IDScan breach exposes the risk inside identity verification
A major breach at IDScan highlights how identity-verification providers can become concentrated stores of highly sensitive data.

Identity verification reduces fraud, but it also creates valuable centralised collections of documents attackers want to steal.
What happened
IDScan confirmed that hackers accessed cloud systems containing driver’s-licence and other government-ID information. A database examined independently was reported to contain records tied to more than 150 million people in the US and Canada.
Why it matters
Identity-verification providers sit in an unusually sensitive part of the technology stack. A breach can expose information that is far harder to replace than a password.
The bigger picture
As more services outsource KYC and identity checks, security risk is becoming concentrated in specialist vendors. The infrastructure that proves who users are is becoming a critical attack surface in its own right.
