IDScan breach: 150M IDs and your verification vendor
IDScan confirmed a breach exposing 150M+ driver's licenses. Why your identity verification vendor is a bigger liability than your own database.
IDScan.net confirmed on September 10 that hackers stole driver's license records from its cloud — a database tied to more than 150 million people in the United States and Canada. TechCrunch reported the confirmation. If you outsource identity verification, you just learned what your vendor's blast radius looks like.
What actually happened
Brian Krebs found it first. On September 1, a dark web search site called Nexus appeared advertising a browsable index of stolen government IDs, and TechCrunch followed the trail back to IDScan.net, a Louisiana company that verifies tens of millions of IDs a month for customers ranging from entertainment venues to cannabis dispensaries.
The stolen data includes full names, driver's license numbers, ID numbers from other government documents including passports, and the license photos themselves. The Nexus operators claimed roughly 500,000 new documents were being added daily — which reads less like a one-time dump and more like a live feed. Nexus went offline after Krebs published. The FBI's New Orleans field office is investigating. IDScan says it will notify affected individuals.
Note what is not a bug here: the vendor was doing exactly what it was hired to do. Collecting IDs at scale is the product. The breach is the product working, with an extra reader attached.
Why your identity verification vendor is now your risk
Every age gate, every KYC step, every "scan your license to pick up" flow hands a permanent identifier to a third party. Driver's license numbers do not rotate. Passport numbers do not rotate. Your customer cannot change their face. A leaked password is a Tuesday; a leaked license photo is forever.
Small operators outsource this precisely to avoid holding the data — and that instinct is correct. The mistake is assuming the outsourcing ends your exposure. It moves it. Your customers gave you their ID. When the vendor leaks, they will call you, and depending on your state, your breach notification obligation may not care whose S3 bucket it was.
Three things worth doing this week. First, find out what your verification vendor retains after a check passes — the answer should be a yes/no and a timestamp, not an image. Second, check your contract for a retention limit and a deletion SLA with a number in it. Most don't have one. Third, ask whether you actually need verification at all, or whether you copied it from a competitor.
The cheapest PII to protect is PII you never stored.
Key takeaways
- IDScan.net confirmed a breach affecting a database tied to 150M+ people in the US and Canada
- Stolen data includes names, license numbers, passport numbers, and license photos — none of which can be rotated
- The dark web site Nexus claimed ~500,000 new documents added daily, suggesting sustained access rather than a single dump
- The FBI is investigating; IDScan says it will notify affected individuals
- Outsourcing verification moves your PII exposure to a vendor — it does not remove it, and your customers will still call you
- Audit vendor retention: a passing check should leave a boolean and a timestamp, not a stored image
The best breach response is a smaller data footprint. We design intake and verification flows that keep identifiers out of your systems entirely — pass/fail results, short retention, and no images sitting in a bucket you forgot about. See how we handle sensitive data, or send us the flow you're worried about.
Sources: TechCrunch (Sept 10), TechCrunch (Sept 2).
- #data-breach
- #identity-verification
- #vendor-risk
- #pii
- #compliance
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
ShieldCrash: Microsoft's Defender patch got bypassed again
A new PoC reads arbitrary files as SYSTEM on fully patched Windows after September's update. Third Defender escalation in the same chain since June.
Read itCisco FMC CVE-2026-20079: patched in March, exploited now
A CVSS 10.0 auth bypass in Cisco Secure Firewall Management Center is under active attack six months after the fix shipped. Sandworm and Qilin are both in the logs.
Read it