Another KYC Data Breach, Another Warning
A dark-web service is reportedly selling more than 153 million American and Canadian driver’s license records. The FBI is investigating an apparent breach tied to IDScan.net, an identity-verification provider. Many people have never heard of IDScan, but they may have handed a driver’s license to a car rental counter, bank, hotel, casino, dispensary, or retailer that uses its scanning tools. The company captures front and back images, extracts personal details, compares photos with selfies, and stores or transmits data to cloud portals. That makes it a valuable target.
The Same Data That Fights Fraud Also Feeds It
KYC checks are supposed to stop fraud and illegal activity. In practice, they create large stores of personal information. Names, addresses, license numbers, passport details, and photos sit in databases. If a company fails to protect them, criminals get exactly what they need for identity theft. The model is not inherently safe just because a vendor promises security. It concentrates risk.
Equifax is the obvious comparison. In 2017, attackers compromised sensitive data on nearly 148 million Americans. The Department of Justice later alleged the Chinese People’s Liberation Army was behind the hack. That case showed the scale of harm when a central repository of personal data is breached. The IDScan case, if confirmed, would add to a long list.
Why Crypto Users Should Care
For people in crypto, the issue is familiar. Exchanges and other services collect IDs under anti-money laundering rules. Those records can become a single point of failure. A user may control their private keys, but they cannot control a vendor’s cloud portal. If that portal leaks, the consequences follow them into traditional finance and daily life. The problem is not that verification exists. The problem is how it is collected and stored.
A Better Path for Identity Checks
There are alternatives worth considering. Companies can verify age, residency, or accreditation without keeping copies of IDs. Zero-knowledge proofs and selective disclosure could let a person prove a fact without revealing the underlying document. Some of these tools are still early, and they are not a cure-all. But the current approach creates honeypots, and hackers know it. The FBI investigation into IDScan may take months to resolve. Whatever it finds, the larger lesson is already clear: collecting more data than necessary turns security into a liability. Changing that will take pressure from users, regulators, and businesses. The column’s author, Laz Pieper of Coin Center, argues for private peer-to-peer networks and the right to build and use them. That view is not the only one, but it points to a real tension. Identity verification can protect people, yet careless collection can expose them. Another breach is likely unless the collection model changes.
![]()

