IDScan.net Leaked 153 Million Driver License Scans for 13 Months via Unsecured Feed
A single identity verifier's unsecured endpoint exposed 153 million U.S. and Canadian driver's licenses over 13 months. The incident directly contradicts the company's public security and compliance claims while it lobbied for expanded verification mandates. Operational consequence is permanent loss of control over primary identity documents for millions.
The breach originated at IDScan.net, a Louisiana firm contracted by Hertz, FedEx, Target, cannabis dispensaries, and age-verification platforms. An exposed endpoint streamed every scanned ID to an attacker-controlled service selling the images. FBI New Orleans opened an inquiry the day the feed went dark. Affected individuals matched dates of ID submission at multiple unrelated businesses, confirming the verifier as the single point of failure.
KrebsOnSecurity documented the 153 million record count through direct access and victim interviews. IDScan.net's Trust Center page, still live post-breach, listed GDPR, CCPA, and SOC 2 attestations while the live feed operated. The same firm publicly supported state age-verification mandates and KOSA provisions that would expand its market. No evidence of encryption at rest or egress monitoring appears in the available logs.
Prior incidents at Onfido, Jumio, and CLEAR showed identical patterns: central collection of high-resolution IDs without effective segmentation. Each breach scaled with regulatory pressure for verification, not with security investment. IDScan.net's exposure demonstrates that compliance checkboxes do not constrain data flow once collection volume exceeds operational controls.
Regulators face a binary choice: mandate collection and accept systemic leakage, or shift to zero-knowledge proofs and decentralized attestations. Existing contracts with state DMVs and federal contractors will require immediate termination clauses and forensic audits within 90 days.
KrebsOnSecurity: 50+ additional class-action filings naming IDScan.net customers within 120 days.
Sources (3)
- [1]KrebsOnSecurity(https://krebsonsecurity.com/2024/09/identity-theft-service-sells-153-million-drivers-license-images/)
- [2]TechDirt(https://www.techdirt.com/2024/09/03/hackers-had-a-live-feed-of-every-id-this-verification-company-scanned-for-over-a-year/)
- [3]Eric Goldman age verification analysis(https://blog.ericgoldman.org/archives/2023/age-verification-privacy-risks.htm)