Identity verification vendor IDScan.net confirmed on September 4 that an unauthorized third party accessed customer data stored in its cloud platform. In its own notice, the company said it became aware of the incident around September 1 and that the exposed data “may include full names and driver’s license or other government-issued identification numbers.” IDScan said full access to the stolen data required payment on the dark web market where it surfaced, and that it is offering free credit monitoring and identity protection to potentially affected individuals while working with federal law enforcement. The company’s notice did not state how many customers were affected.
That scale gap matters because independent security journalist Brian Krebs, who first tied the leaked data to IDScan by authenticating database samples, reported that a Russia-linked dark web marketplace called Nexus was selling access to more than 153 million driver’s license scans belonging to US and Canadian residents, alongside 10 million ID card scans, more than 3 million travel documents, and at least 579,000 medical cards, all pulled from the same breached database. IDScan.net’s own announcement was posted to its website with a directive telling search engines not to index it, a common but often criticized practice that keeps a public notice technically compliant while making it far harder for affected customers to find on their own.
The original insight here is about the customers IDScan never disclosed to directly. Businesses across cannabis retail, gun sales, banking and other age- and identity-restricted industries feed IDScan raw government ID scans to verify customers, which means the actual blast radius of this breach runs through hundreds of downstream businesses that have no visibility into IDScan’s security practices and no seat at the table in its incident response, only a vendor relationship they now have to explain to their own customers.
Source: IDScan.net
Related: Grindr Pays 26 Million Pounds Over Old HIV Data Leak and A Shipping Vendor Kept Data Trezor Thought Was Gone.