When Age Verification Gets Breached: The IDScan Lesson
A suspected breach at ID verification firm IDScan.net exposed over 153 million driver's licence scans. Here's what it means for anyone who has ever handed over their ID.
In early September 2026, investigative journalist Brian Krebs reported something that should alarm anyone who has ever handed their driving licence to a bouncer, a dispensary clerk, or a hotel check-in terminal. A dark-web identity-theft service called Nexus was selling scans of more than 153 million US and Canadian driver's licences, 10 million ID cards, 3 million travel documents, and roughly 580,000 medical cards. The data was traced to IDScan.net, a Louisiana-based identity verification company used by retailers, hospitality businesses, financial services firms, automotive dealerships, and cannabis dispensaries across North America.
The FBI's New Orleans field office opened a formal investigation. Nexus operators claimed they had been silently pulling data from a live breach at IDScan for over a year before going public—and the service vanished shortly after Krebs published his findings. Whether that disappearance means the operators cashed out and moved on, or simply rebranded, is unknown. What is certain is that the data already existed somewhere beyond IDScan's control.
This incident is worth examining carefully, not because it is unique, but because it is the clearest example yet of a specific and growing problem: the mandatory collection of government-issued identity documents at the point of service. Every business that scans your ID creates a record. Every record is a liability. This article looks at what went wrong, why the harm is permanent, and what individuals can reasonably do to limit their exposure going forward.
What IDScan.net actually does
IDScan.net provides real-time identity and age verification software to businesses that are legally required—or commercially motivated—to confirm who their customers are. A cannabis dispensary in a state with strict age controls, a casino, a hotel, a car rental desk, a bank branch: all of these might use a platform like IDScan to scan a physical document, parse its machine-readable data, and return a pass or fail verdict in seconds.
The appeal for businesses is obvious. Manual verification is slow, inconsistent, and depends on staff training. Automated scanning is fast, auditable, and reduces legal liability if an under-age customer slips through. For regulators, it looks like a robust compliance solution.
The problem is the data trail it creates. When a system scans your licence, it typically captures your full name, date of birth, home address, physical descriptors, licence number, and often an image of the document itself. That data has to live somewhere—on IDScan's servers, in a customer's database, or both. And wherever it lives, it can be stolen.
The scale of the exposure
153 million driver's licence scans is not an abstract number. The combined population of the United States and Canada is roughly 375 million people. If Nexus's figures were accurate, this breach touched a significant fraction of the entire adult population of both countries. The breakdown, as reported by Krebs, looked like this:
| Document type | Records reportedly exposed |
|---|---|
| Driver's licences (US & Canada) | 153 million+ |
| ID cards | 10 million |
| Travel documents | 3 million |
| Medical cards | ~580,000 |
Nexus operators claimed they had been inside IDScan's systems for more than a year before going public. If that timeline is accurate, it means the data was being exfiltrated slowly and quietly—a classic low-and-slow approach designed to avoid triggering anomaly detection. By the time the breach became public knowledge, the damage was long done.
Why this kind of breach is worse than most
Data breaches have become depressingly routine. Leaked email addresses and hashed passwords are serious, but they are also recoverable: you change your password, you enable two-factor authentication, you move on. The IDScan breach belongs to a different category of harm entirely.
Government-issued identity documents cannot be changed. Your date of birth is fixed. Your address, while changeable, is tied to years of historical records. Your licence number, your physical description, your document's expiry date—all of these are persistent identifiers that fraud operations can use indefinitely. Security experts commenting on the breach made this point plainly: every person in the dataset carries the exposure permanently. There is no patch, no reset, no recovery in the conventional sense.
This creates a long tail of harm. Identity fraud enabled by a 2026 breach might not surface until 2028 or 2030, when someone attempts to open a credit account, apply for a loan, or cross a border using synthetic identity data assembled from the leaked records. The victims may not connect the fraud to the original incident at all.
Medical card data adds another dimension. While 580,000 records is the smallest category in the breach, medical identifiers carry specific risks: insurance fraud, prescription fraud, and the corruption of medical records with another person's health history—a problem that can have direct clinical consequences.
The structural problem with mandatory ID collection
It is worth being clear about something: IDScan.net is not the villain here. The company was providing a service that its clients—and in many cases, regulators—demanded. The structural problem is that mandatory identity verification creates centralised pools of extremely sensitive data, and centralised data pools attract attacks.
Regulatory requirements around age verification have expanded significantly in recent years, particularly in sectors like cannabis retail and online platforms. Each expansion of mandatory ID checks creates a new class of businesses that must collect, process, and store government-issued document data. Each of those businesses, in turn, may rely on a third-party verification provider. The attack surface grows with every new compliance mandate.
This is not an argument against age verification in principle—there are legitimate reasons to confirm someone's age before selling them certain products. It is an argument that the method of verification matters enormously. Systems that verify age without retaining the underlying document data, or that use tokenisation and minimum-necessary data principles, impose far less risk on the people being verified. Whether those principles are built into verification platforms is largely a question of procurement choices made by businesses and technical standards set by regulators.
What individuals can do—and what they cannot
The honest answer is that your options are limited once your ID has already been scanned. You cannot opt out retroactively. If you have ever bought something at a cannabis dispensary, rented a car, or checked into a hotel that used IDScan's platform, your data may be in that dataset. That uncertainty is part of what makes breaches of this type so corrosive to public trust.
Going forward, there are a few practical steps worth taking:
- Monitor your credit file. In the UK, services like Experian and Equifax offer alerts for new credit applications. In the US, you can freeze your credit at each of the three major bureaus, which prevents new accounts from being opened in your name without an active unfreeze.
- Be alert to identity fraud indicators. Unexpected bills, unfamiliar credit applications on your file, or official letters addressed to your address for someone else can all signal that your identity is being used.
- Ask before you hand over your ID. When a business asks to scan your document, it is reasonable to ask what data they retain, how long they keep it, and who processes it. You may not always get a useful answer, but the habit of asking creates friction that signals consumer awareness.
- Limit digital identity exposure where you can. Your online activity—your real IP address, browsing habits, location data—represents a separate but related layer of identity information that can be combined with leaked ID data to build a more complete profile. A no-logs VPN does not solve a document breach, but it does reduce the ambient data available about you online.
On that last point: a VPN cannot protect you from a breach at a company that already holds your physical ID data. Anyone suggesting otherwise is overstating what the technology does. What a VPN does address is the ongoing collection of behavioural and location data by your ISP, advertising networks, and sites you visit—data that, in aggregate, adds to your overall exposure profile. If you are reassessing your digital hygiene in light of incidents like this one, that is a reasonable place to start. PremierVPN's no-logs policy means we do not retain records of what you do while connected, which is precisely the kind of data minimisation that IDScan apparently did not apply to the records it held.
The regulatory question this raises
The IDScan suspected breach will likely accelerate a conversation that was already happening in privacy and data protection circles: what obligations should verification providers carry, and should regulators mandate data minimisation as part of any age verification framework?
Several principles seem worth pushing for:
- Minimum retention periods. If the purpose of scanning an ID is to verify age at the point of sale, there is no compelling reason to retain the full document data for months or years afterwards. A verification result—pass or fail, with a timestamp—may be sufficient for most compliance purposes.
- Prohibition on centralised storage by third parties. Verification providers that aggregate data from thousands of client businesses create single points of catastrophic failure. Architectures that process and discard, rather than process and store, would reduce this risk substantially.
- Mandatory breach notification with specific timelines. If Nexus operators were inside IDScan's systems for over a year, that is a detection failure as much as it is a prevention failure. Regulators should scrutinise whether IDScan's monitoring capabilities met reasonable standards.
None of these changes would eliminate the risk of a breach. They would, however, reduce the scale of harm when one inevitably occurs.
The permanent nature of the problem
The most important thing to understand about the IDScan incident is what it is not. It is not a story about a company that did something unusual. It is a story about what happens when the routine collection of government-issued identity data meets the routine reality of data breaches. Both of those things—routine collection and routine breaches—are features of the current environment, not aberrations.
For every person whose data appeared in the Nexus dataset, the exposure is now a permanent condition. That is not alarmism; it is an accurate description of what it means to have your date of birth, address, physical description, and ID number in the hands of criminals who trade in that information. The documents cannot be reissued to neutralise the risk. The data cannot be un-leaked.
This should change how businesses, regulators, and individuals think about the cost of mandatory ID collection. The benefit—age or identity verification at the point of service—is real but bounded. The risk—permanent exposure of every person whose document was ever scanned—is also real, and it compounds with every new record added to a centralised database.
If you are rethinking your broader digital privacy posture after reading about incidents like this one, starting with what data you actively generate online is a reasonable first step. The basics of what a VPN does and does not do are worth understanding clearly, as is being selective about the services and platforms you hand your personal information to. PremierVPN's free browser extension can help reduce the ambient tracking that follows you across the web—a small but concrete measure in a landscape where every layer of unnecessary data collection carries some degree of risk.
The IDScan incident is a lesson in what happens when data minimisation is treated as optional. It should not be.
Share this article
Protect your privacy with PremierVPN
Fast, secure, and truly private VPN service with servers in 12+ countries.
Get Started