A Year of Quiet Access, Then a Confirmation
IDScan, a Louisiana-based identity verification service used by entertainment venues and cannabis dispensaries to check customer documents, confirmed on September 10 that hackers had stolen identity records from its cloud storage. Security journalist Brian Krebs had reported the underlying breach on September 2, after a dark web platform began offering searchable access to a database the sellers called Nexus, more than 11.5 million pages of results at roughly fifteen records per page. The attackers claimed to have been continuously exfiltrating new data from IDScan for over a year before the listing appeared, meaning the exposure was not a single incident but a long, undetected harvesting operation.
The FBI's New Orleans field office opened a formal investigation on September 1, and the Pentagon confirmed it was aware of the suspected breach after US Secretary of Defense Pete Hegseth's own record turned up among the compromised files, verified independently by a security researcher. IDScan's public statement offered almost nothing beyond acknowledgment, telling one reporter it was not yet able to share additional details while its own investigation continued. Full access to the leaked database reportedly required payment, the structure of an extortion sale rather than a simple dump.
What Was Actually Taken
The stolen records break down by document type, and the scale sits well above any comparable identity-document breach reported this year. Driver's licenses make up the overwhelming majority, but the collection reaches into several other document categories IDScan's customers rely on for age and identity checks.
| Document type | Records exposed |
|---|---|
| US and Canadian driver's licenses | 153 million or more |
| Other identification cards | 10 million or more |
| Passports and travel documents | 3 million or more |
| Medical and dispensary cards | 579,000 or more |
Ontario alone accounted for roughly 473,000 of the Canadian licenses in the set, a reminder that a US-based vendor's breach does not respect the border its customers operate across. Each record carries a full name and a government document number, and in most cases the scanned photo page itself, exactly the combination identity thieves need to open accounts or pass automated verification checks elsewhere.
The Gap Your Own Vendor Contract Should Close
An EU or UK business that outsources age verification or identity checks, increasingly a legal requirement rather than a convenience under rules like the Digital Services Act's age-assurance provisions, hands a third-country vendor a copy of its customers' government documents and then has almost no visibility into how long that vendor sits on a breach before saying anything. GDPR gives a controller 72 hours from becoming aware of a breach to notify its supervisory authority, and NIS2 gives an essential or important entity as little as 24 hours for an early warning. Neither deadline reaches IDScan directly, because the clock only starts once the EU-side controller itself becomes aware, and a US processor has no equivalent statutory duty to tell its customers quickly, or at all, beyond whatever the underlying data processing agreement happens to specify.
That gap is the actionable part of this story. A business relying on an identity-verification vendor should already know exactly what notification deadline its own data processing agreement sets for that vendor, in writing, rather than assuming a US company will volunteer the news the moment something goes wrong. IDScan's own timeline, a claimed year of quiet access followed by nine days between the public dark web listing and a company confirmation, is the case for treating that clause as load-bearing rather than boilerplate, and for asking now, not after the next headline, exactly how fast a vendor is contractually required to call.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: A Vendor Breach Your DORA Register Can't Explain | CEVA Breach Exposes Steam Hardware Buyers in Europe



