A third-party data breach is the kind of incident that happens to your customers because of a company they never chose. In September 2026, the US identity verification firm ID Scan confirmed that hackers had stolen identity data from its cloud systems.
The stolen information includes full names and driving licence numbers, along with identity numbers from other government documents such as passports.
IDScan is not a household name. It is the software that checks and records identity documents at the counter of other businesses: venues, retailers, rental firms and more. That is why this story matters far beyond the United States. Businesses collect, scan and store identity documents every day, very often through third-party tools.
This article explains what happened, why a third-party data breach is so hard to see coming, and six steps to reduce your exposure.
THE IDSCAN BREACH IN NUMBERS
- 150 million+Â driving licence records IDScan’s own materials say it holds (The Paypers)
- 153 million licences a dark web service claimed to be selling access to (KrebsOnSecurity)
- Over a year how long the sellers claimed to have been extracting data (KrebsOnSecurity)
- 400,000Â new records added to the stolen database in a single 24 hours (KrebsOnSecurity)
What Happened in the IDScan Third-Party Data Breach
On or around 1 September 2026, the security journalist Brian Krebs reported that a new dark web service was offering searchable access to scanned driving licences for people in the United States and Canada, including photographs. Krebs confirmed the data was authentic by finding his own record.
The sellers claimed the images came from an active breach at a major identity verification company and boasted that they had been continuously extracting new data for more than a year.
Researchers linked the data to IDScan, a Louisiana-based firm. The FBI opened an investigation. About a week later, IDScan published a notice confirming that hackers had stolen driving licence data from its cloud, its first acknowledgement that it had been breached.
According to reporting by Malwarebytes, the trove advertised by the sellers also included around 10 million ID cards and 3 million travel documents. The investigation is ongoing.
The scale is only part of what makes this third-party data breach significant. The company says it processes more than 21 million identity verification a month across more than 20,000 client locations. A single failure at one vendor therefore splits across hundreds of unrelated brands at once.

Your customers trust you with their identity. If your vendor loses it, they will still hold you responsible.
Why a Third-Party Data Breach Is So Dangerous
A breach of your own systems is bad. A third-party data breach is worse in three specific ways.
You cannot see it happening
If the sellers’ claims are accurate, data was leaving IDScan’s systems for over a year before the public knew. None of IDScan’s customers could have detected that from their side. When your data lives in someone else’s cloud, your visibility depends entirely on their monitoring.
The data is permanent
A third-party data breach involving identity documents is especially damaging. A password can be changed. A driving licence number, a passport number and a photograph of your face cannot.
Identity documents are among the most valuable things a criminal can obtain, because they enable fraud that can follow a victim for years.
One vendor serves many businesses
Specialist vendors concentrate data from thousands of customers in one place. That makes them efficient, and it makes them targets, because one third-party data breach can compromise many clients at once. A single weak point in one supplier becomes a weak point for every business that relies on it.
The Nigerian Angle: KYC Data Is Everywhere
Nigeria’s digital economy runs on identity checks. Banks, fintechs, telecoms operators, lenders, estate managers and employers routinely collect National Identification Numbers, Bank Verification Numbers and images of identity documents, and many rely on third-party verification providers to do it. Every one of those relationships is a potential third-party data breach waiting for the wrong day.
The regulator is paying attention. Under the Nigeria Data Protection Act 2023, organisations must notify the Nigeria Data Protection Commission within 72 hours of becoming aware of a personal data breach that is likely to put people’s rights and freedoms at risk. The maximum penalty for a data controller or processor of major importance is the greater of ₦10 million or 2 per cent of annual gross revenue.
The Commission has shown it will use those powers. It fined MultiChoice Nigeria ₦766.2 million in July 2025 and Fidelity Bank ₦555.8 million in August 2024, and in June 2026 it disclosed that it was probing 1,369 organisations over data breaches. Crucially, outsourcing a process does not outsource the responsibility. If a third-party data breach exposes your customers’ data, regulators will still expect you to show how you protected it.
The UK Picture
The position is similar in the United Kingdom. Under the UK GDPR, organisations must report qualifying personal data breaches to the Information Commissioner’s Office within 72 hours, and controllers are expected to use only processors that provide sufficient guarantees about security, backed by a written contract. A third-party data breach does not move the controller’s obligations onto the supplier.
For businesses operating in both countries, the practical standard is the same: know your vendors, limit what they hold and be ready to act fast.
Steps to Reduce Your Third-Party Data Breach Risk
You cannot control a supplier’s security team. You can control what you give them, what you agree to and how quickly you respond.
- Build a vendor inventory: List every supplier that stores or processes personal data on your behalf, including identity checks, payroll, customer relationship management, cloud storage, marketing tools and messaging platforms. Note what data each one holds and where it is stored. You cannot manage a risk you have not written down.
- Minimise what you collect and keep: Ask whether you or your supplier need to keep a full image of a customer’s identity document once verification is complete. Often, a verification result and a reference number are enough. If you never store the data, thieves cannot steal it.
- Do real due diligence: Before signing, ask how data is encrypted, who can access it, where it is hosted, how long it is retained and what independent security certifications the supplier holds. For higher-risk vendors, repeat the questions every year.
- Put breach terms in writing: Your contract or data processing agreement should require the supplier to notify you of a breach within hours, not weeks, give you the information you need to meet your own 72-hour obligations, and delete your data when the relationship ends.
- Lock down access on your side: Make sure the accounts that connect your systems to suppliers use multi-factor authentication and the minimum permissions they need, and that activity is logged and reviewed. Many cloud incidents start with a stolen credential rather than a sophisticated exploit, and a third-party data breach can begin on your side of the connection just as easily as on theirs.
- Plan your response before the call comes: Write down who does what if a supplier tells you your customers’ data has been exposed: who assesses the risk, who notifies the regulator, who speaks to customers and what they say. Rehearse it once. A third-party data breach will not wait for you to find the right people.
FIVE QUESTIONS TO ASK YOUR IDENTITY VERIFICATION PROVIDER
- Do you store full images of identity documents, and for how long?
- In which countries is our customers’ data hosted and backed up?
- How quickly will you tell us about a suspected breach?
- What independent security certifications do you hold?
- How do you confirm deletion when our contract ends?
Trust Is Only as Strong as Your Weakest Supplier
Nobody who handed over a driving licence at a counter thought they were trusting a company in Louisiana. That is the uncomfortable truth behind every third-party data breach: your customers see your brand, but their information often lives with someone else.
The businesses that come through the next third-party data breach with their reputations intact will be the ones that asked hard questions of their suppliers before anything went wrong.
DO YOU KNOW WHERE YOUR CUSTOMERS’ DATA REALLY LIVES?
Cloud Technology Hub helps organisations map their data flows, assess supplier and cloud security, and build breach response plans that meet NDPA and UK GDPR expectations.
Talk to our team at info@technohub.cloud. TALK
Leave a comment and Read More Here


