Back to all lessons
Awareness Lessons
3 days ago

153 Million Driver License Images Exposed via Identity Verification Firm Breach

A threat actor allegedly exfiltrated over 153 million driver license and identity card scans from IDScan.net, an identity verification service provider, and listed them for sale on the dark web. This incident highlights the extreme concentration risk inherent in third-party identity verification platforms, which aggregate highly sensitive PII at massive scale, making them high-value targets. When a single vendor holds biometric and government-issued identity data for millions of individuals, a single breach can have cascading, irreversible consequences — unlike passwords, driver license images cannot be 'reset.' Organizations that rely on third-party identity verification services must rigorously vet those vendors' security postures, as their data exposure becomes your liability and your customers' harm.

Tactical Insight

Immediate actions

  • Notify affected individuals promptly and provide guidance on monitoring for identity fraud and enrolling in credit monitoring services.
  • Conduct an emergency audit of all third-party identity verification vendors to assess their data handling, retention policies, and breach status.
  • Revoke or rotate any API credentials and access tokens connected to the potentially compromised IDScan.net integration.

Long-term improvements

  • Enforce strict data minimization contracts with vendors, requiring that sensitive identity images are not retained longer than operationally necessary.
  • Implement a formal Third-Party Risk Management (TPRM) program with regular security assessments and audit rights for all vendors handling PII.
  • Require identity verification vendors to demonstrate compliance with recognized standards (SOC 2 Type II, ISO 27001) before onboarding.

Detection measures

  • Deploy dark web monitoring services to receive early alerts when organizational or customer data appears in illicit marketplaces.
  • Establish continuous logging and anomaly detection on all data egress points connected to identity data repositories to catch bulk exfiltration attempts.