Table of Contents

Free Active Directory Auditing Tool

Try it now
idscan breach

IDScan Breach: The Risk to Organizations

Table of Contents

More than 153 million driver license records have been exposed on the dark web, linked to a breach of ID verification service IDScan. Details about exactly how the attackers got in, and who was ultimately responsible, remain limited. However, the risk to organizations is immediate.

The problem is that possessing identity information is not the same as proving identity. Once a genuine ID image has been stolen, an attacker can present the same information as its legitimate owner.

That matters anywhere identity is used to recover access, particularly service desk password and MFA resets, account recovery and onboarding new starters. The IDScan breach therefore becomes a test of the identity controls organizations have in place. If stolen identity data is enough to pass them, those controls need another layer.

What We Know About the IDScan Breach

The breach was first reported by security journalist Brian Krebs, who said a new service had launched selling digital scans of ID documents from people in the US and Canada. The data appeared for sale through Nexus, a service that claimed to have exfiltrated the data for over a year. According to Nexus, the data includes:

  • Drivers’ licenses
  • Identification cards
  • Travel documents
  • International IDs
  • Medical cards
  • Common access cards
  • Residence cards
  • Employment authorization documents

Some of the records reportedly included images of both the front and back of licenses, as well as infrared and ultraviolet scans. Researchers were able to match timestamps on genuine records with occasions when individuals had presented their IDs for verification, helping trace at least some of the exposed data back to IDScan.

IDScan has since acknowledged that customer information stored within customer accounts in its cloud environment may have been accessed and copied without authorization. The ID verification giant has not disclosed how the environment was initially compromised, and attribution remains unclear. The FBI also announced an investigation into the leaked data.

What’s the Risk to Organizations?

A stolen ID gives an attacker a credible set of personal details and images of the document itself. If an organization relies on that information to verify someone’s identity, it gives the attacker more convincing material for social engineering and impersonation attempts.

Service Desk and Account Recovery Fraud

When the usual authentication factors are unavailable, service desks still need to establish someone’s identity. If that process depends on information such as a name, date of birth, address, or a photo of an ID, leaked identity data can make an attacker’s attempt much more convincing.

The attacker does not need to defeat MFA directly if they can persuade a support agent to reset it. In that situation, the recovery process becomes the weakest part of the authentication chain.

More Convincing Employee Impersonation

A criminal pretending to be an employee can use genuine personal information to answer questions or provide a copy of a real ID when challenged. That can add credibility to social engineering attacks aimed at IT teams, HR, finance, or other internal functions.

The risk is greater when employees are under pressure to resolve a problem quickly. A caller who knows the right personal details and can produce a matching identity document may appear legitimate, particularly if the verification process is designed to check what someone knows or possesses rather than prove who they are.

The same principle applies to deepfake-enabled attacks. A convincing voice or video can strengthen the impersonation, but the underlying weakness is still the same: relying on information or images that can be copied and replayed.

Customer and Third-Party Identity Fraud

Organizations that use identity documents during customer onboarding, account recovery, or supplier verification may also be exposed if their checks accept an uploaded image as proof of identity.

A genuine stolen license can contain everything an attacker needs to complete basic identity checks. If the process only compares the submitted details with the image on the document, there may be little to distinguish the legitimate owner from someone using their stolen data.

Help your service desk verify user identities, enforce user authentication, securely unlock accounts, and reset passwords

What Can Organizations Do Now?

The practical response is to assume that static identity information may already be in an attacker’s hands. That information should not be treated as strong proof of identity on its own.

Organizations should focus on the points where identity checks matter most, particularly password resets, account recovery and any process that relies on someone presenting an identity document.

Require More Than a Photo of an ID

Where organizations do need to verify government-issued identity documents, they should treat a photograph as one part of the process rather than the final proof. A stronger check looks at whether the document itself is genuine and should then establish that the person presenting the document is both live and matches the person shown on it.

Specops Verified ID combines document verification with biometric liveness scanning. AI-driven analysis of real-time facial movements and depth cues confirm physical presence, blocking fraudulent attempts using photos or videos.

Verified ID also scans government documents to confirm their authenticity and compares attributes against the user’s Active Directory or Entra ID record. Importantly, Verified ID doesn’t store data like driving license images, so isn’t vulnerable to an incident like the IDScan breach.

Strengthen Service Desk Verification

Service desks are a natural target for social engineering because they are designed to help people who cannot use their normal authentication methods.

That makes it important to avoid verification processes based solely on information an attacker could know or obtain. Asking a name, date of birth or photograph of a driver’s license may confirm that the caller has access to those details, but it does not confirm that they are the person they claim to be.

Specops Secure Service Desk enforces verification factors that cannot be answered using leaked identity data alone. Agents can use any combination of more than 15 MFA factors to support any user type and ensure anyone, whether they have a mobile device or not, can be securely verified at the service desk. This closes off common social engineering tactics while minimizing lockout times for genuine users.

For particularly sensitive actions, such as during onboarding and during key recovery processes, Specops Secure Service Desk with the Verified ID add on delivers the highest level of assurance for verification.

Secure Your Identities with Specops

While identity data can help establish who someone claims to be, possession of that data does not prove they are that person. Organizations need verification controls that still work when even genuine ID documents are already in an attacker’s hands.

Specops provides that assurance through solutions that add stronger verification methods that don’t rely on static identity information alone. To see how Specops can help protect your organization against identity-based attacks, book a demo today.

Last updated on September 11, 2026

darren james

Written by

Darren James

Darren James is a Senior Product Manager at Specops Software, an Outpost24 company. Darren is a seasoned cybersecurity professional with more than 20 years of experience in the IT industry. He has worked as a consultant across various organizations and sectors, including central and local governments, retail and energy. His areas of specialization include identity and access management, Active Directory, and Azure AD. Darren has been with Specops Software for more than 12 years and brings his expertise to the support and development of world-class password security and authentication solutions. 

Back to Blog

Related Articles


Free Active Directory Auditing Tool!