HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Breach

IDScan.net Confirms Massive Data Breach Exposing Over 153 Million Driver Licenses

IDScan.net disclosed that an outside party accessed more than 153 million driver‑license records stored in its cloud platform. The breach highlights the need for continuous vendor oversight and auditable access‑control evidence to satisfy governance and risk frameworks.

Verisq™ Intelligence · 📅 September 12, 2026 · 📰 databreachtoday.com
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
5 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

IDScan.net Confirms Massive Data Breach Exposing Over 153 Million Driver Licenses

What Happened — IDScan.net, a Louisiana‑based identity‑verification SaaS provider, disclosed that an unauthorized party accessed or copied records stored in its cloud platform. The breach is believed to involve more than 153 million driver‑license records and additional government‑issued IDs from the United States and Canada. The FBI has opened an investigation into the alleged sale of the data on the dark web.

Why It Matters for Trust & Control Assurance

  • This incident illustrates the risk of insufficient access‑control and monitoring over third‑party cloud environments – a core control objective for any continuous‑control‑assurance program.
  • Demonstrating documented vendor oversight (e.g., periodic security assessments, real‑time access‑log review) provides the defensible evidence auditors expect under NIST CSF 2.0 governance and risk categories.
  • A robust third‑party risk framework helps organizations prove due diligence when a supplier’s breach could cascade to their own compliance posture.

Who Is Affected – Banking and fintech firms, casinos and gaming operators, schools and universities, freight carriers, and law‑enforcement agencies that rely on IDScan.net’s verification APIs.

Recommended Actions

  • Review and tighten contractual security clauses with IDScan.net, emphasizing continuous monitoring and breach‑notification obligations.
  • Conduct an immediate audit of any internal processes that ingest IDScan.net data; verify that access logs are being retained and reviewed.
  • Activate incident‑response playbooks for identity‑theft scenarios, including credit‑monitoring enrollment for affected individuals.

Source: DataBreachToday

Technical Notes

  • Attack vector: unknown – the breach notice does not disclose how the intruder gained access.
  • Data types exposed: full names, driver‑license numbers, and potentially scanned images of government‑issued IDs.

Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/id-verification-firm-idscannet-confirms-data-breach-a-32804

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →