153 Million Driver's Licenses Leaked in IDScan.net Data Breach
A breach at ID-verification vendor IDScan.net exposed 153 million driver's licenses. The same outsourced KYC risk applies to Indian banks and fintechs.
A marketplace called Nexus, on the dark web (the part of the internet that isn't indexed by search engines and is commonly used to trade stolen data), started selling scanned copies of more than 153 million driver's licenses this month, along with 10 million other ID cards, 3 million passports and travel documents, and nearly 580,000 medical cards. None of the people whose faces and addresses are sitting in that database ever chose to hand their ID to whoever is selling it.
How a background-check company became a single point of failure
The trail leads back to IDScan.net, a Louisiana-based firm most people have never heard of. It doesn't sell anything to consumers directly — it sells ID-scanning software to car rental counters, retailers, and cannabis dispensaries, the kind of businesses that need to verify you are who your license says you are before handing over a car key or a product. Security journalist Brian Krebs first spotted the listing on the dark web marketplace and confirmed it was real by checking whether his own scanned documents, and those of people who volunteered to be tested, showed up in the trove. They did.
IDScan.net posted a notice on its site on September 4th acknowledging that around September 1st, it had detected unauthorized access to its systems. The FBI's New Orleans field office has opened an investigation. What makes this breach worse than a typical password leak is the nature of what's exposed: a driver's license scan isn't something you can reset. Once your license photo, signature, date of birth, and home address are on a criminal marketplace, they stay useful to fraudsters for the rest of your life.
Every time a business outsources "check this person's ID" to a third party, it adds one more company that can leak your identity — one you never chose, never signed up with, and have no relationship with to demand accountability from.
What actually leaked
Based on reporting so far, the exposed dataset reportedly includes:
- 153 million+ scanned driver's licenses from the US and Canada
- 10 million other government-issued ID cards
- 3 million passports and travel documents
- Roughly 579,000 medical ID cards
That combination is a near-complete identity kit — enough to open bank accounts, apply for credit, or pass many "verify your identity" checks that companies use precisely because they assume a scanned ID is hard to fake.
Why this should worry Indian readers too, not just Americans
It's tempting to read this as a US problem, since IDScan.net's customers are American car rental chains and retailers. But the underlying pattern — outsourcing identity verification, or KYC (know-your-customer) checks, to third-party scanning vendors — is exactly how Indian banks, telecom operators, and fintech apps handle onboarding too. Every time you scan an Aadhaar card or PAN to open a bank account, activate a SIM, or sign up for a lending app, that image often passes through a vendor's servers before it reaches the company you actually trust. India's Digital Personal Data Protection (DPDP) Act, 2023 places obligations on the company that collects your data, but enforcement of how well their downstream vendors secure it is still maturing, and Aadhaar-linked identity documents carry even more weight than a US driver's license because they're tied to banking, mobile connections, and welfare benefits all at once. A breach at any of India's e-KYC or document-verification vendors would arguably be more damaging than this one.
This isn't the first time an ID-verification pipeline has turned into the weak link — Code24 covered a similar failure last year when Discord's age-verification vendor leaked 70,000 government IDs. The pattern keeps repeating because the incentive to outsource ID checks is strong and the incentive to secure them properly, for a company that never talks to the end user, is weak.
What you can actually do about it
There's no way to "opt out" of a breach that happened at a company you never dealt with. But a few things genuinely help:
- Set up a fraud or credit alert if you've rented a car, visited a dispensary, or done an age-gated purchase in the US recently — that's the population most likely affected here.
- In India, keep an eye on your Aadhaar's authentication history through UIDAI's portal, since unusual scan requests are one of the few visible signs of misuse.
- Treat any business that asks to "scan your ID" as handing your document to an unknown third party, not just the business in front of you — ask what vendor they use if it matters to you.
The uncomfortable truth is that identity verification has become infrastructure — quiet, outsourced, and rarely audited by the people whose documents flow through it. Every new "scan your ID to continue" prompt, whether at a rental counter in Ohio or a KYC screen in a Mumbai fintech app, adds one more link in a chain that's only as strong as its least careful vendor.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0