If your business uses any identity or age verification service, you should know about the IDScan.net breach. Not just as news, but as a direct example of how third-party vendors can be a risk for your organization.
Here’s What Happened
A dark web identity-theft marketplace called Nexus appeared on a Russian cybercrime forum on August 31, 2026, advertising searchable scans of more than 153 million U.S. and Canadian driver’s licenses. This also included over 10 million ID cards, 3 million travel documents, and roughly 580,000 medical cards, such as marijuana dispensary cards. The operator claimed the data contained more than 170 million individuals.
Security journalist Brian Krebs verified his own Virginia driver’s license in the database and traced the source to IDScan.net, a Louisiana-based identity verification company whose scanning technology sits behind ID checks at retailers, bars, dispensaries, car rental counters, and Fortune 500 clients including Hertz, Target, and Caesars Entertainment. The company confirmed it detected unauthorized access to its systems on or around September 1, 2026, and brought in forensic specialists.
The FBI’s New Orleans field office opened a formal investigation, reportedly in part because some of the exposed licenses belonged to FBI agents. Defense Secretary Pete Hegseth’s license appeared in the database, listed for $100. The Nexus marketplace went offline after the story broke, but not before Krebs observed the license count climbing by nearly 400,000 records within a single 24-hour window, suggesting the breach may have still been active when it was discovered.
When You Hand a Vendor Sensitive Data, You’re Trusting Their Security
IDScan.net’s clients weren’t breached; their vendor was. And now their customers’ driver’s licenses are on the dark web.
Every business that used IDScan.net to scan IDs was trusting IDScan.net with some of the most sensitive documents their customers carry. A scanned driver’s license isn’t just a name and a birthdate. It’s a government-issued photo ID with an address, a license number, and biometric features that make it far harder to replace than a stolen credit card. You can’t cancel a driver’s license the way you cancel a card.
The breach operators claimed they had been continuously exfiltrating data for over a year before anyone noticed. That means they had persistent access to a system holding hundreds of millions of identity documents that went undetected long enough to copy most of them.
This is what third-party vendor risk looks like. Your internal security controls, your employee training, and your firewall don’t apply to a vendor’s environment. The data you hand them is governed by their security practices, not yours. And in most small business vendor relationships, nobody has ever asked what those practices are.
Third-party vendor risk shows up in our risk assessments. Most businesses discover the gap after something goes wrong. Let’s talk about what that looks like for your vendor relationships.
Â
Why This Hits Closer to Home Than Most Breaches
IDScan.net’s clients range from large enterprises to small independent retailers, bars, and dispensaries. IDScan.net was a great fit for these businesses because the scanning technology was affordable, easy to deploy, and helped them stay compliant with age-verification requirements.
Most of those businesses likely had no idea how much data IDScan.net was retaining on their behalf, where it was stored, or how it was protected. They bought a scanner, signed a contract, and didn’t think too much about the security. And if they did, they probably asked the vendor, and the vendor said it was handled.
The operators behind Nexus claimed the data included records from clients across retail, hospitality, cannabis, and car rental. Now the businesses themselves are implicated in a breach they had no control over.
Insider wrongdoing incidents jumped sevenfold in the first half of 2026, according to the ITRC’s H1 report. Whether this breach involved an insider, an external actor, or something more complex isn’t yet confirmed. What is confirmed is that the breach went undetected long enough to copy data at an extraordinary scale, pointing to inadequate monitoring or controls, or both.
Questions to Ask Your Identity Verification or Age Verification Vendor
If your business uses a vendor to scan, verify, or store identity documents, ask these questions before the next news cycle brings a similar story about a different vendor.
1. How long do you retain scanned documents, and in what format?
This is the most important question. Some vendors retain scanned images indefinitely. Others delete them immediately after verification. The difference determines how large a data exposure could be if the vendor is breached. A vendor that deletes scans immediately after use has far less to lose than one that keeps years of archived images.
2. Where is that data stored, and who has access to it?
Cloud storage misconfiguration is consistently one of the top findings in security assessments, and identity document data stored in cloud environments that aren’t properly secured is exactly the kind of target attackers exploit. Ask whether the data is encrypted at rest, who within the vendor organization can access it, and whether access is logged.
3. Have you had a security assessment or penetration test in the last 12 months?
The vendor should be able to answer yes to this question and tell you who conducted it. A vendor who can’t answer the question hasn’t prioritized it.
4. What does your breach notification process look like?
The Nexus marketplace appeared on August 31. IDScan.net detected unauthorized access on September 1. The timeline is tight, but the breach operators claimed to have been inside for over a year. Your contract with an identity verification vendor should specify how quickly they must notify you of a breach, and what information they must provide.
5. Does your service agreement limit your liability if a breach at your end exposes our customers’ data?
Most standard vendor contracts do limit liability, often significantly. You should be aware of how limited it is.
6. Do you have cyber insurance, and what does it cover?
A vendor with cyber insurance coverage has, at minimum, been through an underwriting process that required them to document their security controls. That’s not a guarantee of adequate security, but it’s a better starting point than a vendor who has never gone through that process.
Â
What to Do If You’re an IDScan.net Client Right Now
If your business used IDScan.net and you’re trying to figure out what to do, the first step is to contact IDScan.net directly to understand the scope of what was accessed from your account specifically. Their forensic investigation is ongoing, and the picture will likely get clearer in the coming weeks.
Beyond that, consider proactively notifying your customers before they read about it elsewhere. The breach affects their driver’s licenses, not their payment information, so the immediate fraud risk is different from a typical payment card breach. But a driver’s license exposure creates longer-term identity theft risk that affected individuals should know about so they can monitor accordingly.
From a legal standpoint, whether you have breach notification obligations depends on your industry, the state(s) where your customers are located, and the specific nature of what was exposed through your vendor relationship. If your business is in healthcare, financial services, or any regulated industry, you may want to speak with legal counsel sooner rather than later.
The Broader Lesson
Understanding what your vendors hold, how they protect it, and what happens if they get breached isn’t an enterprise-level concern. It’s a basic business question that got a lot harder to ignore this week.
If you want help thinking through your vendor relationships and what due diligence looks like, we’re glad to join the conversation. MainNerve has been helping organizations assess their real security exposure for over 20 years. Contact us today for a free consultation.