← Blog · · df00tech

IDScan Confirms Cloud Breach Linked to 153 Million Stolen Driver's License Scans

security-news breach

Identity verification vendor IDScan has confirmed that attackers accessed customer data stored in its cloud platform, according to a report from BleepingComputer. The confirmation follows earlier reporting that linked the company to a massive exposed database containing more than 153 million scanned driver's licenses. Details on the intrusion vector, timeline, and full scope of affected records have not yet been disclosed.

Why It Matters

IDScan provides identity-verification and document-scanning services, meaning the exposed data likely includes high-fidelity images and extracted fields from government-issued IDs — information well-suited to identity theft, synthetic identity fraud, and downstream account-takeover or KYC-bypass schemes. Because the company sits in the supply chain for other businesses that rely on it for identity checks, the blast radius may extend well beyond IDScan's direct customers to end users whose documents were scanned during onboarding elsewhere.

What Defenders Should Watch For

  • Organizations that use IDScan or similar identity-verification/KYC vendors should review vendor notifications and ask for specifics on what data types and date ranges were exposed.
  • Watch for a rise in identity-document-based fraud attempts (new account openings, KYC bypass attempts using scanned or synthetic IDs) in the weeks following large driver's-license data exposures.
  • Audit cloud storage and access-logging configurations for any third-party identity-verification integrations your organization uses — misconfigured cloud storage is a recurring root cause in these types of incidents, though the specific cause here has not been confirmed.
  • Consider increased scrutiny on ID-based verification workflows (e.g., additional liveness or biometric checks) if you rely on document scans alone for identity assurance.

This is a developing story and further details on the root cause and full scope of exposure have not yet been confirmed. For the latest reporting, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.