IDScan, Florida Probe Driver-Data Breach Claims

The allegedly exposed records reportedly include information belonging to high-profile individuals, including Defense Secretary Pete Hegseth; the Department of Defense said it was aware of the reports and evaluating them.
IDScan provides identity-verification services to major companies including Hertz, FedEx and GameStop, meaning documents may have been collected when consumers rented vehicles, received deliveries or used other commercial services.
IDScan’s September 4 breach notice was configured with a “noindex” directive that prevented search engines from indexing it, a detail that contributed to criticism over the company’s limited public disclosure.
Security researchers cited IDScan documentation indicating that its products defaulted to collecting and retaining identity records, while the basic plan reportedly offered no option to delete them—raising questions about whether long-term data retention amplified the incident’s potential scale.
In the Florida incident, University of South Florida cybersecurity professor Thomas Hyslip said the attackers likely exploited an unpatched vulnerability in DAVID’s password-recovery function and described ShinyHunters as a financially motivated group that typically steals data to extort ransom payments.
An identity-verification company called IDScan has confirmed that hackers accessed customer data stored on its cloud platform, potentially exposing more than 153 million driver's licenses and government ID documents from the US and Canada HelpNetSecurity. The leaked data reportedly includes names, license numbers, and scans or photographs. A separate cybercrime group claims it stole about 200,000 Florida driver's licenses and Social Security numbers by exploiting a password-reset function in the state's DAVID database WCTV. The FBI and Florida officials are investigating both incidents.
IDScan processes identity checks for major companies like Hertz, FedEx, and GameStop CybersecurityInsiders. When you rent a car or use these services, your driver's license gets scanned and stored. A single breach at IDScan exposed documents collected across all these businesses. This creates what security experts call "systemic risk"—one company holds millions of records from many sources.
Worse, security researchers found that IDScan's default settings kept identity records forever with no easy way to delete them CybersecurityInsiders. Unlike passwords, you can't just change your driver's license number. Exposed IDs remain useful to criminals for years, potentially enabling identity fraud and impersonation for a long time.
The leaked records reportedly include information belonging to high-profile individuals, including Defense Secretary Pete Hegseth CyberInsider. The Department of Defense said it was aware of the reports and is evaluating them. The breach highlights how identity data breaches don't just affect ordinary people—public officials and government leaders face the same exposure risks.
A cybercrime group called ShinyHunters claims it stole about 200,000 Florida driver's licenses and Social Security numbers from Florida's DAVID database WCTV. The attackers exploited a vulnerability in the password-reset function, according to security experts. Cybersecurity professor Thomas Hyslip said attackers likely used an unpatched weakness to gain access WCTV. ShinyHunters typically steals data to demand ransom payments.
Florida officials have not confirmed the breach but temporarily disabled the password-reset feature and are investigating FOX10TV. The incident shows how even government databases can fall victim to attackers who exploit old security flaws. Unlike private companies, government agencies move slowly to patch vulnerabilities.
IDScan posted its breach notice on September 4 but configured it with a "noindex" directive that blocked search engines from finding it HelpNetSecurity. This kept the public from easily discovering the announcement. Critics say the company did not disclose the breach loudly or quickly enough. Lawsuits have already been filed against the company.
Major questions remain unanswered: How many people were actually affected? Did attackers demand a ransom? How long was the breach happening before IDScan discovered it? CyberInsider The company says it has now secured its systems, hired outside specialists, and is offering free credit monitoring and identity-protection services to those potentially exposed.
Publishers
17
Articles
22
Reach
39