Your ID Verification Vendor Just Lost 153 Million Driver's Licenses. Here's What That Means If You're the One Scanning Customer IDs. — security

Your ID Verification Vendor Just Lost 153 Million Driver's Licenses. Here's What That Means If You're the One Scanning Customer IDs.

IDScan.net confirmed a breach of 150+ million driver's licenses on September 10, 2026. If your shop checks IDs for age, rentals, or dispensary compliance through a third-party vendor, this is the audit to run this week.

Note: Security researcher Brian Krebs first flagged this on August 31–September 1, 2026, when his own driver’s license turned up as a free sample on a Russian cybercrime forum. IDScan.net formally confirmed the breach on September 10, 2026 — the same day this piece was written. This is current news, not a recap; the confirmation is hours old as of publishing, and most affected businesses and consumers haven’t heard about it yet.

If your shop scans a customer’s driver’s license for anything — checking age at the counter, verifying a renter, onboarding a dispensary customer, running background checks on tenants — you’ve probably never thought hard about where that scan actually goes after the screen says “verified.” For a lot of small operators, the honest answer is: into a cloud database run by a company you’ve never heard of, using software licensed through whatever POS or age-gate app you bought. That database just turned up for sale on the dark web, 153 million records deep, and the company that ran it didn’t notice until an outside researcher found his own license in it.

This isn’t a story about a hospital chain or a bank. It’s a story about the identity-verification layer that a huge number of small businesses — bars, vape shops, cannabis dispensaries, car rental counters, delivery services, anyone required by law to check ID — plug into without ever seeing the plumbing behind it. That’s exactly the kind of vendor dependency this site keeps coming back to: the software you didn’t build, running on infrastructure you don’t control, holding data you’re legally responsible for.

What actually happened

The identity-verification company IDScan.net confirmed on September 10, 2026 that hackers stole a large trove of scanned identity documents from its cloud systems. The company says it “received information” about the claimed breach around September 1 and has been investigating since, notifying affected individuals and offering credit monitoring.

The discovery didn’t come from IDScan’s own monitoring. It came from Brian Krebs, the security journalist behind Krebs on Security, who was alerted on August 31, 2026 when his own Virginia driver’s license showed up as a free sample on Exploit, a Russian-language cybercrime forum. That sample was bait for a new dark-web storefront called Nexus, which launched offering a searchable database of stolen identity documents — roughly 11.5 million pages of results, about 15 records per page, with photo previews available before purchase. Security researcher Zach Edwards traced the data back to IDScan.net after finding his own license in the set, complete with timestamps matching a trip to DEFCON in Las Vegas where he’d visited a cannabis dispensary — a detail that shows exactly how granular and personally traceable this data is.

The FBI’s New Orleans field office opened a formal investigation on September 1, 2026. The seller behind Nexus claimed in forum posts to have “been continuously exfiltrating new data for over a year” before going public — meaning the exposure window, if the claim is accurate, is much longer than the week or two of headlines suggests.

IDScan.net’s own account, laid out in a security notice dated September 4, 2026, is notably more hedged than the researcher findings. The company says it learned “on or around September 1” that certain data “may have” been accessed without authorization, and that “upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident.” As of this writing, the company still hasn’t confirmed exactly how the intrusion happened, hasn’t matched Krebs’s and Edwards’s 153-million-record estimate with a number of its own, and hasn’t said whether the “over a year” exfiltration claim checks out against its own logs. That gap between “researchers found the data for sale” and “vendor confirms scope” is itself a pattern worth remembering the next time any vendor tells you a breach is “limited” or “contained” within days of discovery — full scope takes weeks, sometimes longer, and initial vendor statements are written by legal and PR teams before the forensic work is done, not after.

The legal fallout moved fast. Four class-action lawsuits were filed against IDScan.net on September 2, 2026 in the U.S. District Court for the Eastern District of Louisiana; by September 8, that number had grown to nine separate suits docketed in less than a week. Named businesses tied to the exposure in court filings and reporting include Planet 13, a large multi-state cannabis dispensary chain, alongside the previously reported Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment relationships. None of that litigation changes what a small operator needs to do this week, but it’s a useful signal: when a backend vendor gets hit this hard, its engineering and support attention shifts toward outside counsel and forensic firms for months, not toward answering a four-location vape shop’s retention questions. Ask now, while support can still spare the time.

DetailValue
CompanyIDScan.net (Louisiana-based ID verification vendor)
Records exposed153+ million U.S. and Canadian driver’s licenses, plus 10M+ ID cards, 3M+ passports/travel documents, 579,000+ medical/dispensary cards
Data typesFull names, license/ID numbers, front-and-back document images, infrared and ultraviolet scans, photos
DiscoveredAugust 31–September 1, 2026 (via researcher, not vendor monitoring)
Confirmed by vendorSeptember 10, 2026
InvestigatingFBI, New Orleans field office
Vendor’s responseNotifying affected individuals, offering credit protection
Alleged exfiltration window”Over a year,” per the seller’s own claim (unverified)

IDScan.net isn’t a fringe operator. It processes over 21 million identity verifications a month across more than 20,000 locations worldwide, and its customer list includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry (a major financial-services software provider), and Caesars Entertainment, plus over 1,000 cannabis dispensaries across 19 states. If you’ve had your ID scanned — not just glanced at, but run through a machine that photographs both sides under infrared and UV light — at a rental counter, a casino, a dispensary, or a large venue in the last several years, there’s a real chance it went through this company’s systems at some point, directly or through a reseller.

Why full-document scans are a different animal than a password leak

Every operator has some instinct for “we had a data breach” by now, mostly shaped by password and credit-card leaks. Driver’s license scans are a meaningfully worse category of exposure, for reasons worth spelling out plainly:

  • You can’t rotate a driver’s license the way you rotate a password. A compromised password gets changed in thirty seconds. A driver’s license number, once exposed alongside a face photo and full name, stays valid identifying information until the physical card itself is reissued — which most states only do on request, at a fee, with paperwork.
  • The images themselves are the valuable part, not just the numbers. IDScan’s technology captures front-and-back photos plus infrared and ultraviolet scans — the same layers used to detect fake IDs. In the wrong hands, those scans are a template for producing convincing forgeries, not just a record to commit fraud with directly.
  • It cross-references with sensitive context. Security researcher Larry Baldwin flagged a specific, serious risk: a searchable database of driver’s licenses tied to visit timestamps and locations “could dangerously expose people fleeing domestic violence or in federal witness protection” — categories of people for whom a public record of “here’s their current legal address and what they look like” isn’t a fraud risk, it’s a physical safety risk.
  • It implicates people who never chose to interact with the vendor at all. Zach Edwards put the structural problem simply: “These systems are putting sensitive data into more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.” Your customer agreed to show ID at your counter. They didn’t agree to have that document’s raw image sitting in a cloud database run by a company three steps removed from your business that they’ve never heard of.

The part that applies directly to you: you probably don’t run this vendor, you just use it

Here’s the uncomfortable structural point this breach makes visible: almost no small business builds its own ID-verification pipeline. You buy or subscribe to a system — an age-gate kiosk, a POS plugin, a rental-counter scanner, a background-check integration — and that system quietly routes the actual document image through a backend vendor like IDScan.net, or one of its handful of competitors, that you’ve likely never separately vetted. Your compliance obligation (checking ID, verifying age, screening a renter) got satisfied. Your vendor-security obligation, in most small shops, never got asked about at all.

That gap matters more every year, not less, because the regulatory trend is pushing more businesses into exactly this kind of vendor relationship. States have been rolling out age-verification requirements for online adult content, social media access for minors, and alcohol delivery apps — each one typically satisfied by bolting on a third-party ID-verification API rather than building in-house checks. The addressable surface for “a business that outsources ID verification to a vendor it’s never audited” is growing, not shrinking, at the same time this breach is showing exactly what can go wrong on the vendor side.

A worked example: the four-location vape shop chain

Take a small chain with four retail locations, using a POS system that includes an “ID scan for age verification” add-on the owner turned on three years ago because it was faster than eyeballing birthdates and satisfied a state compliance requirement. The owner has never asked, and the POS vendor’s sales rep never volunteered, which backend company actually processes and stores those scans, how long the images are retained, or what happens to that data if the backend vendor gets breached.

Here’s the honest audit that shop needs to run this week, and it’s the same audit that applies to a dispensary, a car rental counter, a bar carding at the door with a scanner instead of eyes, or a property manager screening applicants:

  1. Find out which backend vendor actually processes your scans. Ask your POS or age-gate provider directly — “who is your identity-verification subprocessor” is a normal, answerable vendor question, not an unusual one.

  2. Ask how long scans are retained, and where. A verification event only needs a yes/no answer and maybe an audit-trail flag (“verified, over 21, timestamp X”). It does not need the full front-and-back image kept indefinitely in a searchable database. If your vendor retains full images by default, ask why, and ask whether that’s configurable.

  3. Check your contract’s breach-notification clause. Most vendor agreements for compliance software include (or should include) a clause requiring the vendor to notify you within a defined window if their systems — or their own subprocessors’ systems — are breached. If yours doesn’t have this, or you don’t know, that’s a gap to close before you need it, not after.

  4. Ask about scan-and-discard versus scan-and-store as a configuration option. Some verification providers support confirming an ID is valid and the person meets an age threshold without retaining the raw document image afterward. That’s a meaningfully smaller blast radius if the vendor ever gets breached, and it’s often available as a setting, not a separate product.

  5. Tell your customers something true if you’re asked. If a customer asks “what happens to my ID after you scan it,” most staff currently can’t answer beyond “it just checks it.” Knowing your own vendor’s actual retention practice, even briefly, is a real trust signal in a week when this is in the news.

  6. Ask how many layers of reseller sit between you and the actual processor. A lot of small-shop compliance software is sold by a POS or app vendor that itself licenses the verification engine from a company like IDScan.net, which may in turn route through a regional integrator. Each layer is a company that touched your customer’s document and that you’ve never separately vetted. You don’t need to audit all of them yourself — but you do need your direct vendor’s contract to make them responsible for flowing breach notification and security requirements down the chain, in writing, not as an assumption.

This vendor audit is a different exercise from — and doesn’t replace — the baseline data hygiene (MFA on every account, patched systems, tested backups) covered in the small-business data security checklist. That checklist handles the systems you control directly; this one handles the ones you don’t, which is exactly the gap this breach exposes.

A second worked example: what happens when the same customer gets hit twice

Hertz is a useful case study here precisely because it’s a large company with a real vendor-security program, and it still got caught in this breach — as a customer of IDScan.net’s rental-counter verification, not as the operator of the system. And this isn’t Hertz’s first vendor-caused exposure. In October and December 2024, the Cl0p ransomware group breached Cleo Communications, a file-transfer vendor Hertz used for a different purpose entirely, exposing driver’s license numbers, payment card data, and in some cases Social Security numbers for tens of thousands of Hertz customers — a breach the company didn’t publicly disclose until April 2025. Fourteen months later, a second vendor two layers removed from Hertz’s own systems is the source of another exposure involving the same customers’ driver’s license data.

The lesson for a small operator isn’t “even Hertz can’t get this right, so why bother.” It’s the opposite: Hertz has legal, security, and vendor-management staff whose job is specifically to catch this kind of exposure, and it still happened twice in just over a year through two unrelated vendors. A four-person shop with no dedicated IT person and a POS add-on it enabled once and never revisited has dramatically less visibility into its vendor stack than Hertz does — which means the five-question audit above isn’t a one-time task you check off this week and forget. It’s worth re-asking “who processes our scans, and how long do they keep them” roughly once a year, the same cadence you’d use for renewing insurance or reviewing a lease, because the vendor behind your POS add-on can change (through an acquisition, a backend migration, or a new subprocessor) without your contract or your day-to-day experience visibly changing at all.

Comparing your actual options for ID checks

ApproachWhat it collectsBreach exposure if vendor is compromisedBest fit
Visual check only (staff looks at physical ID)Nothing storedNone — no digital record existsLow-volume counters, staff trained and consistent
Scan-and-discard (verify, don’t retain image)Pass/fail result + minimal metadata (age flag, timestamp)Low — no document image to steal even if the vendor is breachedMost small shops with a legal verification requirement
Scan-and-store (full image + IR/UV retained)Full document image, infrared/UV scan, name, ID numberHigh — exactly the category exposed in the IDScan breachOnly where retention is a specific legal/compliance requirement (some financial services, some age-restricted goods) — verify it’s actually required, don’t assume
In-house verification system (no third-party vendor)Whatever you choose to collect and storeDepends entirely on your own security practicesLarger operators with dedicated IT; rarely worth building for a small shop

The middle row is the one most small operators should actually be asking their vendor about switching to, if they’re not already there. It satisfies the same legal requirement — confirming someone is who their ID says they are and old enough for whatever’s being sold or rented — without keeping a permanent, breachable copy of the document that made the check possible.

When this genuinely isn’t your problem

If you check ID visually, with staff eyes, and nothing gets scanned or stored anywhere — this breach doesn’t touch you directly, and there’s no vendor audit to run. Keep doing what you’re doing; the friction of training staff to actually check birthdates carefully is a real cost, but it comes with zero digital breach surface.

If you already know your verification vendor uses scan-and-discard and you’ve confirmed it contractually — this is exactly the setup that minimizes your exposure to a breach like this one, and you’re in reasonable shape. Worth re-confirming the contract language once, not urgently re-architecting anything.

If you’re a consumer wondering whether your own license was in this breach rather than a business owner running a shop — the practical steps are different: watch for unfamiliar credit inquiries, consider a credit freeze, and be skeptical of anyone contacting you referencing your license details, since those details are now plausibly in criminal hands regardless of what you personally did. That’s a real concern, but it’s a different action list than the vendor-audit one this piece focuses on for operators.

Bottom line

IDScan.net isn’t a company most small business owners have heard of, which is exactly the point — its role is invisible by design, tucked inside whatever POS add-on or age-gate app actually asked your customer to scan their license. This breach didn’t happen because a small shop did something wrong. It happened three layers up the vendor stack, and it’s now every downstream business’s problem to sort out, the same pattern this site has flagged before with Magento’s supply-chain compromises and with taking any vendor’s security claims at face value instead of verifying them. The fix here isn’t dramatic — it’s a five-question vendor audit that takes less than an hour, and a genuine push toward scan-and-discard instead of scan-and-store wherever your compliance requirement allows it. Do that this week, while the news is fresh enough that your vendor’s support line is actually primed to answer these questions honestly.

Sources

All facts accessed September 10, 2026.

[read next]
ai agents · sep 13
Anthropic's CEO Says an AI Swarm Could Take Over the Internet Within a Year. Here's the Boring Version of That Problem You Actually Have Today.
hardware · sep 13
700 AI Agents Coordinated a Hack Without Anyone Noticing Until After. The $289 Box That Would Have Caught It Sooner.