IDScan Confirms Breach Affecting 150 Million-Plus IDs
Identity verification company IDScan.net has confirmed what security researchers had been warning about for weeks: its systems were breached, and the personal data connected to more than 150 million driver's license records has been exposed. The confirmation follows earlier reports that a dark web service was offering digital scans of driver's licenses tied to IDScan's platform.
What makes this incident notable isn't just the scale, it's the client list. Hertz, FedEx, and Target have all been named as businesses that relied on IDScan's verification services, meaning customers of these companies may have had their driver's license data swept up in the breach without ever knowing IDScan was involved in the transaction at all. Most people who rented a car, verified a delivery, or completed an age check at checkout had no direct relationship with IDScan. They simply interacted with a familiar brand that, behind the scenes, outsourced identity verification to a third-party vendor.
This breach has already drawn legal scrutiny. As covered in our earlier reporting on the IDScan breach and its role in the KOSA safety debate, the scale of exposed driver's license data has become a flashpoint in broader conversations about how much personal identification information companies should be allowed to collect, store, and share with outside vendors in the first place.
Why Third-Party ID Verification Vendors Are a Growing Attack Surface
The IDScan incident illustrates a structural problem that extends far beyond one company. When large brands need to verify a customer's age, identity, or eligibility, many don't build that capability in-house. Instead, they route sensitive documents, driver's licenses, passports, and other government-issued IDs, through specialized third-party vendors that promise faster, more accurate verification.
That arrangement creates a single point of failure. Instead of a breach affecting one company's customer base, a compromise at a shared vendor like IDScan can ripple across every business that relies on it. A consumer who never directly submitted information to IDScan.net still ends up with their driver's license data at risk, simply because the retailer, rental company, or shipping service they trusted outsourced that verification step.
This dynamic is exactly what has fueled the lawsuits and regulatory attention detailed in our prior coverage of the IDScan breach fueling the KOSA safety debate. As more platforms adopt age verification and identity checks, often in response to new regulations, the pool of sensitive documents flowing through third-party vendors keeps growing, and so does the potential blast radius when one of those vendors is compromised.
What Hertz, FedEx, and Target Customers Should Do Now
If you've rented a vehicle from Hertz, verified a delivery through FedEx, or completed an identity check at Target within the timeframe that IDScan processed data, it's worth treating your driver's license information as potentially exposed. A driver's license number, combined with a name, date of birth, and address, is often enough for identity thieves to open new accounts, file fraudulent tax returns, or pass themselves off as you in other contexts.
Start by checking whether any of the three named companies have sent breach notifications directly. Even if you haven't received one yet, consider placing a fraud alert or credit freeze with the major credit bureaus, since driver's license data is frequently used to bypass other identity checks. Monitor your accounts for unfamiliar activity, and be cautious of phishing attempts that may reference the breach to appear legitimate. Scammers often follow high-profile breaches with targeted emails or texts designed to extract even more information from affected individuals.
Limiting Future Exposure: Reducing How Much ID Data You Share
While you can't control how a retailer or rental company handles verification behind the scenes, you can be more deliberate about when and where you hand over a driver's license image or scan. Ask whether a physical inspection is sufficient before agreeing to upload a photo of your ID to an app or website. When digital verification is unavoidable, check whether the company discloses which vendor processes that data, and look for privacy policies that specify how long records are retained.
It's also worth periodically searching for your own information alongside terms like your name and "driver's license" to catch early signs of exposure, and using identity monitoring services that specifically watch for government ID misuse rather than just credit card numbers.
The Bottom Line
The IDScan data breach driver's license exposure shows how quickly a single vendor compromise can spread across household-name brands. Hertz, FedEx, and Target customers didn't choose to share their data with IDScan.net, yet many now face the same risks as if they had. As identity verification becomes more common online and in stores, staying alert to which vendors are handling your documents, and pushing back when it's not clear, is one of the few ways consumers can push back against this growing attack surface. If you've done business with any of the named companies recently, take the precautionary steps now rather than waiting for a formal notification letter to arrive.




