153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story
153 Million Driver's License Scans Just Turned Up for Sale. If Your Business Ever Checks a Customer's ID, This Is Your Vendor Risk Story.
This week, a database of more than 170 million scanned identity documents — driver's licenses, ID cards, travel documents — surfaced for sale, reportedly traced to a single identity-verification company whose scanning equipment sits behind the counter at car rental desks, hotels, casinos, and age-restricted retailers across North America. The company hasn't confirmed the breach. The FBI has opened an investigation. But the part of this story that matters most for small businesses isn't who got breached — it's a gap in the rules that most businesses scanning a customer's ID have never thought to ask about.
Late last week, researchers investigating a dark-web identity-theft marketplace found something unusually large: a database advertising more than 170 million scanned identity documents belonging to people across North America. Investigative security reporting has traced the likely source to a single identity-verification company whose scanning terminals process ID checks at car rental counters, hotels, casinos, shipping and logistics counters, retailers, and age-restricted point-of-sale locations across the country. The company has not confirmed unauthorized access, and the exact origin of the data has not been conclusively established as of this writing. The FBI has opened a formal investigation.
We're deliberately not naming the company here, for the same reason we don't name victims elsewhere in this series: the facts are still developing, nothing has been formally confirmed, and the lesson for your business has nothing to do with which specific company this turns out to be. It has to do with a pattern that almost certainly extends far beyond this one case.
scanned identity documents were found for sale in a single database — the vast majority US and Canadian driver's licenses
The breakdown reported: more than 153 million driver's licenses, over 10 million other identity cards, roughly 3 million travel documents, and nearly 579,000 medical or dispensary cards. This isn't a list of email addresses and passwords. It's scanned images of the physical documents governments issue to prove who you are — the kind of record that gets created every time someone hands their ID across a counter to be checked.
Why this is a different kind of breach than the ones you've read about
What makes this exposure especially serious is what the scans reportedly include. Beyond a simple front-facing photo, records apparently contain front-and-back images captured under three different lighting conditions: ordinary visible light, infrared, and ultraviolet. That multi-spectrum capture isn't incidental — it's the same verification method banks, government agencies, and border checkpoints use specifically to confirm a document is genuine rather than a convincing forgery. State-issued IDs embed security features — invisible ink patterns, layered printing, fluorescent markings — that only reveal themselves under infrared or ultraviolet light.
The regulatory gap almost nobody knows exists
Here's the part of this story most coverage has missed, and it's the one every small business should actually take away from it. Payment card processors are legally barred from storing your raw credit card number once a transaction is complete — that's a well-known, strictly enforced rule. No equivalent rule exists for companies that scan and verify identity documents. There is no federal standard requiring an ID-verification vendor to delete the images it captures once it has confirmed your identity.
That gap is reportedly exactly what created the exposure in this case: a company processing many millions of verifications a month, at tens of thousands of locations, apparently retained the underlying scans rather than discarding them after each check — turning an ordinary verification process into an enormous, standing archive of government identity documents. Nothing about that retention was necessarily illegal. It simply wasn't required to stop.
Where this touches your business, even if you've never heard of the vendor involved
You don't need to run a car rental counter to have exposure here. Any business that checks a government-issued ID as part of its normal operations is a potential link in exactly this kind of chain — and most never think to ask what happens to the scan after the check is done.
Every one of these business types typically doesn't build ID-scanning technology itself — it licenses a third-party service or device to do it, exactly the arrangement reportedly at the center of this incident. If your business or point-of-sale system uses a third-party ID scanner or verification API, your customers' data may be sitting in a vendor's database you've never had reason to think about, governed by retention rules that may be looser than you'd assume.
Three questions to ask if your business checks IDs
Does your ID-verification vendor delete scans after checking them?
Ask this weekIf you use a third-party scanner, app, or terminal to check IDs — for age verification, rentals, check-in, or onboarding — ask the provider directly whether the scanned image is discarded once the check is complete, or retained, and for how long. "We only verify, we don't keep it" is the answer you want. If the vendor can't answer clearly, that's the answer.
If scans are retained, ask why — and whether you can opt out
Vendor conversationSome retention may be for legitimate reasons — fraud prevention, compliance in specific regulated industries like cannabis retail. Others simply never turned deletion on. Either way, you're entitled to ask, and a vendor with a genuine reason should be able to explain it rather than shrug.
Add data retention to your vendor risk list — it's usually missing entirely
ProcessOur earlier post on vendor questions focused on access and credentials — who can reach your systems, and for how long. Retention is the companion question: not just who can get in, but how much of your customers' sensitive information a vendor is quietly sitting on, indefinitely, whether or not it's still needed.
The short version
A very large amount of scanned identity data reportedly surfaced this week, apparently traced to one vendor among many that businesses across the country rely on to check a customer's ID. The company involved hasn't been confirmed, and may not be the last. What's certain is the gap underneath it: nothing requires an identity-verification company to delete the images it captures once it's done verifying them, and most businesses using these services have never thought to ask whether their vendor does. If your business ever scans an ID, this week is a reasonable time to find out.
Know what your vendors are actually holding — not just whether they can be breached.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series → Read the full series

Comments
Post a Comment