SecurityWeek reported on September 3, 2026 that a threat actor was offering digital scans of more than 153 million U.S. and Canadian driver licenses through a dark-web identity theft service called Nexus. The reporting, based heavily on work by Brian Krebs, tied the likely source to IDScan.net, a Louisiana-based identity verification provider. IDScan had not confirmed the incident scope in the public reports, so the right word here is still reportedly. The business lesson, however, is already clear.
For many organizations, scanning a driver license has become ordinary. A customer checks into a facility. A visitor enters a building. A tenant signs paperwork. A delivery driver, patient, student, volunteer, or employee proves who they are. The scanner beeps, the workflow moves on, and everyone assumes the ID check was just a momentary gate.
The problem is that an ID scan may not be momentary at all. It can become a stored image, a retained record, a vendor-managed data set, an API transaction, a support artifact, or a long-lived identity proof that the business no longer thinks about after the front desk transaction is over. That is where identity verification vendor risk becomes an owner-level issue, not just an IT setting.
The Risk Is Not Only The Scan
A driver license image is different from a password or a credit card number. A password can be changed. A payment card can be replaced. A license scan often includes a face, address, date of birth, license number, barcode data, and sometimes front-and-back images. Follow-up reporting also described infrared or ultraviolet versions of some ID images, which are used by verification systems to inspect physical document features.
That kind of identity evidence can help a legitimate business reduce fraud. It can also help a criminal make fraud more convincing if the data escapes. For a New Jersey business, the practical issue is not whether identity checks are bad. Sometimes they are legally required or operationally necessary. The issue is whether the business has treated ID scan retention as a deliberate policy decision.
If the answer is, we use whatever the vendor stores by default, the business may be accepting a privacy, compliance, and reputation exposure it never actually approved.
The Owner Decision Behind ID Verification
The business decision is simple to state and easy to overlook: collect the least identity data that still satisfies the real requirement, then make sure the vendor contract matches that decision.
That means separating identity verification from identity retention. A business may need to confirm that a person is old enough, authorized, licensed, credentialed, or tied to a transaction. It does not automatically follow that the business or its vendor needs to keep a full image of the ID indefinitely.
Owners and operators should ask whether the workflow can verify an ID without storing the image, whether retention can be shortened, whether sensitive fields can be masked, and whether access to retained scans is logged. Those details matter before a breach, not after a reporter, regulator, customer, or plaintiff asks for answers.
Questions To Ask Your IT Provider Or Vendor
If your business uses ID scanning, age verification, visitor management, rental verification, credential checks, or customer onboarding tools, ask direct questions before renewing the service or expanding its use.
- What exactly is collected? Confirm whether the system stores full images, barcode data, selfies, device metadata, transaction timestamps, or only a verification result.
- Where does the data go? Identify the vendor, sub-processors, cloud location, support access path, and any API integrations that receive identity data.
- How long is it retained? Require a retention schedule in writing. Default retention is not the same as approved retention.
- Who can access it? Ask about administrator access, service accounts, support staff, role-based controls, and logging for bulk exports.
- What evidence will you receive after an incident? Contract terms should cover notification timing, affected data fields, logs, forensic summaries, and deletion or containment evidence.
- Can the business reduce the data? Ask whether the system can verify age, identity, or authorization without retaining the full document image.
These are not exotic security questions. They are basic vendor accountability questions. If a provider cannot answer them clearly, the business has learned something important before the next renewal.
A Practical Next Step
Start with an inventory. List every place your organization collects a driver license, passport, student ID, employee credential, medical card, visitor badge, or other identity document. Include front-desk tools, websites, mobile apps, HR systems, payment workflows, property management platforms, school systems, and one-off shared folders where staff may have saved copies.
For each workflow, document the purpose, legal or business reason, vendor, retention period, access owner, and deletion process. Then decide which scans are truly necessary and which can be replaced with a lighter verification record.
The reported IDScan story is a reminder that identity proof can become identity inventory. Once that inventory exists, someone owns the risk. Better to decide who that is while the system is quiet than after customer ID data appears somewhere it never belonged.
Sources and further reading