← All Briefings
Briefings


IDScan Confirms Cloud Breach Behind 153 Million License Leak

Risky Business framed the leak as a nation-state feeding opportunity: Tom Uren and James Wilson's read is that Chinese intelligence services now hold a scan-quality corpus of American identity documents at a scale no prior breach matched. IDScan's own disclosure, four days after BleepingComputer first tied the database to the company, says customer data was "accessed" in its cloud platform. Neither statement names the misconfiguration. A database of 153 million scanned licenses does not leak from a phishing email; it leaks from a bucket or an access policy that let a customer's data reach the open internet, and IDScan has not said which.

An APAC bank running IDScan or a comparable identity-verification vendor for KYC onboarding has one live exposure here: the HKMA and MAS both require regulated institutions to know where verification-flow customer data physically sits and who can reach it, and "we outsourced the scan" is not an answer to that question during an on-site inspection. Circular 26EC54, out this month from the SFC via the Brokers' Forum, extends supervisory expectations to virtual asset intermediaries and associated entities on exactly this kind of third-party data handling. A bank that has not asked its identity-verification vendor for the specific cloud access control that failed at IDScan is asking the wrong question when it asks whether IDScan is "secure."

The control that would have mattered is data residency plus access logging on the storage layer holding scanned documents, not endpoint detection or network monitoring, because the exfiltration path here was direct read access to stored files. No firewall rule or EDR agent sits between a misconfigured cloud bucket and the internet. Any bank whose KYC vendor cannot produce access logs showing who touched the underlying storage in the past ninety days has a gap that a circular citation will not close.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.