A Rant On ID Scanning, Lax Privacy Protections, and Big Targets
<rant>
Yes, this will be an angry rant written by - as coined by Mark Twain - A Pen Warmed Up In Hell. I'll keep my language mostly fraking respectable, but I'm angry, and sick of this feldercarb. (translations not required if you're a Battlestar Galactica fan)
In the Before Times...
Once upon a time, let's call it the 20th century, if you wanted to perform an activity that required validation of your identity, this was a matter of copying down letters and numbers from a card you carried onto a form, usually via a pen or typewriter, but eventually evolving into doing so via a computer interface. Other situations called for a burly person standing in front of a door to insist on physically inspecting your ID card to determine if you really were 21 or just had a printer and laminating machine at home.
So if you were, say, renting a car, entering a bar, buying a house, or even visiting your doctor there might be a short pause while you or an employee of the place you were visiting was inspecting your card.
Generally, that information was then filed away, either on paper in a cabinet or possibly through some computer system that was owned and managed by the company you were interacting with.
But These Days...
Today even the bar bouncer has an ID scanner that is cloud connected. You buy beer at the local mega-mart and they scan your license. Your data is not simply being stored locally, it's being uploaded to one of a few service providers who offer validation services and "confirm" your ID once they've got a digital copy of your ID card (driver's license, state ID, military ID, passport, etc.)
Behold, the kind of reader you might see at TSA, the rental car company, or even your local watering hole.That means that identity thieves have an opportunity to score big in one hit. It means that identity breaches aren't limited to the "200 people" who rented a car from the rental office on Main Street in August, but to the 150M people who's ID scans were sent to and stored by one of these companies. And no, that isn't hyperbole.
Brian Krebs Breaks the Story - September 1, 2026
FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on SecurityKrebs on Security - a fantastic resource
I encourage you to stop right here and read his reporting on this. For those who don't, here's the TLDR:
A brand new illegal identity broker showed up on the "darkweb" the last week of August offering to sell digital scans of ID cards - more than 153M driver's licenses along with millions of other ID cards from US and Canada. After some digging, Krebs was able to not only confirm the authenticity of the data (his license was in the database) but was able to identify the likely source of the leak: IDScan. Finally, he identified that the breach had data that seemed to have been collected over the course of about a year, and even identified Hertz car rental company as one of the likely sources of the ID scans. He leads, of course, with the fact that (oddly enough) on the same day he's publishing the FBI is announcing an investigation.
So what makes me so angry about this? For one thing, losing 153 Million driver's licenses from the US and Canada.
Let's do some math: published population for the US is 341M, and 41M in Canada, for a total of 382M people. The number of people with drivers licenses in the US is 238M and 26M in Canada, for a total of 264M people with licenses. That seems to say that this one company lost the data of 58% of drivers in that combined population. That's nearly 6 out of every 10 of us with drivers licenses whose data seems to have been leaked. That's also about 40% of the total population of the combined US and Canada, just from driver's licenses alone. (these numbers were AI sourced, so feel free to check my stats)
So congratulations! You have a really high chance of having been impacted by this. No, don't look around, I really mean you.
In the second, why are companies like this allowed to be clearing houses for digital scans of our IDs? How do they not face stiffer regulation because of the sensitive nature of the data they're aggregating? Why didn't I get to know who had copies of my driver's licensee until I read about it on Krebs' blog? Well, that's because we have some of the world's most lax privacy laws. Yes, the Bill of Rights is pretty explicit about what the government can and cannot do to track you and such, but it is absolutely silent on what private companies can do, which is why so much rides on electing folks who are committed to fixing this situation.
But that was last week...
Fast Forward To Today, September 10, 2026
Today everybody has the news story that, IDScan has now confirmed they had a breach.
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen | TechCrunchThe ID checking company said the data breach included people’s full names and driver’s licenses and other government-issued identity documents.The company's online statement - they're minimizing.
Again, doing the math, that's 9 days after Krebs broke his story and the FBI started their investigation of a breach that clearly lasted about a year.
It seems to me that a company storing this sort of data being breached for a year and not realizing it until a journalist prompts the FBI to investigate you should qualify as gross negligence.
Yup, I used those words. (I told you where my pen was warmed up earlier) Look, you don't become a large ID scanning company without having some lawyer along the way point out to you that you're storing really sensitive information, and you should be taking extra care to protect that data, or a CISO telling you the same thing from their perspective, or even your prospects and customers bringing that idea up. You don't get to pretend that "you weren't a target," or "you had no idea that anybody would attack you" or "but our pen-test from last year showed no problems." We're not talking about a local restaurant whose home-built loyalty program got hacked, this is a company whose stock and trade is dealing in sensitive identity information - and seems to have had it on about 40% of the people residing in the US and Canada!
Normally I'm not a "blame the victim" person, and indeed IDScan was a victim here. But I'll also argue that their business model made all of us (well, at least 40% of us) victims without our knowledge or consent. And that makes them perpetrators.
This is the worst-case reminder that whenever you share your data with anyone you're sharing it with all the other people they choose to share it with: when Hertz scans your driver's license as part of your rental they're sharing that digital image with this compromised company. (They're not the only ones of course, but they were singled out by Mr. Krebs) You have no say over who they share what with, normally you can't even "opt out," of the sharing.
This kind of a breach is exactly why many of us don't believe age validation laws are a good means of protecting children online - they create this exact scenario. The evidence is right in front of us.
If any breach in the past 24 months deserves criminal charges, this one does, in my not-so-humble opinion. Though as I am not a lawyer I'm not sure there's really any existing laws that would allow prosecution, so this one is likely to go where all of these do: a class-action lawsuit that gets virtually no relief to the actual victims.
In Spite of My Rage...
Look, I've been in this industry for most of my adult life. I've seen companies of all sizes take security for granted, and I've seen them take it seriously. But this sort of story just makes my blood boil. It has it all:
- A big treasure trove of personal information about individuals who have no visibility or consent to their data being part of the pool
- A company that has been grossly negligent about how they've secured that very sensitive data.
- Government that has yet to legislate useful consumer protections for this sort of scenario.
- A company that will end up settling a class action lawsuit and continue on essentially as before.
We can, and must, do better. Better legislation. Better accountability. Better privacy.
</rant>
🦣You can follow Between To Firewalls on Mastodon, Threads, BlueSky and other Fediverse connected solutions. Connect with us on those apps with this handle: @posts@between-two-firewalls.com