IDScan, a Louisiana identity verification firm most people have never heard of, has confirmed a breach covering more than 150 million driver’s license records from the United States and Canada. The haul includes licence photos, full names, licence numbers and identity numbers lifted from other government documents, passports among them.
The company only acknowledged the incident around September 1, after a searchable dark web site appeared offering lookups against the stolen set and after Brian Krebs published what he’d found there. The intrusion into IDScan’s cloud systems had been running for roughly a year before anyone noticed. Both the FBI and the Pentagon opened investigations.
Who Was Feeding This Database
IDScan sells document authentication to businesses that have to check an ID at the door or at the counter. Bars and entertainment venues. Cannabis dispensaries. Car dealerships, rental desks, age-gated retail. Every one of those checks produced a scan, and the scans were kept.
That’s the part worth sitting with. A regulatory obligation to verify age or identity turned into an operational habit of storing the verification artefact indefinitely, at a vendor the end customer never chose and never evaluated. The bouncer scanned a licence in Baton Rouge in 2023 and the image is on sale now.
A Credential Nobody Can Rotate
Breached passwords get reset. Breached card numbers get reissued, usually within a week, and the fraud loss sits with the issuer. A driver’s licence image is different. The number stays valid for years, the photo stays valid until the holder ages out of it, and the state has no mechanism for mass reissue. Holders in most states can replace a licence only by paying a fee and explaining why.
Which means this dataset has a long useful life for anyone doing synthetic identity fraud, account takeover at institutions that accept a licence image as proof, or remote onboarding fraud at the very KYC services that generated it in the first place. Document-image verification as a control just got measurably weaker across the whole market, and the vendors selling it know it.
Where the Money Moves Next
Expect three things. Enterprise buyers of KYC and age-verification services will start asking about retention, and zero-retention architectures that verify and discard will move from a differentiator to a requirement in RFPs. Cyber insurers will reprice the vendors that warehouse identity documents at scale, because the aggregate liability of a single verification provider can now be measured in nine figures of records. And state regulators, already active on biometric and identity data, get a very clean case study to point at.
The verification industry sold itself as the answer to identity fraud. It also built the largest single stockpile of identity fraud raw material in North America. Both things are true, and this year the second one is what the market is looking at.