IDScan.net Data Breach in 2026 Exposes Core Identity Verification Records
IDScan.net, a provider of identity verification services, reported an unspecified data breach to regulators in September 2026. The incident, which occurred in April 2026, exposed a range of sensitive personal data, including foundational identity details collected for verification purposes, posing potential risks to affected individuals.
- State
- Texas
- Breach date
- April 1, 2026
- Reported
- September 21, 2026
What may have been exposed
- Full Name
- Date of Birth
- Government ID Number
- Scanning Metadata
- Residential Address
- Biometric Verification Data
- Email Address
- Phone Number
IDScan.net, a company specializing in identity verification and age-verification systems, reported an unspecified data breach to the Texas Attorney General on September 21, 2026. The security incident itself is noted as occurring on April 1, 2026, impacting systems that handle sensitive personal information.
The reported exposed data includes Full Name, Date of Birth, Government ID Number, Scanning Metadata, Residential Address, Biometric Verification Data, Email Address, and Phone Number. These categories represent a significant portion of the core identity information often collected and processed by verification services.
Such a broad exposure of personal identifiers carries substantial risks. Unlike easily changeable data, elements like Full Name, Date of Birth, and Government ID Number are fundamental to an individual's identity and cannot be readily altered. Their compromise could potentially enable various forms of identity theft, unauthorized access, or fraudulent activities.
Individuals who receive a notification regarding this IDScan.net breach are encouraged to take general protective measures. It is advisable to consistently monitor financial accounts and statements for any unusual transactions, regularly review credit reports for unfamiliar inquiries or accounts, and exercise caution with unexpected communications requesting personal information.
As a proactive step, consider implementing a fraud alert or a security freeze on your credit files with the three major credit bureaus. These measures can help prevent unauthorized parties from opening new accounts in your name and add a layer of protection against potential misuse of your exposed data.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Texas Attorney General filing
Related data breach cases
- Aprio Advisory Group, LLC
- Seyfarth Shaw LLP
- Doctor's Choice Home Care
- Affordable Mortgage Advisors
- Call-on-Doc
- Opportune LLP
- The City of Jacksonville, TX
- Boston Capital Holdings LP
- Three Oaks Hospice, Inc.
- Three Oaks Hospice of West Houston
- Three Oaks Hospice of San Antonio
- Three Oaks Hospice of North East Texas
- Three Oaks Hospice of Fort Worth
- Mitchell County Hospital District