IDScan Alleged Data Breach Exposes 153 Million Driver’s Licenses
What Happened – Hackers accessed IDScan’s identity‑verification platform and posted more than 153 million U.S. and Canadian driver‑license scans, 10 million ID cards, 3 million travel documents, and hundreds of thousands of medical cards on a dark‑web marketplace. The leak was first reported by Brian Krebs and is now the subject of multiple lawsuits and a federal investigation.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of relying on a single third‑party for large‑scale personal‑identification data without continuous oversight.
- Highlights the need for documented vendor‑risk assessments, ongoing security‑control monitoring, and a defensible audit trail of due‑diligence.
- Shows how a breach of a vendor can cascade to many downstream businesses (car rentals, retailers, financial institutions, etc.), triggering regulatory and litigation exposure.
Who Is Affected – Car‑rental firms, retailers, gun shops, financial institutions, cannabis dispensaries, hospitality operators, and any organization that uses IDScan’s scanning solution.
Recommended Actions
- Review and update your third‑party risk management program to include continuous monitoring of vendor security controls.
- Collect and retain evidence of IDScan’s security posture (SOC reports, penetration‑test results, data‑handling policies).
- Incorporate vendor‑access logs into your security‑information‑event‑management (SIEM) for real‑time anomaly detection.
- Align incident‑response playbooks to cover data‑exfiltration scenarios originating from a supplier breach.
Source: BleepingComputer
Technical Notes – The breach appears to be a credential‑theft or insider‑type exposure; the exact attack vector has not been disclosed. Stolen scans were sold on a dark‑web service (“Nexus”) that is now offline, but the data remains accessible to cybercriminals. No specific CVE or software flaw has been identified.