// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / IDScan.net
Breach Record

IDScan.net

DISCLOSED 2026-09-10 · UNPATCHED CVE

IDScan.net, an identity verification company, had a vulnerability that allowed hackers to access a live feed of every ID scanned for over a year. The exposed data included driver's license scans, including that of the Secretary of Defense, which were being sold for $100. The breach was discovered by security researcher Brian Krebs.

The record

What we know

Disclosed
2026-09-10
Attack vector
Unpatched Cve
Sector
identity verification
Country
USA
Domain
idscan.net
Data classes exposed
driver's license scanspersonal identification information
Sources

Cited reporting

Similar vector · recent

Other unpatched cve breaches on file

This page is the permanent ColdRecon entry for the IDScan.net disclosure. It updates if new public reporting emerges. All tracked breaches →

IDScan.net just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →