IDScan, a company providing identity verification services, has acknowledged a data breach involving the theft of driver’s license information from its cloud systems. The breach was initially reported by cybersecurity journalist Brian Krebs, who discovered a dark web database containing searchable records of over 150 million driver’s licenses from the United States and Canada. The stolen data includes full names, driver’s license numbers, and identity numbers from other government-issued documents such as passports.

IDScan’s services are used by various businesses, including entertainment venues and cannabis dispensaries, to verify customer identities. The company first announced it was investigating a potential security incident last week but only recently confirmed the breach in a notice on its website. The notice states that IDScan was alerted to the hack around September 1, coinciding with Krebs’ public report.

The exposed database reportedly contains information on high-profile individuals, including the U.S. Secretary of Defense and a security researcher who verified their own data. The FBI and the Pentagon have acknowledged awareness of the breach and are investigating.

IDScan’s statement indicates that full access to the stolen data required payment, suggesting a possible ransom demand by the hackers. The company has not disclosed the total number of affected individuals but notes that it holds records for over 150 million driver’s licenses. IDScan has not responded to inquiries regarding ransom negotiations or further details about the breach.

This incident highlights the risks associated with centralized storage of sensitive identity information and raises concerns about the security practices of companies handling such data. The breach could have significant implications for identity theft and fraud prevention efforts.