Somewhere in this country there is a finance manager who has never logged into IDScan.net, could not tell you what VeriScan is, and may have had a federal reporting clock start ticking on September 1.
That is the part of the IDScan data breach that will not appear in anybody’s press release.
On September 4, IDScan.net confirmed a data security incident, and the notice now sits behind a banner on the company’s homepage. It follows a week of reporting by security journalist Brian Krebs, who traced a dark web listing offering scans of more than 153 million U.S. and Canadian driver’s licenses back to the Louisiana identity-verification firm, and who reported that the FBI’s New Orleans field office had opened an investigation. We covered the rental-counter trail and the dealership side of it when the story surfaced.
The notice itself is short. The most consequential phrase in it is easy to skim past. IDScan says an unauthorized third party may have accessed or copied customer information “stored within their accounts on the IDScan.net cloud.”
Stored within their accounts.
That is not evasion. It is a roughly accurate description of how this business is structured — and of who federal law is going to look at first.
The Dealer Is The Financial Institution. The Vendor Is Not.
A dealership that arranges financing, or leases vehicles for longer than 90 days, is a financial institution under the Gramm-Leach-Bliley Act. Not figuratively. The FTC says so directly: the definition turns on what a business does, not on what it calls itself. That is what pulls new-car stores under the Safeguards Rule alongside mortgage brokers and payday lenders.
The rule does two things that matter this month.
First, it makes the dealer answerable for its vendors. A financial institution must select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess the provider. Buying the scanner does not outsource the duty. It creates one.
Second — and this is the provision most showroom managers have never had occasion to use — since May 2024 the rule has required a financial institution to notify the FTC of a notification event involving the unencrypted information of at least 500 consumers, as soon as possible and no later than 30 days after discovery.
IDScan says it identified the problem on or around September 1.
Do the arithmetic.
That obligation runs to financial institutions. In this arrangement, IDScan is the service provider. Which means the entity that fills out the form is not the company that lost the data. It is the dealership whose customers’ records were sitting in the account.
And here is the detail that should make a dealer principal sit up straight. The FTC’s security event reporting form warns that the report may be made public. There is a checkbox for requesting a delay when law enforcement asks for one. There is no checkbox for “our vendor already put out a statement.”
Whether any individual store clears the 500-consumer threshold is precisely the question dealers need answered right now, and it belongs to their counsel and their vendor rather than to a columnist. But the clock does not pause while the answer gets convenient.
Twelve Fields Go In. Two Came Out In The Notice.
IDScan describes the exposed data as full names and driver’s license or other government-issued identification numbers.
That is a narrower description than what a scanner actually ingests.
Every U.S. license carries a PDF417 barcode on the back, and its contents are not up to the dealership or the vendor. They are fixed by the AAMVA DL/ID Card Design Standard, the specification every state DMV builds to. Under the current version, the mandatory encoded elements include family name, given names, date of birth, date of issue, date of expiry, the customer identifier, the document discriminator, the cardholder’s address, sex, height, eye color and issuing jurisdiction. Hair color, weight and place of birth sit on the optional list that states may add.
Twelve mandatory fields. Your home address among them.
The document discriminator deserves a moment, because it is the element almost nobody notices and the one that makes ID scanning work at all. It is a number that distinguishes one particular card issued to you from every earlier card you have held, so an issuer can tell a live credential from a replaced one. It is also the detail a forger most often gets wrong — which is exactly what makes a real one valuable to the next forger.
A scanned license is not a photocopy. It is a structured database record.
The Delete Button Was There The Whole Time
Now read IDScan’s own page for car dealerships, which is still live.
Among the features it advertises are field-level controls permitting “data retention, or data flush, of every field on a scanned identity document.” A few lines away, the same page promises “No more photocopies!” because the software automatically saves a high-quality image of the ID.
Both statements are true at the same time, and that is the whole story.
The product was built so a dealership could verify a license and then discard the data, field by field. It was also built so a dealership could keep every bit of it, indefinitely, in a cloud account, with an image attached. Which of those two happened at any given store came down to a configuration screen and whoever happened to be standing in front of it on onboarding day.
Verification is an event. Retention is a decision. Auto retail spent a decade letting a vendor’s settings screen make the second one on its behalf.
Nobody set out to build a national identity archive. It accumulated one test drive at a time, because deleting required somebody to think about it and keeping required nothing at all.
About That Line Regarding Payment
One sentence in the notice deserves to be quoted fairly and then examined. IDScan observes that full access to the information required payment, and says it is notifying potentially affected individuals out of an abundance of caution.
That is an accurate statement about the listing. It is not a statement about risk.
Criminal data brokers charge money because the merchandise has value, not because it lacks reach. A paywall on a dark web marketplace is a business model, not a security control. It filters out the curious and leaves the motivated — and the motivated are the entire population that matters when the product for sale is a verified government identity document.
What A Dealer Should Actually Do This Week
Three things, none of which require waiting for an investigation to close.
Ask the vendor, in writing, for your account’s retention configuration and its history: which fields were retained, whether images were stored, and across what date range. That document is the difference between a short conversation with counsel and a very long one.
Ask for your account’s affected-record count. The 500-consumer threshold is not rhetorical.
Then reread the service-provider language in the contract you signed, because the Safeguards Rule assumes there is some.
Dealers have had a rough education lately in how expensive paperwork can get. Santander’s suit against a Ventura Jeep dealer over allegedly fraudulent loan contracts is a reminder that a documentation trail cuts in both directions. This is the same species of risk arriving from a direction nobody in the store was watching.
The Fix Already Exists. Almost Nobody Is Buying It.
Here is what makes the next five years worth watching.
The mobile driver’s license standard that AAMVA and ISO have spent years building solves this at the source. An mDL can answer a yes-or-no question — is this person over 21, is this credential valid — without surrendering the record behind it. AAMVA’s implementation guidelines require issuers to include age-over attestations, and require the holder’s app to give them control over which elements are shared at all.
A dealership verifying someone before a test drive does not need an address, an eye color and a document discriminator. It needs to know the license is real and belongs to the person holding it. The technology to ask only that narrow question has existed for years.
But AAMVA’s own guidance is candid about the limit. Once data reaches a verifier, the association notes, it is beyond the technical control of both the holder and the issuing authority — which is why the guidelines recommend that jurisdictions pursue regulatory solutions instead.
Translated: the standard can stop you from collecting. Only the law can stop you from keeping.
What To Remember
The dealership that scanned the license never owned the server. It is going to own the consequence anyway.
That lesson reaches well past ID scanners. Nearly every convenience the modern store has bolted on — the CRM that remembers, the desking tool that syncs, the scanner that fills the form for you — works by making a permanent copy of something that only needed to be checked once.
A scanner that verifies is a tool. A scanner that remembers is a liability with a subscription.
Has a dealership ever scanned your license, and did you think about where that scan ends up? Tell us in the comments.

