IDScan Breach Exposes 153 Million Driver’s License Scans via Unauthorized Cloud Access
What Happened — IDScan, an identity‑verification SaaS, confirmed that an unauthorized party accessed its cloud platform in early September 2026. The breach potentially exposed full names, driver’s‑license numbers and scanned images of more than 153 million U.S. and Canadian IDs.
Why It Matters for Trust & Control Assurance
- Unrestricted or poorly monitored privileged access to cloud‑hosted PII is a classic failure of an access‑control control objective that continuous‑control‑assurance programs are built to detect and evidence.
- Demonstrating real‑time logging, anomaly detection, and documented remediation provides the defensible audit trail required for frameworks such as NIST CSF 2.0.
Who Is Affected – Car‑rental firms, retailers, banks and other financial institutions, cannabis dispensaries, gun shops, and hospitality operators that rely on IDScan’s verification service.
Recommended Actions –
- Conduct an immediate IAM review of all cloud‑based services that store PII; enforce least‑privilege and MFA for privileged accounts.
- Deploy continuous monitoring of access logs and set up automated alerts for anomalous activity.
- Verify that third‑party oversight processes (e.g., vendor risk assessments, security‑by‑design contracts) are up‑to‑date and documented.
Technical Notes – The breach was discovered on September 1 2026; IDScan engaged third‑party investigators and took the platform offline. No specific vulnerability (CVE) was disclosed, and the exact attack vector remains unknown. Source: BleepingComputer