Skip to content
Rush Commerce
Software & Dev3 min read

IDScan breach: 150M IDs and your verification vendor

IDScan confirmed a breach exposing 150M+ driver's licenses. Why your identity verification vendor is a bigger liability than your own database.

IDScan.net confirmed on September 10 that hackers stole driver's license records from its cloud — a database tied to more than 150 million people in the United States and Canada. TechCrunch reported the confirmation. If you outsource identity verification, you just learned what your vendor's blast radius looks like.

What actually happened

Brian Krebs found it first. On September 1, a dark web search site called Nexus appeared advertising a browsable index of stolen government IDs, and TechCrunch followed the trail back to IDScan.net, a Louisiana company that verifies tens of millions of IDs a month for customers ranging from entertainment venues to cannabis dispensaries.

The stolen data includes full names, driver's license numbers, ID numbers from other government documents including passports, and the license photos themselves. The Nexus operators claimed roughly 500,000 new documents were being added daily — which reads less like a one-time dump and more like a live feed. Nexus went offline after Krebs published. The FBI's New Orleans field office is investigating. IDScan says it will notify affected individuals.

Note what is not a bug here: the vendor was doing exactly what it was hired to do. Collecting IDs at scale is the product. The breach is the product working, with an extra reader attached.

Why your identity verification vendor is now your risk

Every age gate, every KYC step, every "scan your license to pick up" flow hands a permanent identifier to a third party. Driver's license numbers do not rotate. Passport numbers do not rotate. Your customer cannot change their face. A leaked password is a Tuesday; a leaked license photo is forever.

Small operators outsource this precisely to avoid holding the data — and that instinct is correct. The mistake is assuming the outsourcing ends your exposure. It moves it. Your customers gave you their ID. When the vendor leaks, they will call you, and depending on your state, your breach notification obligation may not care whose S3 bucket it was.

Three things worth doing this week. First, find out what your verification vendor retains after a check passes — the answer should be a yes/no and a timestamp, not an image. Second, check your contract for a retention limit and a deletion SLA with a number in it. Most don't have one. Third, ask whether you actually need verification at all, or whether you copied it from a competitor.

The cheapest PII to protect is PII you never stored.

Key takeaways

  • IDScan.net confirmed a breach affecting a database tied to 150M+ people in the US and Canada
  • Stolen data includes names, license numbers, passport numbers, and license photos — none of which can be rotated
  • The dark web site Nexus claimed ~500,000 new documents added daily, suggesting sustained access rather than a single dump
  • The FBI is investigating; IDScan says it will notify affected individuals
  • Outsourcing verification moves your PII exposure to a vendor — it does not remove it, and your customers will still call you
  • Audit vendor retention: a passing check should leave a boolean and a timestamp, not a stored image

The best breach response is a smaller data footprint. We design intake and verification flows that keep identifiers out of your systems entirely — pass/fail results, short retention, and no images sitting in a bucket you forgot about. See how we handle sensitive data, or send us the flow you're worried about.

Sources: TechCrunch (Sept 10), TechCrunch (Sept 2).

  • #data-breach
  • #identity-verification
  • #vendor-risk
  • #pii
  • #compliance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.