ID Verification Firm IDScan.net: 153M License Scans Leaked for Over a Year
Original: Hackers Had a Live Feed of Every ID Verification Company Scanned for over a Year
Why This Matters
The breach of 153M records from a major ID verification vendor highlights systemic privacy risks in mandatory age-verification frameworks.
Hackers accessed a live feed of every ID scanned by Louisiana-based IDScan.net for over a year, exposing 153 million U.S. and Canadian driver's licenses now sold on the dark web. The FBI's New Orleans field office has launched an official inquiry into the breach.
Security journalist Brian Krebs reported a major breach involving IDScan.net, a Louisiana-based identity verification company with contracts spanning thousands of cannabis dispensaries, Hertz, FedEx, and Target, as well as numerous online age-verification clients. Hackers gained continuous, real-time access to every ID scan the company processed, accumulating over 153 million U.S. and Canadian driver's license images now listed for sale on a newly launched dark web identity theft service. On the day the breach was publicly disclosed—and just before the dark web site was taken down—an additional 400,000 records were added to the database. Krebs confirmed victims' identities by cross-referencing database entry dates with individuals' personal calendars, linking scans to real-world interactions at businesses like Hertz and cannabis retailers. IDScan.net had publicly promoted its security practices through a 'Trust Center' page and had advocated for age-verification legislation, including the Kids Online Safety Act (KOSA). The FBI's New Orleans field office has opened a formal inquiry. The breach underscores longstanding concerns from privacy researchers, including a widely cited 2025 analysis by Eric Goldman, that age and identity verification systems inherently create large-scale privacy risks regardless of vendor security claims.