Restricted analysis, made public daily.
Declassified under standing order Edition No. 074 Tuesday, September 15, 2026

IDScan Verifies Identities.
Who Protects the Proof?

IDScan.net verifies identity documents for car-rental counters, retailers, and cannabis dispensaries. A dark-web marketplace advertised more than 153 million driver’s license records. IDScan.net disclosed possible unauthorized access to customer information, and lawsuits allege it failed to protect that data.

IDScan.net provides technology for scanning and authenticating identity documents. Businesses use those results to support identity and age checks — car-rental counters, retailers, and cannabis dispensaries among them. On or around September 1, 2026, the company says it learned that certain data may have been accessed without authorization. The sellers claimed they had been extracting data for more than a year.

IDScan.net’s own notice, posted September 4, uses careful, hedged language throughout: an unauthorized party “may have accessed and/or copied” customer information, and the affected data “may include” full names and driver’s license or other government-issued identification numbers. The notice gives neither an affected-record total nor an explanation of how the possible access occurred.

Brian Krebs first reported the incident September 1, after a source alerted him to a listing on the Russian cybercrime forum Exploit. The seller, a marketplace called Nexus — reported offline by BleepingComputer on September 4 — advertised more than 153 million scanned U.S. and Canadian driver’s licenses, 10 million ID cards, more than 3 million travel documents and/or international IDs, and 579,000 medical cards. That claimed inventory also included records Krebs’s reporting says may refer to Common Access Cards, the credential issued to U.S. military and government personnel. IDScan.net has adopted none of those figures; its own site separately states it holds more than 150 million driver’s license records in total, a routine claim about its database size, not a confirmation of how many were exposed here. TechCrunch reported on September 10 that IDScan.net had not responded to its requests for comment. The FBI confirmed it is investigating; a spokesperson did not elaborate.

A valid ID check is not a security audit of the company performing it.

What the record establishes

The data at risk is the data the system was built to hold. Names and government ID numbers, the exact two fields IDScan.net’s own notice names, may have been accessed, the company says. Resetting a password cannot retrieve a copied identity document.

The scale comes from the seller, not from IDScan.net. 153 million-plus licenses is the inventory Krebs on Security found advertised on a cybercrime forum; IDScan.net has published no breach total of its own.

The duration is a sales claim, not a finding. “Over a year” is how the people selling the data describe their own access, in their own listing. Neither IDScan.net nor the FBI has confirmed it.

Proposed class actions have been filed, not merely solicited. Multiple proposed class actions were filed against IDScan.net in the U.S. District Court for the Eastern District of Louisiana between September 2 and 4, 2026, alleging the company failed to protect customer data. The allegations have not been established by the filings themselves, and BleepingComputer reported IDScan.net had not responded publicly as of September 4.

The Agentics read

Businesses rely on specialist systems to support verification. That reliance leaves a separate question about the provider’s handling of the underlying data. On September 10, Ant International, Mastercard, and Visa announced collaboration on a “Know Your Agent” interoperability framework. The initiative preserves each network’s own verification processes while pursuing common trust signals, operator traceability, certification requirements, and continuous monitoring. It raises an adjacent question: what evidence keeps a trusted credential trustworthy after it’s first accepted?

A business relying on IDScan.net’s verdict still has another question to answer: what happens to the information afterward, who can reach it, and what evidence supports continued trust in the company holding it? Through the Agentics lens, the distinction is a simple one: confidence in a provider’s verification result does not establish confidence in its data custody. Each requires its own evidence. Larry Baldwin, a principal intelligence researcher at Cybera, described the stakes: “the very thing those improvements are dependent on are compromised.”

None of this required an ID check to fail. IDScan.net says its investigation continues; the lawsuits allege it failed at exactly the second question. Verification answers a question. Custody creates an obligation.

Sources

IDScan.net posted its own notice September 4, 2026, quoted directly above. Krebs on Security first reported the incident September 1, and is the source for the marketplace’s claimed inventory and the “over a year” access claim, the sellers’ own unverified description. TechCrunch’s September 10 account confirms IDScan.net did not respond to requests for comment, and that its 150-million-plus figure is the company’s general holdings claim, not a breach count.

BleepingComputer reported on September 4 that multiple lawsuits had been filed against IDScan.net in Louisiana, alleging failures to protect customer information, and that the company had not responded to its requests for comment. Court filings show the suits were docketed in the U.S. District Court for the Eastern District of Louisiana between September 2 and 4, 2026.

The Know Your Agent framework is described directly in Ant International’s own September 10 announcement, characterized there as a newly begun collaboration, not a finalized standard.

Who protects the proof?

A verification result tells a business something about an identity document. What stands behind the company holding that data is a separate question entirely. As more decisions pass through digital systems — three payment networks began collaborating this month on one such framework — continued trust needs continued evidence. Bring that question to SIA — the Intelligence Officer.

Every edition, in order, from No. 001 · A new edition releases daily, 05:30 CT.

Open the Record
‹ Edition No. 073 Next Dispatch — releases 05:30 CT ›