Third-Party Risk

IDScan breach: the hidden risk in outsourced ID checks

Praeferre ResearchPraeferre Insights Team
Published
Read time5 min read
Third-Party Risk

In early September 2026 identity verification provider IDScan.net confirmed a breach of customer data held on its cloud platform. Reporting by Krebs on Security, TechCrunch and Help Net Security links it to a criminal marketplace advertising more than 150 million scanned US and Canadian driver’s licences, collected over more than a year. The people affected never chose IDScan. They simply showed their ID at a counter. That is exactly why this is a third-party risk story every organisation should study.

What happened

Krebs on Security reported on 1 September that a dark web service called Nexus was advertising access to more than 153 million US and Canadian driver’s licences, more than 10 million ID cards, over 3 million travel documents and more than 579,000 medical cards. Krebs traced the data to IDScan.net, whose technology is used to verify identity documents at car rental desks, retailers, hotels and cannabis dispensaries, and reported that data appeared to have been taken continuously for more than a year.

IDScan stated that on or around 1 September it received information indicating that certain data may have been accessed without authorisation, according to Help Net Security, which reports that the company engaged security specialists and offered affected people credit monitoring and identity protection. TechCrunch reports that the stolen data includes names, licence numbers, identity numbers from passports and other documents, and licence photos, and that the FBI is investigating. Reported figures vary between sources, and a final count of affected individuals had not been confirmed at the time of writing.

Key points
Supplier
IDScan.net, an identity document verification provider.
Scale
More than 150 million driver’s licence records advertised, plus other ID types.
Duration
Reported to span more than a year.
Who carries the risk
The businesses that used the service, and the individuals whose IDs were scanned.

Why identity vendors deserve your closest scrutiny

Identity verification is now routinely outsourced: age checks, right-to-work checks, know-your-customer onboarding, visitor management and fraud prevention. These suppliers often hold the most sensitive data an organisation ever touches, and they concentrate it across thousands of clients. That makes them a prime target.

Three uncomfortable lessons emerge:

  • Data you do not keep can still be your breach. A business that only needed to confirm someone’s age may have assumed the scan was transient. If its supplier retained full images, that business may still have regulatory and reputational exposure.
  • Long-running exfiltration signals weak monitoring. A theft spanning more than a year suggests detection controls that questionnaires rarely test.
  • Criminals notice concentration. A single supplier breach delivered data from many unrelated businesses at once.

Under the UK GDPR and EU GDPR, controllers must use only processors providing sufficient guarantees, and must apply data minimisation. Identity documents are high-risk data that can enable fraud and identity theft, so the bar for due diligence should be correspondingly high.

“The best way to protect an ID scan is not to keep it. The second best is to know exactly who does.”

— Praeferre analysis

What to do now

  1. Find your identity suppliers. List every vendor that captures, verifies or stores ID documents on your behalf, including in-store and on-site systems.
  2. Challenge retention. Ask what is stored, for how long and why. Where you only need a yes or no answer, such as age over 18, require that the supplier does not retain full document images.
  3. Tier by data sensitivity. Treat identity and biometric processors as critical suppliers, with deeper assessments, contractual audit rights and faster breach notification terms.
  4. Test detection, not just policy. Ask how the supplier would spot bulk exfiltration, and request evidence such as independent audit reports or penetration test summaries.
  5. Prepare your response. Decide in advance how you would notify affected customers and regulators if a supplier breach involved your data.

Praeferre’s Third-Party Risk Management platform helps you identify high-risk suppliers, run proportionate assessments and monitor them continuously. Our DPO as a Service team can review processor contracts and data minimisation for identity checks.

Identify your highest-risk suppliers and keep watch on them continuously.

Explore TPRM

Common questions

IDScan.net confirmed that data on its cloud platform was accessed without authorisation. Reporting links the breach to a criminal marketplace advertising more than 150 million scanned US and Canadian driver’s licences, collected over more than a year.

The reported data relates to US and Canadian documents. The lessons apply to any organisation that outsources identity checks, including UK age verification, right-to-work and customer onboarding.

Ask what data they retain and for how long, whether full document images are stored, how they detect bulk data theft, what independent assurance they hold, and how quickly they will notify you of a breach.

Sources

  1. FBI Probes Service Selling 153M+ Drivers Licenses — Krebs on Security, 1 September 2026
  2. ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen — TechCrunch, 10 September 2026
  3. IDScan confirms breach after 153 million driver’s licenses leak on dark web — Help Net Security, 11 September 2026