DataBreachSearch.com

Did IDScan.net have a data breach?

Answer

Yes. IDScan.net reported a data breach to the Oregon Attorney General on September 18, 2026.

View the official filing

What the filing says

Reported to
Oregon Attorney General
Filing date
September 18, 2026
Breach date
April 1, 2026
People affected
Not stated in the filing

Information involved

  • Full Name
  • Date of Birth
  • Mailing Address
  • Government ID Number
  • Driver's License Number
  • Scanned Identification Document Images
  • Biometric Metadata
  • Email Address
  • Phone Number

In plain terms

IDScan.net operates at the critical intersection of identity verification, age validation, and data parsing technology, providing advanced software and hardware solutions used to capture, parse, and authenticate government-issued identification cards, driver's licenses, and passports. Because their clients span high-security sectors including hospitality, gaming, law enforcement, banking, and age-restricted retail, IDScan.net processes and archives massive volumes of highly sensitive Personally Identifiable Information (PII). The company's infrastructure is designed to ingest and store intricate identity credentials, making its databases a high-value repository for cybercriminals seeking raw data capable of facilitating comprehensive digital impersonation.

The security incident reported to the Oregon Attorney General in 2026 highlights the pervasive vulnerabilities inherent in managing centralized identity verification databases and third-party software integrations. While the exact vector remains under active investigation, breaches of identity technology firms typically involve unauthorized external access, credential stuffing, or the compromise of cloud storage environments where parsed document data and scanning logs are maintained. Because IDScan.net handles raw image files of identification documents alongside structured demographic and biometric records, a successful penetration of their systems implies that attackers may have bypassed perimeter defenses to access deep storage archives containing historical scan logs.

The exposure of data originating from an identity verification platform creates severe, multi-faceted risks for affected consumers. Unlike a standard retail breach where only a credit card or email address might be compromised, an IDScan.net breach potentially exposes full legal names, dates of birth, physical addresses, government identification numbers, and biometric metadata extracted directly from scanned driver's licenses or passports. This constellation of data is exceptionally dangerous because government ID numbers and document images cannot be easily changed or reset like a password. Malicious actors can leverage these details to construct sophisticated synthetic identities, open fraudulent financial accounts, execute targeted phishing campaigns, bypass know-your-customer (KYC) security protocols on financial platforms, and commit wide-scale identity theft that can plague victims for years.

As an entity collecting and processing sensitive consumer credentials, IDScan.net operated under strict legal obligations to implement robust, industry-standard cybersecurity measures to protect stored PII. Under Oregon state data protection laws, as well as overarching federal standards enforced by the Federal Trade Commission Act, companies holding high-risk personal data are legally required to maintain reasonable security safeguards, including encryption at rest and in transit, multi-factor authentication, rigorous access controls, and regular vulnerability assessments. The occurrence of a data breach compromising sensitive identity records strongly suggests potential failures in these foundational security duties, raising serious questions about whether adequate encryption and monitoring protocols were actively enforced across all storage environments.

Receiving a data breach notification letter from IDScan.net is a formal acknowledgment that your private identity information was compromised due to inadequate corporate security practices, and it provides you with the legal standing necessary to participate in a class action lawsuit. In data privacy litigation, affected individuals do not need to prove that they have already suffered direct financial loss to seek legal recourse; the mere exposure and misappropriation of your sensitive data constitutes a compensable injury under modern consumer protection jurisprudence. Our law firm is investigating this breach on a contingency fee basis, meaning there is never any out-of-pocket cost or financial risk to you, and we only collect a fee if we successfully recover compensation on your behalf.

Other filings by IDScan.net

Companies often file the same breach in several states. Each filing is listed separately.

Commonly recommended next steps

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Oregon

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with IDScan.net.