Severity Daily

IT and AI security incidents, checked against the primary source

Tag: identity verification

  • IDScan.net confirms unauthorized access to its cloud and names no number — every figure in circulation comes from the marketplace that sold the data

    IDScan.net confirms unauthorized access to its cloud and names no number — every figure in circulation comes from the marketplace that sold the data

    The company’s own notice confirms unauthorized access and gives no figure at all; the 153 million and 170 million numbers in circulation come from the criminal marketplace that offered the data, and from a researcher who searched it.

    What happened

    What changed, and when: IDScan.net published a notice titled “Notification of Data Security Incident,” dated September 4, 2026, confirming that customer data held in its cloud may have been accessed by an unauthorized party. Severity Daily is writing it up on September 10 because the confirmation is the primary-source event here, and because the numbers attached to it in wide circulation this week are not the company’s.

    The notice is short and hedged. It says that “on or around September 1, 2026, IDScan.net received information indicating that certain data may have been accessed without authorization,” and that the company determined “an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud.” The data “may include full names and driver’s license or other government-issued identification numbers.” IDScan says it “took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope,” and that it is “cooperating with federal law enforcement on their investigation.” It offers free credit monitoring and identity protection, and advises “potentially impacted individuals” to review credit reports and account statements.

    The notice names no number. Not a record count, not an individual count, not a per-state count. It does not say whether license images were included, and it does not name which of the company’s customers were affected.

    Where the numbers come from

    Every figure circulating this week originates outside the company.

    The largest set comes from the criminal marketplace itself. A dark-web service calling itself Nexus advertised a searchable database and claimed more than 153 million United States and Canadian driver’s licenses, more than 10 million identification cards, more than 3 million travel documents, and more than 579,000 medical cards. That is an attacker’s sales claim, and it should be read as one. The 170 million figure that has appeared in headlines is the sum of those claimed document classes, not a separate finding.

    The strongest independent evidence of scale is Brian Krebs’s own reporting, and it is a researcher’s count rather than a company disclosure. Krebs was alerted to the Nexus service on August 31, 2026, and reported that a blank search returned roughly 11.5 million pages at about 15 results per page. He wrote that he located his own license in the database along with those of nine friends and family members, with timestamps matching travel or car-rental dates. That is direct verification of the data’s authenticity and rough order of magnitude by someone who searched it. It is not an audited count, and Krebs does not present it as one.

    Krebs also reported that the FBI’s New Orleans field office opened an investigation, and that he took part in a call with bureau cyber-division staff on September 1, 2026. The Nexus site went offline on September 2, 2026 at 6:05 p.m.

    Two things the record does not agree on

    When the notice appeared. The page itself carries the date September 4, 2026. Krebs’s account has IDScan publishing the notice on September 8. We could not resolve which is the publication date and which is the drafting date, and the page does not carry a revision history.

    Whether the company has said anything at all. Reporting on the resulting lawsuits, published this week, states that IDScan “has not published any statements about these allegations, and it did not respond to BleepingComputer’s requests for comments.” The notice quoted above was live on idscan.net when we read it this afternoon. Those two things can both be true — a company can post a breach notice and still decline to comment on litigation — but a reader following the coverage would reasonably conclude the company has been silent, and it has not been. Where coverage and the primary source diverge, the primary source is the notice.

    Separately, when Krebs approached the company before the notice, a named IDScan representative told him: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.”

    Why it matters

    This is a breach of an identity-verification vendor, which makes the exposed material qualitatively different from the usual email-and-hashed-password set. IDScan’s product exists to read government identity documents at a point of sale or a rental counter; the data it holds is by definition the data used to prove that a person is who they say they are. Reporting on the company’s customer base describes car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries and hospitality businesses, with Hertz named. Every one of those is a place where a consumer hands over a license as a condition of the transaction and has no visibility into where the scan goes afterward, or how long it is kept.

    That is the structural point worth carrying away, and it does not depend on which number turns out to be right. The people in this data set are not IDScan’s customers. They are their customers’ customers, and in most cases they will never have heard the vendor’s name. The notice’s advice — review your credit reports — is the only advice available, and it is advice addressed to people who cannot check whether they are in the set, because the company that holds the set has not said who is in it.

    The number vacuum has a second-order effect that is already visible. When the affected organization publishes no figure, the attacker’s figure becomes the headline figure by default, and it propagates into litigation, into regulatory attention and into every subsequent story as though it were established. It may well be roughly right — Krebs’s search results point that way. But “roughly right, sourced to the seller” is a different epistemic object from “confirmed by the holder,” and once the two are conflated in print they are very hard to separate again. This publication’s standing practice is to show conflicting numbers as conflicting rather than pick one, and here the conflict is not between two counts. It is between a count and an absence.

    The route that normally resolves this is the state breach-notification system, which forces a per-state resident count into a public filing. That route is partly closed right now. Maine’s public breach-notice database — usually the fastest searchable source for a hard number — is offline, with the state directing queries to an email address. California’s published list showed no IDScan entry when we checked this afternoon. Whether that reflects no filing yet, a filing not yet posted, or notification still in progress, we cannot say.

    What to do

    If you are an IDScan customer — a business that used the platform to scan identity documents — ask the vendor directly, in writing, whether your account’s stored records are in scope and for what date range, and ask specifically whether images as well as document numbers were involved. The public notice answers neither question. Treat the answer as a notification obligation trigger for your own customers, and get counsel involved on the timing rules in every state you operate in.

    If you handle identity documents through any vendor, this is the week to establish what your provider retains after a verification completes, for how long, and whether images are stored or discarded once the document number is read. Retention is the variable that turned a scanning service into a 150-million-record repository, and it is a contract term, not a technical one.

    For individuals, a driver’s license number is not rotatable the way a password is. Credit monitoring detects misuse after the fact; a credit freeze at the three bureaus prevents new-account fraud, is free, and is the stronger control. Some states allow a license number to be reissued after documented identity theft — a question for your own motor vehicle agency.

    Sourcing note

    Checked directly: IDScan.net’s own “Notification of Data Security Incident,” dated September 4, 2026, for every statement attributed to the company, including the absence of any figure; Krebs on Security’s September 1, 2026 report for the Nexus marketplace’s claimed document counts, the search-result estimate, the personal verification, the FBI New Orleans investigation and the site’s removal on September 2; TechCrunch’s September 10 report and BleepingComputer’s litigation report as leads and as the source of the “has not published any statements” characterization; the California Attorney General’s published breach list, which showed no IDScan entry; and Maine’s breach-notice database, which is offline.

    Not established: the number of affected individuals or records; whether license images were exposed; which IDScan customers are in scope; the number, court and filing dates of the lawsuits, which we could not confirm from a primary docket; and the true publication date of the notice. No attribution to any named actor or group is made here — the Nexus operators’ identity is unknown, and the marketplace’s claims about what it held are claims. IDScan has confirmed unauthorized access. It has not confirmed scale.