153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story


Breaking
Vendor Risk
September 2026  ·  7 min read

153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story.

This week, a database of more than 170 million scanned identity documents — driver's licenses, ID cards, travel documents — surfaced for sale, reportedly traced to a single identity-verification company whose scanning equipment sits behind the counter at car rental desks, hotels, casinos, and age-restricted retailers across North America. The company hasn't confirmed the breach. The FBI has opened an investigation. But the part of this story that matters most for small businesses isn't who got breached — it's a gap in the rules that most businesses scanning a customer's ID have never thought to ask about.


Late last week, researchers investigating a dark-web identity-theft marketplace found something unusually large: a database advertising more than 170 million scanned identity documents belonging to people across North America. Investigative security reporting has traced the likely source to a single identity-verification company whose scanning terminals process ID checks at car rental counters, hotels, casinos, shipping and logistics counters, retailers, and age-restricted point-of-sale locations across the country. The company has not confirmed unauthorized access, and the exact origin of the data has not been conclusively established as of this writing. The FBI has opened a formal investigation.

We're deliberately not naming the company here, for the same reason we don't name victims elsewhere in this series: the facts are still developing, nothing has been formally confirmed, and the lesson for your business has nothing to do with which specific company this turns out to be. It has to do with a pattern that almost certainly extends far beyond this one case.

170M+

scanned identity documents were found for sale in a single database — the vast majority US and Canadian driver's licenses

The breakdown reported: more than 153 million driver's licenses, over 10 million other identity cards, roughly 3 million travel documents, and nearly 579,000 medical or dispensary cards. This isn't a list of email addresses and passwords. It's scanned images of the physical documents governments issue to prove who you are — the kind of record that gets created every time someone hands their ID across a counter to be checked.

Why this is a different kind of breach than the ones you've read about

What makes this exposure especially serious is what the scans reportedly include. Beyond a simple front-facing photo, records apparently contain front-and-back images captured under three different lighting conditions: ordinary visible light, infrared, and ultraviolet. That multi-spectrum capture isn't incidental — it's the same verification method banks, government agencies, and border checkpoints use specifically to confirm a document is genuine rather than a convincing forgery. State-issued IDs embed security features — invisible ink patterns, layered printing, fluorescent markings — that only reveal themselves under infrared or ultraviolet light.

This is the detail that changes the calculation. A stolen password is inconvenient; you reset it and move on. A driver's license number, photo, and address are already hard to change. But leaked infrared and ultraviolet captures of a genuine ID go a step further: they give a forger the exact reference data needed to reproduce the hidden security features that verification systems check for. In principle, that's enough to help defeat the very method used to catch fake IDs — at a bank, a rental counter, or anywhere else that scans a license expecting the scan itself to prove authenticity.

The regulatory gap almost nobody knows exists

Here's the part of this story most coverage has missed, and it's the one every small business should actually take away from it. Payment card processors are legally barred from storing your raw credit card number once a transaction is complete — that's a well-known, strictly enforced rule. No equivalent rule exists for companies that scan and verify identity documents. There is no federal standard requiring an ID-verification vendor to delete the images it captures once it has confirmed your identity.

That gap is reportedly exactly what created the exposure in this case: a company processing many millions of verifications a month, at tens of thousands of locations, apparently retained the underlying scans rather than discarding them after each check — turning an ordinary verification process into an enormous, standing archive of government identity documents. Nothing about that retention was necessarily illegal. It simply wasn't required to stop.

Where this touches your business, even if you've never heard of the vendor involved

You don't need to run a car rental counter to have exposure here. Any business that checks a government-issued ID as part of its normal operations is a potential link in exactly this kind of chain — and most never think to ask what happens to the scan after the check is done.

Businesses that routinely scan a customer's ID
Bars, restaurants, and retailers checking age for alcohol, tobacco, or cannabis sales
Car and equipment rental businesses
Hotels, short-term rentals, and property managers at check-in
Staffing agencies and employers verifying identity during onboarding
Delivery, courier, and logistics businesses confirming recipient identity
Landlords and property managers screening prospective tenants

Every one of these business types typically doesn't build ID-scanning technology itself — it licenses a third-party service or device to do it, exactly the arrangement reportedly at the center of this incident. If your business or point-of-sale system uses a third-party ID scanner or verification API, your customers' data may be sitting in a vendor's database you've never had reason to think about, governed by retention rules that may be looser than you'd assume.

21M+ monthly identity verifications reportedly processed by the vendor at the center of this incident — a scale that turns a routine service into a concentrated, high-value target Reported vendor disclosures, 2026
0 federal requirements mandating that ID-verification companies delete scanned document images after verifying them — unlike the strict rule that applies to raw card numbers PCI DSS standard vs. no ID-scan equivalent
Not resettable a driver's license, unlike a password, can't simply be changed — the exposure of a person's identity document is effectively permanent General identity-theft risk analysis

Three questions to ask if your business checks IDs

1

Does your ID-verification vendor delete scans after checking them?

Ask this week

If you use a third-party scanner, app, or terminal to check IDs — for age verification, rentals, check-in, or onboarding — ask the provider directly whether the scanned image is discarded once the check is complete, or retained, and for how long. "We only verify, we don't keep it" is the answer you want. If the vendor can't answer clearly, that's the answer.

2

If scans are retained, ask why — and whether you can opt out

Vendor conversation

Some retention may be for legitimate reasons — fraud prevention, compliance in specific regulated industries like cannabis retail. Others simply never turned deletion on. Either way, you're entitled to ask, and a vendor with a genuine reason should be able to explain it rather than shrug.

3

Add data retention to your vendor risk list — it's usually missing entirely

Process

Our earlier post on vendor questions focused on access and credentials — who can reach your systems, and for how long. Retention is the companion question: not just who can get in, but how much of your customers' sensitive information a vendor is quietly sitting on, indefinitely, whether or not it's still needed.

The uncomfortable pattern connecting this story to several others in this series: a business does the responsible thing — verifying identity, checking age, confirming who someone is — by handing that responsibility to a specialist vendor. The vendor does its job correctly, the transaction completes, and the sensitive data involved simply never leaves. Not because anyone intended it to sit there forever. Because nothing required it not to.
This is exactly the category of exposure the Veriti Spottr CyberScore's vendor and third-party risk assessment is built to surface — not just whether a vendor can be breached, but how much of your customers' sensitive data they're actually holding, and for how long. A vendor relationship that felt like a simple service can quietly become a standing liability if nobody ever asks what happens to the data after the transaction ends.

The short version

A very large amount of scanned identity data reportedly surfaced this week, apparently traced to one vendor among many that businesses across the country rely on to check a customer's ID. The company involved hasn't been confirmed, and may not be the last. What's certain is the gap underneath it: nothing requires an identity-verification company to delete the images it captures once it's done verifying them, and most businesses using these services have never thought to ask whether their vendor does. If your business ever scans an ID, this week is a reasonable time to find out.

Know what your vendors are actually holding — not just whether they can be breached.

View the Threat Intelligence feed → Find Out More About Veriti Spottr →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.