153 Million ID Scans for Sale: What the IDScan Breach Teaches About Identity Data

Headline 'Scanned Once, Stored Forever' beside a driver's license scan flowing into a cloud vault of identity cards, with a red warning icon and a '153M' count.

A driver's license scan is shown for a few seconds at a counter. Then it is scanned, stored, and, in at least one case, kept in a cloud account for much longer than the transaction needed.

In early September, identity-verification provider IDScan disclosed that an unauthorized third party "may have accessed and/or copied" customer information stored in accounts on its cloud platform. According to The Record and BleepingComputer, a dark web marketplace was offering what was described as 153 million driver's license scans, along with roughly 10 million ID cards, 3 million travel documents, and 579,000 medical cards.

IDScan has not confirmed those numbers, and its investigation was still ongoing at the time of reporting. But the pattern is familiar, and the lesson does not depend on the final count. The real question is not only how attackers got in. It is why so much identity data was sitting in one place to be taken.

What Has Been Reported So Far

The public facts are limited, and it is worth separating what the company said from what others have reported:

  • Timeline: IDScan says it learned of possible unauthorized access on or around September 1, 2026, and posted a security notice on September 4.
  • What IDScan confirmed: Full names and driver's license or other government-issued ID numbers may have been accessed or copied.
  • What others reported: Journalist Brian Krebs found his own records offered on Nexus, a Russia-linked marketplace, and the scale figures above come from that reporting. The notice itself was reportedly published with a search-engine blocking directive.
  • What is not known: The attack method has not been disclosed, nor has the number of affected customers. Reporting also does not say whether the stored images were encrypted.
  • Response: IDScan is offering free credit monitoring and identity protection, and the FBI has confirmed an inquiry. Multiple lawsuits have been filed.

IDScan's customers include car rental companies, retailers, financial institutions, cannabis dispensaries, gun shops, and hospitality businesses. Most of them never suffered an intrusion of their own. Their customers' data was exposed through a vendor.

Reporting on the IDScan notice also highlights a smaller point. The company's own statement said the investigation was ongoing and that the data "may" have been accessed. That is a normal and careful way to disclose an early-stage incident, and it is fair to give the company room to finish its work. For the businesses that rely on a platform like this, though, the practical takeaway comes sooner than any final report: decide now what you would need to know from a vendor, and how quickly, if the same notice arrived in your inbox tomorrow. Many organizations discover that they cannot say which of their customers' records a vendor holds, or for how long.

Verification Creates a Copy. Retention Creates a Target.

Checking an ID is a legitimate, often legally required, step. A scan taken to confirm age or identity serves its purpose in seconds. Whether the image needs to be kept afterward is a separate decision, and it is one that is easy to leave unmade.

When verification data accumulates across thousands of customer accounts, a platform becomes a concentration point. One successful intrusion reaches every customer at once. We described this dynamic in our article on the sensitive data supply chain: every copy of sensitive data is another place it can be lost, and copies held by vendors are the hardest to see.

Identity Documents Cannot Be Rotated

A leaked password can be reset. A leaked payment card can be reissued. A driver's license scan contains a name, a photo, a date of birth, a document number, and often an address. None of that changes because it was exposed. The scan can be used to impersonate someone long after the breach is forgotten.

That permanence is what makes this category of data different. Credit monitoring helps people detect misuse, but it does not make the exposed data safe again. Protection has to happen before the exposure, because afterward there is very little left to do.

Third-Party Platforms Inherit Your Risk

When an organization sends customer identity data to a vendor, the legal responsibility for that data usually stays with the organization. Its customers will not distinguish between the business they handed an ID to and the platform behind it.

That makes vendor design a data security question, not only a procurement one. If the vendor holds readable copies of ID images and numbers, then the vendor's security perimeter becomes the only thing between that data and an attacker. Perimeters fail. Account-level access controls on a cloud platform protect against the wrong user, not against someone who reaches the platform's own storage.

A Practical Framework for Identity Data

Organizations that collect or process ID documents can work through a short list:

  1. Collect only what the purpose needs. If a yes or no answer to an age check is enough, storing the full scan is not necessary.
  2. Set a retention limit and enforce it. Define how long images and ID numbers are kept, and verify that deletion actually happens, including at vendors.
  3. Tokenize or mask identifiers. Where systems only need to match or reference a record, a token can stand in for the real document number.
  4. Encrypt the data itself, with keys controlled separately. Encryption that is applied to the data and governed by identity-based policy limits what a platform compromise exposes.
  5. Monitor access to the data. Bulk reads of identity records should look different from routine lookups, and should be visible quickly.
  6. Ask vendors direct questions. How long do you retain scans? Are they encrypted? Who holds the keys? Can bulk export be detected?

None of this requires knowing in advance how an attacker will get in. That is the point. It is a plan for the day someone does.

OnData's Take

The IDScan reports are a reminder that identity data is among the most durable, and most reusable, information an organization can hold. Once copies are spread across vendor platforms, the security of that data depends on every environment it touches.

A data-centric approach starts with the data. OnData SecureFile discovers, classifies, and encrypts sensitive files, including scanned documents, with access governed by identity and need to know. OnData SecureDB applies the same persistent protection to structured records, including identifiers that can be masked or tokenized so the real values are only revealed to those authorized to see them.

Verification should confirm who someone is. It should not leave behind a permanent archive that anyone who breaks in can read.