Did IDScan.net have a data breach?
Answer
Yes. IDScan.net reported a data breach to the Oregon Attorney General on September 18, 2026.
View the official filingWhat the filing says
- Reported to
- Oregon Attorney General
- Filing date
- September 18, 2026
- Breach date
- April 1, 2026
- People affected
- Not stated in the filing
Information involved
- Full Name
- Date of Birth
- Mailing Address
- Government ID Number
- Driver's License Number
- Scanned Identification Document Images
- Biometric Metadata
- Email Address
- Phone Number
In plain terms
IDScan.net operates at the critical intersection of identity verification, age validation, and data parsing technology, providing advanced software and hardware solutions used to capture, parse, and authenticate government-issued identification cards, driver's licenses, and passports. Because their clients span high-security sectors including hospitality, gaming, law enforcement, banking, and age-restricted retail, IDScan.net processes and archives massive volumes of highly sensitive Personally Identifiable Information (PII). The company's infrastructure is designed to ingest and store intricate identity credentials, making its databases a high-value repository for cybercriminals seeking raw data capable of facilitating comprehensive digital impersonation.
The security incident reported to the Oregon Attorney General in 2026 highlights the pervasive vulnerabilities inherent in managing centralized identity verification databases and third-party software integrations. While the exact vector remains under active investigation, breaches of identity technology firms typically involve unauthorized external access, credential stuffing, or the compromise of cloud storage environments where parsed document data and scanning logs are maintained. Because IDScan.net handles raw image files of identification documents alongside structured demographic and biometric records, a successful penetration of their systems implies that attackers may have bypassed perimeter defenses to access deep storage archives containing historical scan logs.
The exposure of data originating from an identity verification platform creates severe, multi-faceted risks for affected consumers. Unlike a standard retail breach where only a credit card or email address might be compromised, an IDScan.net breach potentially exposes full legal names, dates of birth, physical addresses, government identification numbers, and biometric metadata extracted directly from scanned driver's licenses or passports. This constellation of data is exceptionally dangerous because government ID numbers and document images cannot be easily changed or reset like a password. Malicious actors can leverage these details to construct sophisticated synthetic identities, open fraudulent financial accounts, execute targeted phishing campaigns, bypass know-your-customer (KYC) security protocols on financial platforms, and commit wide-scale identity theft that can plague victims for years.
As an entity collecting and processing sensitive consumer credentials, IDScan.net operated under strict legal obligations to implement robust, industry-standard cybersecurity measures to protect stored PII. Under Oregon state data protection laws, as well as overarching federal standards enforced by the Federal Trade Commission Act, companies holding high-risk personal data are legally required to maintain reasonable security safeguards, including encryption at rest and in transit, multi-factor authentication, rigorous access controls, and regular vulnerability assessments. The occurrence of a data breach compromising sensitive identity records strongly suggests potential failures in these foundational security duties, raising serious questions about whether adequate encryption and monitoring protocols were actively enforced across all storage environments.
Receiving a data breach notification letter from IDScan.net is a formal acknowledgment that your private identity information was compromised due to inadequate corporate security practices, and it provides you with the legal standing necessary to participate in a class action lawsuit. In data privacy litigation, affected individuals do not need to prove that they have already suffered direct financial loss to seek legal recourse; the mere exposure and misappropriation of your sensitive data constitutes a compensable injury under modern consumer protection jurisprudence. Our law firm is investigating this breach on a contingency fee basis, meaning there is never any out-of-pocket cost or financial risk to you, and we only collect a fee if we successfully recover compensation on your behalf.
Other filings by IDScan.net
Companies often file the same breach in several states. Each filing is listed separately.
Commonly recommended next steps
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Oregon
- Poppins Payroll CompanyYes — reportedOregon · September 30, 2026
- Midvale Indemnity CompanyYes — reportedOregon · September 30, 2026
- Lamb Weston Holdings, Inc.Yes — reportedOregon · September 29, 2026
- Upbound Group, Inc.Yes — reportedOregon · September 28, 2026
- OneMain FinancialYes — reportedOregon · September 28, 2026
- MedImpact Healthcare Systems, Inc.Yes — reportedOregon · September 26, 2026
- Call-On-Doc, Inc.Yes — reportedOregon · September 24, 2026
- Ridgeway Pharmacy LtdYes — reportedOregon · September 21, 2026
- Kaniksu Community HealthYes — reportedOregon · September 15, 2026
- Craneware, Inc.Yes — reportedOregon · September 14, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with IDScan.net.