IDScan.net says it is investigating a data-security incident involving customer information stored within accounts on its cloud service. In a notification dated September 4, the identity-verification company said it received information on or around September 1 indicating that certain data may have been accessed without authorization.
The company said an unauthorized third party may have accessed and/or copied certain customer information stored in IDScan.net cloud accounts. According to the notice, the affected data may include full names and driver’s-license or other government-issued identification numbers. The investigation is ongoing, so this is the boundary of what the company has publicly confirmed.
What IDScan.net has confirmed
IDScan.net says it took steps to secure its systems after learning of the issue and brought in third-party specialists to help determine the incident’s nature and scope. It also says it is cooperating with federal law enforcement.
The notice does not provide a confirmed record count, a technical entry point, a complete data inventory, a specific threat actor, or a definitive statement that every account or customer was affected. Those details matter, and they should not be filled in from marketplace claims or reporting that the company itself has not substantiated.
For affected people, the distinction between a confirmed data category and a publicly reported estimate is important. A government-issued identification number can be useful in identity-theft and impersonation attempts, but the appropriate response should be based on a notification from the company and on evidence of account misuse—not assumptions about information that may not have been included in a particular person’s record.
What potentially affected individuals can do
IDScan.net says it is notifying potentially impacted individuals and offering free credit monitoring and identity-protection services. The company’s notice says access to the information required payment, and recommends that people remain vigilant for signs of identity theft or fraud.
Recommendations
- Use the company’s notification channel. If you receive an IDScan.net notice, confirm eligibility for the credit-monitoring and identity-protection service through the contact information in the company’s official notice.
- Review credit reports and account statements. IDScan.net specifically recommends looking for suspicious activity and errors. Treat unfamiliar account openings, address changes or service requests as signals to investigate promptly.
- Consider fraud alerts or a credit freeze. The company’s notice points affected individuals to the major credit-reporting agencies and the FTC’s identity-theft resources for these options. Choose the measure that fits your situation and local requirements.
- Expect targeted impersonation attempts. Do not rely on unexpected calls, texts or emails that claim to be about this incident. Independently locate the organization’s contact details rather than following links or numbers supplied in an unsolicited message.
- Keep records. Save the notification, enrollment confirmation and any evidence of suspicious activity. That makes it easier to report fraud and resolve account disputes if follow-up is needed.
What remains unknown
The current notice is an early incident disclosure, not a final forensic report. It says the company is still determining the full nature and scope of the event. Until IDScan.net publishes further detail, claims about the total volume of records, the duration of access, the exact documents involved, or the origin of any data offered elsewhere should be treated as unverified in relation to this incident.
Organizations that use identity-verification providers can take a parallel lesson from the disclosure: know which third parties hold identity documents or ID-derived data, what accounts and data fields are involved, how notifications will reach customers, and who owns the response if a provider reports a potential exposure. That preparation does not resolve the current incident, but it shortens the time between a vendor notice and a measured, evidence-based response.



