It sure looks like hackers breached a major ID card verification service
- ID
- 20814
- Status
- summarized
- Published
- 03 Sep 2026, 3:35 AM
- Fetched
- 03 Sep 2026, 3:41 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/02/it-sure-looks-like-hackers-breached-a-major-id-card-verification-service/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 7.0
- Created
- 03 Sep 2026, 3:41 AM
- Tags
- Audience
- developerssaas_founders
What happened
Brian Krebs reports that identity verification service IDScan was likely breached, with a dark web site called Nexus claiming to offer searchable access to over 150 million driver's licenses and passports from the US and Canada, adding ~500,000 new documents daily. Krebs confirmed the data was authentic by finding his own driver's license in the database, and security researcher Zach Edwards helped identify IDScan as the likely source. IDScan's COO confirmed the company is investigating, and the FBI's New Orleans field office is also probing the breach.
Why it matters
If you integrate any third-party identity verification or KYC service into your onboarding flow, this breach shows that vendor's security failures can expose your customers' ID documents in near real-time. Builders should audit which identity verification vendors they rely on, check their data retention and access logging contracts, and consider whether they are storing ID document images they don't need to keep. For Malaysian founders building fintech or regulated products, this is a concrete reminder to evaluate vendor security posture and data minimization before handing over customer ID scans.
Discussion angle
What due diligence should you do on identity verification vendors before integrating them, and what data minimization practices can you adopt so a vendor breach doesn't expose your users' ID documents?