IDScan Breach Exposes 153 Million Driver’s License Scans on Dark Web
What Happened — Hackers accessed the cloud‑hosted database of identity‑verification provider IDScan and posted more than 153 million driver’s‑license scans for sale on the Nexus dark‑web marketplace. The breach was disclosed by IDScan on Sept 4 after the company learned of the intrusion around Sept 1.
Why It Matters for Trust & Control Assurance
- The incident illustrates the exact scenario a continuous third‑party risk‑management program is built to detect, document, and remediate – an external service storing personally identifiable information is compromised.
- Ongoing vendor oversight, evidence‑based monitoring, and a defensible audit trail are required to prove due‑diligence to regulators and customers after a supply‑chain breach.
Who Is Affected — Financial institutions, cannabis retailers, firearms dealers, and any organization that relies on IDScan’s API for government‑ID verification.
Recommended Actions
- Map the breach to your vendor‑risk control objective (e.g., “Assess and monitor third‑party security posture”) and collect current due‑diligence artifacts.
- Initiate a formal review of IDScan’s security attestations, request recent audit evidence, and update contractual security clauses.
- Deploy continuous monitoring of third‑party cloud environments and log access to verification APIs.
Technical Notes — The breach was discovered via dark‑web activity; the exact attack vector (e.g., vulnerability exploit, credential theft) has not been disclosed. Exfiltrated data includes full names, driver’s‑license numbers, other government IDs, travel documents, and medical cards. Source: The Record