IDScan.net Data Breach: What Exposed Identity Data Means for You
Identity verification firm IDScan.net experienced a data breach on April 1, 2026, exposing sensitive identity information including government IDs and biometric data. This puts affected individuals at risk for severe identity theft and fraud. If you received a notification, you may have legal recourse.
Received a IDScan.net notification letter? Find out in minutes if you qualify for compensation.
Free case review- State
- Oregon
- Breach date
- April 1, 2026
- Reported
- September 18, 2026
What may have been exposed
- Full Name
- Date of Birth
- Mailing Address
- Government ID Number
- Driver's License Number
- Scanned Identification Document Images
- Biometric Metadata
- Email Address
- Phone Number
Identity verification provider IDScan.net reported a data breach to the Oregon Attorney General on September 18, 2026, stemming from an incident that occurred on April 1, 2026. The company, which handles vast amounts of personal identity data for various industries, experienced an unspecified security lapse.
The exposed data includes highly sensitive personal information. Affected individuals may have had their Full Name, Date of Birth, Mailing Address, Government ID Number, Driver's License Number, Scanned Identification Document Images, Biometric Metadata, Email Address, and Phone Number compromised. This combination of data is particularly dangerous, as government identification numbers and document images are difficult to change, making victims vulnerable to sophisticated identity theft for years.
Companies like IDScan.net are legally obligated to protect the sensitive data they collect and store. Their failure to prevent this breach suggests potential shortcomings in their cybersecurity protocols and data protection measures. These obligations exist under state and federal laws to ensure consumer data is handled securely.
If you received a data breach notification letter from IDScan.net, it indicates your information was exposed. This event may entitle you to pursue compensation through legal action. Our firm is currently investigating this breach and offers free case reviews to help you understand your options. There are no upfront costs, and we only get paid if we recover for you.
Received a IDScan.net notification letter? Our legal team tracks every IDScan.net data breach filing and offers a free case review. See the full IDScan.net case file on DataBreachClassActions
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Oregon Attorney General filing
Related data breach cases
- Lamb Weston Holdings, Inc.
- OneMain Financial
- Upbound Group, Inc.
- MedImpact Healthcare Systems, Inc.
- Call-On-Doc, Inc.
- Ridgeway Pharmacy Ltd
- Kaniksu Community Health
- Craneware, Inc.
- See's Candies - Corporate Office
- Cornerstone Staffing Solutions, Inc.
- zHealth, Inc.
- Greenberg Traurig, LLP (“GT”)
- Northwest Paper Box Manufacturers
- Quatrro Business Support Services, Inc.