Auditen
practitioner note

153 Million Identity Records Leaked in IDScan Breach

If you’ve outsourced your identity verification to a third party to "lower your risk profile," I have some bad news. You haven't removed the risk; you've just moved it to a different server and lost the ability to see when it’s on fire.

The recent IDScan breach, which exposed north of 150 million identity records, is a disaster. But there's something worse: another verification firm that let hackers maintain a live feed of every ID scanned for over a year. Think about that. For twelve months, someone was watching passports and driver's licenses roll in like a ticker tape.

Small firms love this "compliance as a service" model. It feels clean. You send the customer to a portal, the vendor tells you "Yes, they are who they say they are," and you check a box. The assumption is that the vendor handles the security, so you're off the hook. That’s not how regulators see it. If you choose a vendor that leaves the back door open for a year, you're the one who picked the lock.

The cost of getting this wrong isn't just theoretical. Look at the Health Service Executive in Ireland, which just got hit with a fine of just under 650,000 Euros. Or Hôpital Privé de la Loire in France, paying half a million Euros to CNIL. The common thread isn't necessarily fancy hacking; it's basic failure in how data is held and protected.

The biggest lie in compliance is the idea that you can "simply implement" a vendor solution to solve a legal problem. You can't. When you plug your customer data into an AI gateway or an ID verification tool, you aren't deleting your responsibility; you're just extending your perimeter to include someone else's mistakes.

You might argue that a small firm doesn't have the leverage to audit a giant vendor. You can't send a team of auditors to their data center. That’s true. But most firms don't even do the bare minimum, like checking if the vendor’s SOC 2 report actually covers the specific service you're using or if it's just a general "we have a firewall" certificate.

The second-order effect here will be insurance. When these massive breaches hit the news, cyber insurers don't just raise rates across the board; they start asking specific questions about your supply chain. If you can't prove you’ve monitored your vendors, your premiums will spike or your coverage for third-party failures will vanish. You'll be paying for a policy that doesn't cover the one thing most likely to break.

If you're running a lean operation, you don't need an expensive GRC tool to fix this. You need a brutal pruning of what you actually keep.

The cheapest control is not keeping data in the first place. If your vendor verifies an ID, why are you still holding a copy of that scan on your own internal drive? Why is it sitting in an email thread or a "customer onboarding" folder? Every single PDF of a passport you store is a liability waiting for a bad day.

Once the verification is done, delete the evidence. Keep the timestamp and the "Verified" status. That’s all the auditor needs to see to know you followed the process. They don't need to see the customer's actual driver's license from three years ago.

Then, look at your AI tools. There's a trend of using AI notetakers in professional meetings. These are essentially data vacuum cleaners. They record everything and store it on servers you don't control. If you're discussing client PII or sensitive financial figures, those tools are turning your meetings into a public record for whoever manages the AI's training set.

Stop using them for anything that isn't a generic internal brainstorm. It’s a free change that removes a massive amount of risk.

I suspect we're heading toward a world where "justification" is the new standard. Australia is already moving in this direction with laws slated for 2026 that will force companies to justify every single use of data. The era of "we collect this just in case it's useful" is ending. If you can't explain why you have a piece of data and how it’s protected, you shouldn't have it.

The mistake most people make is thinking compliance is about adding layers—more software, more policies, more certifications. It's actually about subtraction. The less you hold, the less there is to leak.

If you want to be safe on a budget, stop trying to build a fortress around your data and just start throwing the data away.

Check every folder named "KYC," "Onboarding," or "IDs" this week. Delete any scan older than 30 days that has already been verified.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year. - Techdirt. Data Privacy (Google News)
  2. HSE fined €645,000 over data breaches - The Law Society of Ireland Data Privacy (Google News)
  3. SEC’s Accounting Unit Seen as Core Fraud Enforcement Engine - news.bloombergtax.com Compliance Week (Google News)
  4. Bank Financial Disclosures: Actions Needed to Improve Oversight of Information Provided to Investors - U.S. Government Accountability Office (.gov) Compliance Week (Google News)
  5. Over 5,000 Dropbox Accounts Compromised In Targeted Breach - Ubergizmo Data Privacy (Google News)
  6. Health data breach: EUR 500,000 fine against HÔPITAL PRIVÉ DE LA LOIRE - CNIL Data Privacy (Google News)
  7. Tving Data Breach Compromises 39.5 Million Accounts, Probe Finds - streamlinefeed.co.ke Data Privacy (Google News)
  8. Australia Privacy Law 2026: World-First Test Forces Companies to Justify Every Data Use - techtimes.com Data Privacy (Google News)

How stories are selected and assessed