IDScan.net Reports Data Breach to Texas AG in 2026
IDScan.net, a provider of identity verification technology, disclosed a data breach to the Texas Attorney General in September 2026, stemming from an incident on April 1, 2026. The compromise exposed sensitive personal information including Full Name, Government ID Number, and Biometric Verification Data. Affected individuals face potential risks of identity theft and sophisticated fraud.
- State
- Texas
- Breach date
- April 1, 2026
- Reported
- September 21, 2026
What may have been exposed
- Full Name
- Date of Birth
- Government ID Number
- Scanning Metadata
- Residential Address
- Biometric Verification Data
- Email Address
- Phone Number
IDScan.net, a company specializing in identity verification and compliance technology, has filed a data breach notification with the Texas Attorney General's office on September 21, 2026. The company reported an unspecified security incident that occurred on April 1, 2026. The investigation into the matter is currently listed as 'monitoring' status, according to the official filing.
The sensitive data reportedly exposed in this incident includes Full Name, Date of Birth, Government ID Number, Scanning Metadata, Residential Address, Biometric Verification Data, Email Address, and Phone Number. Given IDScan.net's role in processing high-value identity documents, the exposure of these specific data categories is particularly concerning due to their direct link to an individual's core identity.
Such a breach can equip malicious actors with the precise components needed for sophisticated identity theft, fraudulent account creation, and bypassing security checks that rely on identity verification. Unlike financial data which can often be reissued, foundational identity markers like those exposed are immutable, making long-term vigilance crucial for those affected.
If you receive a data breach notification from IDScan.net, it is important to take proactive measures to protect yourself. Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus (Equifax, Experian, and TransUnion). Regularly review your financial account statements, credit reports, and explanation of benefits statements for any unauthorized activity.
Additionally, be cautious of any unsolicited communications, particularly those asking for personal information, as they could be phishing attempts. Remaining vigilant and responding promptly to any suspicious activity can help mitigate the potential impact of such a data compromise. This information is based on public records filed with regulatory bodies.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Texas Attorney General filing
Related data breach cases
- Aprio Advisory Group, LLC
- Seyfarth Shaw LLP
- Doctor's Choice Home Care
- Affordable Mortgage Advisors
- Call-on-Doc
- Opportune LLP
- The City of Jacksonville, TX
- Boston Capital Holdings LP
- Three Oaks Hospice, Inc.
- Three Oaks Hospice of West Houston
- Three Oaks Hospice of San Antonio
- Three Oaks Hospice of North East Texas
- Three Oaks Hospice of Fort Worth
- Mitchell County Hospital District