What happened

At least four class action lawsuits have been filed in the US District Court for the Eastern District of Louisiana against IDScan.net, the identity verification company at the center of a reported mega-breach of driver's license data. The plaintiffs are seeking damages and asking the court to push the company to improve its internal security posture, according to Infosecurity Magazine.

The suits follow reporting by journalist Brian Krebs, who first documented a dark web service called Nexus advertising more than 153 million driver's licenses, mostly from the US and Canada, alongside over 10 million ID cards, travel documents and medical cards. Nexus went dark shortly after Krebs published, but he tracked activity from his own records to tie the trove to New Orleans based IDScan.net. The FBI said last week it is investigating the incident, and IDScan.net says it is looking into the matter.

Two other major firms, Hall Attorneys and Markovits, Stock & DeMarco, are now investigating claims from potential victims. IDScan.net sells B2B verification services to customers including rental car giant Hertz, FedEx and hundreds of cannabis dispensaries across the US, which is why a single compromise could concentrate exposure for so many people.

Why this is a GRC story

This is what third-party risk looks like when it becomes someone else's litigation docket. A vendor that sits inside the onboarding flow of thousands of businesses now faces four lawsuits demanding not just money but changes to its security program. That is the mechanism by which a data incident becomes a governance requirement, without a regulator ever issuing an order.

The case also raises a gap in how we protect identity data. Black Hills Information Security owner John Strand told Infosecurity Magazine the sheer volume of data brokers collect and store is staggering, and argued this class of data may need protections similar to protected health information, possibly through HIPAA-like rules or a framework that treats large personal data collections with the same seriousness.

For companies that collect identity documents, the practical questions are about retention and deletion: how long scans are kept after a verification, whether contracts require data minimization, and whether the vendor can be audited. Those clauses look like fine print until a breach like this turns them into legal exposure for everyone downstream.

What to watch

Watch whether the number of filings grows, whether the FBI confirms the source breach, and whether IDScan.net's business customers start triggering breach notification obligations of their own. The law firms are already telling potential victims to ask which provider scanned their ID, whether front and back images or infrared captures were retained, and whether their record sits inside the incident review. Treat unsolicited breach-check links as suspicious, they warn. That advice is worth keeping in mind regardless of how this litigation lands.

Attribution: Analysis based on Infosecurity Magazine's reporting and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News