IDScan, a Louisiana-based company that provides identity verification services, has confirmed that a data breach occurred, resulting in the theft of driver’s licenses from its systems. The company announced on its website that hackers accessed its cloud systems and stole personal information, including full names, driver’s license numbers, and identity numbers from other government-issued documents like passports. IDScan is used by a variety of businesses, from entertainment venues to cannabis dispensaries, to verify the identities of their customers. This is the first time IDScan has officially acknowledged a cyberattack. Earlier in the week, the company said it was investigating an incident but had not yet confirmed a breach. According to IDScan’s notice, it received information around September 1 about a claim of a hack, the same day that cybersecurity journalist Brian Krebs first reported a data breach at the company. Krebs discovered a website on the dark web where users could search the driver’s license information of over 150 million people in the U.S. and Canada, including photos. Krebs verified the authenticity of the data by checking his own record. The database also included information on high-profile individuals, such as U.S. Secretary of Defense Pete Hegseth and a security researcher who confirmed their data for Krebs’ report. The Pentagon told TechCrunch last week that it was aware of the suspected breach, and an FBI spokesperson confirmed that the agency is also investigating the incident. IDScan stated that its investigation into the breach is ongoing and noted that, while full access to the stolen data required payment—likely a ransom demand from the hackers—the company was informing affected individuals through its website. However, IDScan has not disclosed how many people are affected, only stating that it holds records for over 150 million driver’s licenses. The company did not respond to TechCrunch’s request for further details, including whether the hackers had made a ransom demand in exchange for not releasing the data.