Reported to the TX Attorney General on September 21, 2026.
TX residents may qualify for compensation. Free attorney review — no obligation, no upfront cost.
Check My Rights →IDScan.net was the subject of a data breach notification filed with the TX Attorney General. The AG filing was recorded on September 21, 2026. The breach or discovery date reported in the filing is April 1, 2026.
IDScan.net operates at the critical intersection of identity verification, compliance technology, and secure data processing. As a prominent provider of ID scanning hardware, software-as-a-service (SaaS) solutions, and age-verification systems, the company serves a wide range of highly regulated industries, including hospitality, banking, cannabis retail, law enforcement, and enterprise security. To perform its core functions—such as verifying driver licenses, passports, and government-issued identification documents—IDScan.net ingests, processes, and stores vast quantities of high-value, sensitive personal information on a daily basis. The company's platforms are engineered to capture detailed identity data instantly, making it a central repository for foundational identity markers that malicious actors target for exploitation. The security incident reported by IDScan.net to the Texas Attorney General in 2026 highlights the immense vulnerabilities inherent in managing centralized identity verification databases. While exact technical forensics vary during large-scale network intrusions, incidents involving identity verification technology companies typically stem from unauthorized access to cloud storage buckets, compromised API credentials, or sophisticated ransomware deployments targeting core database architecture. Given the nature of IDScan.net's operations, an infiltration of this scale suggests that external threat actors may have bypassed critical perimeter defenses, exploiting gaps in network segmentation or third-party vendor integrations to gain persistent, unauthorized access to systems designed to protect sensitive personal records. The exposure resulting from the IDScan.net data breach threatens individuals with severe, long-term risks because the compromised information goes far beyond basic contact details. When identity verification databases are compromised, attackers frequently gain access to high-fidelity scans of government-issued identification cards, full legal names, dates of birth, residential addresses, and biometric identifiers or document metadata. Unlike a stolen credit card, which can be canceled and replaced, core identity markers are immutable. The unauthorized disclosure of this deep-level personal data equips cybercriminals with the exact components needed to orchestrate sophisticated identity theft, open fraudulent financial accounts, execute synthetic identity fraud, and bypass biometric or document-based security controls across other platforms used by the victims. As a commercial entity entrusted with handling and storing sensitive consumer and citizen data, IDScan.net is bound by stringent legal obligations under state data protection statutes, such as the Texas Identity Theft Enforcement and Protection Act, as well as the overarching enforcement authority of the Federal Trade Commission Act. These legal frameworks mandate that companies maintain reasonable security procedures and practices appropriate to the nature of the personal information in their possession. The occurrence of a data breach of this magnitude serves as a strong indication of a potential failure in these statutory duties—suggesting that technical safeguards, encryption standards, vulnerability patching, or access controls fell short of the legal thresholds required to prevent unauthorized data exfiltration. Receiving a data breach notification letter from IDScan.net is an official acknowledgment that your private information was compromised due to inadequate data security practices, and it provides you with the legal standing necessary to participate in a class action lawsuit. In data privacy litigation, affected individuals do not need to prove that they have already suffered actual financial loss or out-of-pocket fraud to seek legal redress; the increased, imminent risk of future identity theft and the forced expenditure of time and money to mitigate that risk are recognized legal harms. Our firm investigates these matters on a strict contingency fee basis, meaning you pay no out-of-pocket costs and face no financial risk unless we successfully recover compensation on your behalf.
Based on the data types reported in this filing, affected individuals face the following specific risks:
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.
Under the Texas Identity Theft Enforcement and Protection Act, you may have a legal claim against IDScan.net if any of the following apply:
Applicable law: This breach was reported under the Texas Identity Theft Enforcement and Protection Act, which establishes your right to seek damages from IDScan.net.
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Texas Identity Theft Enforcement and Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from IDScan.net does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by IDScan.net during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.
Received a notification letter from IDScan.net?
Read our dedicated guide — what the letter means and exactly what to do.
If you were affected by the IDScan.net data breach, you may be entitled to compensation. Submit your information below for a free attorney review — no obligation, no upfront cost.
Source: State Attorney General filing, TX
View Official AG Filing →Case review window ends November 16, 2026 — review your letter.
Review Your Letter →IDScan.net breach?
Free case review · No fee unless you win