Product1 publisher2 min readPublished
IDScan.net's breach notice puts 153 million licenses in cloud accounts it kept after the check
IDScan.net says an unauthorized third party may have accessed or copied full names and government-issued ID numbers from customer accounts on its cloud, after 153 million driver's licenses appeared for sale on a dark web site.
The Product Desk · Product desk

What happened
- A dark web site was selling access to millions of US and Canadian driver's licenses, more than 153 million records in total, and that site now appears to have been taken down.
- IDScan.net quietly posted a "Notification of Data Security Incident" dated Sept. 4 saying it is investigating a possible breach; cybersecurity journalist Brian Krebs found it on the company's own website.
- IDScan sells identity card and passport verification to clients including Hertz, FedEx and GameStop, and the consumers whose IDs it held were likely unaware of it, according to PCMag.
- The notification page is absent from major search results because IDScan added code to the site that stops web crawlers from indexing it.
- Court records show more than a dozen US class actions against IDScan, up from four a week earlier, and the FBI told PCMag it has been investigating the potential breach.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure The people whose license numbers are in circulation never signed anything with IDScan. They handed a license to a clerk at a company that had bought the check.
- decision Anyone renewing an ID-verification contract now has to settle what the vendor keeps after it returns a pass or fail, because this notice locates the data in per-customer accounts on the vendor's cloud.
- constraint With the page hidden from crawlers, an affected driver who goes looking will not find the notice, so word reaches them only if IDScan or one of its clients makes contact directly.
- cost Credit monitoring is the cheap line on IDScan's bill. The litigation is the compounding one, having at least tripled in the space of a week.
Hand a license across a rental counter and the service you bought is a check: is the document real, is it yours. IDScan.net's notice describes what sat behind that check. An unauthorized third party "may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud," the notice says [5]. Those accounts belong to IDScan's business customers. The records were still in them.
A verification service can answer pass or fail and keep nothing after it answers. This one held full names and government-issued identification numbers in per-customer cloud accounts, on the evidence of its own notice [5][6]. That is a product decision, and it is the one an operator can inspect before signing.
The public record does not show why the records were there. The notice gives no retention period and does not say whether keeping the data was a client setting or a vendor default [4][5].
A notice that crawlers cannot index reaches only people who already know the vendor's name, and most people who scanned an ID at a store counter never learned it [10]. Brian Krebs, the cybersecurity journalist who first reported the dark web site selling access to millions of US and Canadian licenses, found the notice himself [2][3]. IDScan says it is giving affected users free credit monitoring and identity protection, and urging them to be vigilant against phishing and fraud [9].
Four class actions a week ago, more than a dozen now: at least eight new filings in seven days, better than one a day [11][15].
For anyone renewing an identity-verification contract, the useful exercise is two columns per vendor. What it returns to you, and what it holds after it returns it. Then two questions about the second column. Can your team delete those records without opening a support ticket, and does the default keep or discard?
Four cases fall out. Discard by default with self-serve deletion is the one to buy. Keep by default with self-serve deletion is a configuration job you can finish this week. Discard by default with deletion only through the vendor needs a written confirmation and a date on it. Keep by default with vendor-controlled deletion means you answer for records you cannot reach, and the customer who scanned the ID will call your store, not the vendor's office.
IDScan, based in Louisiana, has not responded to PCMag's requests for comment [14].
What to watch
- Whether IDScan.net states a retention period and says which client accounts held the affected records.
- Whether the FBI inquiry turns into a public enforcement action or stays an investigation.
- Whether Hertz, FedEx or GameStop notify their own customers directly instead of leaving it to the vendor's unindexed page.