Your identity-check vendor just became a 153-million-record archive you never inventoried.

That is the cybersecurity story this week, and it lives in a vendor cloud your edge never sees.

IDScan.net confirmed that attackers reached customer data stored on its cloud platform after reports tied the firm to a dark web database holding more than 153 million driver’s license scans. The Louisiana company processes ID checks for car rental desks, retailers, and cannabis dispensaries. Those buyers paid for a glance at a card. They also created a durable copy of government ID images in a vendor tenant they don’t operate, don’t patch, and don’t page at 2 a.m.

A dispensary that scans a license to keep a regulator happy just replicated that license into a multi-tenant cloud with a different threat model, a different patch calendar, and a different lawyer. You inherited that model when you signed the vendor.

Illustration of a data leak used in coverage of the IDScan.net driver's license breach
IDScan.net confirmed a cloud breach after a dark web dump of license scans.

License scans outlive the checkout

An ID check feels ephemeral. The clerk looks, the gate opens, the session ends. The vendor’s job is to persist the evidence so a later dispute or chargeback has a file. That file is the product. It is also the loot.

You already run threat detection on the store network. You already rate-limit brute-force noise against the POS and the VPN. None of that inspects a SaaS archive of scanned licenses sitting in another company’s cloud. Defense in depth that stops at your firewall is a map of your buildings. The license archive lives off that map.

This is a bad look for any industry that treated ID verification as a compliance checkbox instead of a data-processing relationship with a blast radius measured in millions of government documents.

If you send a driver’s license image to a third party, you inherit two incident response clocks the day they get hit. Yours includes customer notice, regulator timelines, and the ugly fact that you can’t rotate a license number the way you rotate a password.

Treat that vendor like a domain controller that happens to live offsite.

Cybersecurity hardening starts with the copies

Stop arguing about whose SOC owns the ticket.

Own the data path.

You need a short list of every vendor that stores ID images, KYC packets, or temporary scan backups. Then you need proof of where those files live, who can export them, and how long they survive after the customer walks out. Cyber security teams that skip this inventory are writing playbooks for a breach they’ll learn about from a reporter.

  • Immediate: inventory ID-image and KYC processors; pull the DPA; demand region, retention, export, and subprocessor lists in writing this week.
  • Immediate: pull unused staging hosts and self-hosted artifact servers off the public internet, patch them on your identity-provider cadence, require SSO into ID vendors, and confirm a named incident contact who will call you.
  • Ongoing: minimize what you send. Store a verification token or last-four plus a hash where the law allows, and set deletion SLAs with evidence you can show an auditor.
  • Ongoing: tabletop a vendor-cloud dump in your incident response plan, including customer notice language for data you never held locally. Fold threat-protection and access reviews for those admin paths into the same quarterly cycle you already run for VPN and email.

Security hardening here is boring on purpose. Retention limits. Named owners. Proof of deletion. If a vendor can’t answer those in a day, they’re holding production without production controls.

Test boxes and repos finish the job

The same pattern showed up twice more this week, just without a pile of driver’s licenses to make it obvious.

Surfshark says threat actors reached a misconfigured test server that held engineering material, including internal configurations. Test is a label you print on a ticket. Attackers read it as an unlocked copy of how you actually run the network.

VPN lock graphic accompanying coverage of Surfshark's compromised test server
A misconfigured test host with engineering configs is a production leak with extra steps.

A VPN company’s staging host leaking internal configs is the same class of miss as an ID vendor’s cloud dump. The brand on the login page does not change the physics.

Wiz tracked attackers chaining two flaws in self-hosted JFrog Artifactory between August 15 and September 8, taking administrator control and planting backdoors in the repository that build pipelines pull from.

JFrog had already shipped fixes.

The open servers were the ones nobody updated.

Once they have admin on the repo, they can swap a package your pipeline already trusts. Threat detection on the laptop then sees a signed internal artifact. The backdoor arrived with your build.

JFrog Artifactory interface illustrating the repository attackers used to plant backdoors
Unpatched Artifactory hosts gave attackers admin and a place to plant build-pipeline backdoors.

Your artifact repo is another offsite original. It stores the canonical copies of what production will run. Admin on that box is admin on every downstream build. A firewall in front of Artifactory still leaves a known-vulnerable version reachable.

The copies you forget, the staging host you meant to kill, and the repo you patched last quarter are the estate. Inventory them like production, or read about them like IDScan’s customers are reading this week.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.