CuraSec

Act active

IDScan breach exposes 153 million driver's license scans

2026-09-10 14:58 UTC · BleepingComputer · read the source ↗ #vendor-breach#identity-verification#data-breach
  • Engineer — Plan: If your org uses IDScan’s API or SDK for customer identity verification, audit the integration to determine what PII flows to their cloud and whether your API credentials may have been exposed; no patch action, but a data-inventory and vendor-access review is warranted.
  • SOC/IR — Learn: A breach of this scale at an identity-verification vendor could fuel downstream account-takeover campaigns using stolen DL scans as identity proofs, but no IOCs or TTPs have been published to hunt on yet; monitor for follow-on reporting.
  • Leader — Act: Confirm whether your organization uses IDScan for any identity-verification workflow, request their formal incident disclosure and scope attestation, and assess whether your customers’ data is among the 153 million records; brief legal on potential notification obligations if exposure is confirmed.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.