DataBreachSearch.com
MonitoringTexas AG filing · September 21, 2026

IDScan.net Reports Data Breach to Texas Attorney General in 2026

IDScan.net reported a data breach to the Texas Attorney General on September 21, 2026, stemming from an incident on April 1, 2026. This security incident potentially exposed sensitive identity verification data for individuals, raising concerns about potential misuse of personal information.

State
Texas
Breach date
April 1, 2026
Reported
September 21, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Government ID Number
  • Scanning Metadata
  • Residential Address
  • Biometric Verification Data
  • Email Address
  • Phone Number

IDScan.net, a provider of identity verification solutions, filed a data breach notification with the Texas Attorney General on September 21, 2026. The company indicated that a security incident occurred on April 1, 2026, leading to the exposure of personal data. The investigation into the full scope and impact of this breach is currently described as monitoring by the company.

The exposed data types, as reported in the official filing, include Full Name, Date of Birth, Government ID Number, Scanning Metadata, Residential Address, Biometric Verification Data, Email Address, and Phone Number. These categories of information are commonly handled by IDScan.net's systems for identity and age verification across various regulated industries.

The compromise of such detailed identity information presents significant risks for affected individuals. The combination of full names, government ID numbers, residential addresses, and biometric verification data could be used in various forms of identity-related fraud. This type of information is foundational to an individual's identity, making proactive steps important.

Individuals who receive a breach notification from IDScan.net should remain vigilant for unusual activity. It is advisable to review financial statements and credit reports regularly for any unauthorized accounts or transactions. Consider placing a fraud alert or credit freeze with major credit bureaus to help prevent new accounts from being opened in your name.

Additionally, be cautious of unsolicited communications via email, phone, or mail that ask for personal information. Fraudsters often use breach events as an opportunity for phishing or social engineering attempts. Always verify the legitimacy of any requests for personal data, especially if they claim to be from IDScan.net or other official entities.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Texas Attorney General filing

Related data breach cases