$ techbeacon▋
Breaches

IDScan admits breach as hackers market millions of driver‑license scans

IDScan admits breach as hackers market millions of driver‑license scans

IDScan, a provider of identity‑verification services, confirmed that it suffered a data breach after a cyber‑crime forum listed more than 150 million driver’s‑license scans for sale.

The company’s acknowledgment came in a brief notice dated Sept. 4, which was not widely circulated. The filing simply stated that an unauthorized intrusion had occurred and that a “potentially large” amount of personal data may have been accessed, but it stopped short of giving a specific figure for the individuals impacted.

IDScan’s platform is used by banks, retailers and government agencies to confirm the identity of customers in real time. The service collects high‑resolution images of driver’s licenses, along with associated personal details such as name, address, date of birth and the alphanumeric barcode that encodes the document’s data. When that information is compromised, it can be repurposed for synthetic‑identity fraud, account takeover and other illicit activities.

The appearance of the data on a darknet marketplace mirrors a wave of recent incidents in which large volumes of government‑issued IDs have been stolen and offered for purchase. In 2023, a similar breach at a different verification vendor exposed tens of millions of scans, prompting heightened scrutiny from both regulators and industry watchdogs. The price tag attached to the IDScan dump—roughly $150 per million records—reflects the high demand for authentic‑looking identification in the underground economy.

Federal and state authorities are likely to investigate whether IDScan complied with breach‑notification statutes, which generally require timely disclosure to affected individuals and to regulators. The company’s limited communication so far may draw criticism from consumer‑advocacy groups that argue transparency is essential for people to take protective measures such as credit freezes or identity‑theft alerts.

For consumers who may have submitted a driver’s‑license image to IDScan, experts advise monitoring credit reports, placing fraud alerts, and reviewing any unexpected account activity. While the exact scope of the breach remains unclear, the incident underscores the growing risk associated with digital identity verification tools that rely on scanned government documents.

IDScan has not announced a timeline for a full forensic analysis or for any remedial steps such as password resets, system hardening or compensation for affected users. The unfolding situation will likely prompt a broader conversation about how companies that handle sensitive identification data balance operational efficiency with the need for robust cybersecurity safeguards.

Source: The Record
Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related