IDScan Confirms Data Breach Exposing Government ID Scans
IDScan, an identity-verification vendor whose scanning technology is used by cannabis retailers, gun stores, banks, and other age- and identity-restricted businesses, has confirmed a data breach after a large cache of stolen identity document scans appeared for sale on a dark web marketplace.
What Happened
According to a breach notice dated September 4 but not widely publicized, IDScan acknowledged that an unauthorized third party accessed its cloud platform and copied customer identity-verification data. The company did not disclose the specific attack method used to gain access, and its notice did not specify how many individuals were affected — leaving that count to be pieced together from the stolen data itself.
Scale of the Exposure
The data offered for sale, first identified and reported by security journalist Brian Krebs, includes:
- 153 million driver's license scans (U.S. and Canadian citizens)
- 10 million identification card scans
- 3+ million travel documents and international IDs
- 579,000+ medical cards
- Full names and government-issued ID numbers tied to the scanned documents
Discovery
The breach came to light after Krebs identified the stolen dataset being marketed on Nexus, a Russia-linked dark web marketplace. Krebs authenticated the offering by locating his own scanned records among the samples provided by the seller — a strong indicator that the dataset is genuine rather than a recycled or fabricated listing.
IDScan's Response
IDScan's public response has drawn criticism for its limited visibility. The company:
- Acknowledged the incident but downplayed its severity, noting the data was not "freely distributed"
- Applied search-engine indexing blocks to its breach notice, reducing its public discoverability
- Offered affected individuals free credit monitoring and identity-protection services
The FBI has opened an inquiry into the incident, and multiple lawsuits have reportedly already been filed against the company.
Why This Matters
Identity-verification platforms like IDScan sit at a uniquely sensitive point in the data supply chain: they exist specifically to collect and retain scans of government-issued identity documents on behalf of downstream businesses that never intended to store that data themselves. A breach at this layer doesn't just expose one company's customers — it exposes the customers of every business that relied on IDScan's scanning kiosks and verification services, likely without those individuals ever knowing IDScan held their data at all.
With full names, government ID numbers, and document images now circulating on a criminal marketplace, affected individuals face elevated risk of identity theft, synthetic identity fraud, and document forgery using their real personal details as a template.
Recommendations
For Individuals Who May Be Affected
- Request your free credit monitoring if offered by IDScan or a business that used its verification services
- Place a credit freeze with major credit bureaus to prevent new accounts being opened in your name
- Watch for account-opening or loan notifications that you didn't initiate
- Be alert to targeted phishing that references accurate personal details pulled from the leaked scans
For Businesses Using Third-Party Identity Verification
- Audit data retention practices with identity-verification vendors — confirm whether scanned documents are retained or purged after verification
- Review vendor breach-notification contracts to ensure timely, complete disclosure obligations
- Minimize the identity data collected to only what is legally required
- Evaluate vendors' security posture before entrusting them with government ID scans
Sources: The Record, Krebs on Security