IDScan.net Breach Exposes 153M Identity Scans
An apparent breach of IDScan.net exposed more than 153 million U.S. and Canadian driver’s-license scans through the Nexus dark-web service. The FBI is investigating after researchers found timestamps matching scans made at Hertz, Planet13, and other businesses.
This is a catastrophic failure for identity verification—and a warning that outsourcing sensitive checks simply concentrates risk in one opaque vendor.
- –Attackers reportedly maintained a live exfiltration pipeline for over a year, adding nearly 400,000 records in 24 hours.
- –Exposed files could include front, back, infrared, and ultraviolet license images, making identity theft and document forgery substantially easier.
- –IDScan.net’s customers reportedly span car rentals, dispensaries, finance, logistics, and age-verification workflows, multiplying downstream exposure.
- –Developers integrating ID verification APIs should demand strict retention limits, tenant isolation, immutable audit logs, anomaly detection, and independent breach monitoring.
- –The incident undermines claims that mandatory online age verification can be privacy-safe when third-party vendors retain high-resolution identity documents.
DISCOVERED
1h ago
2026-09-04
PUBLISHED
3h ago
2026-09-04
RELEVANCE
AUTHOR
beardyw