Sage Team
4 days ago3 min read
When Your Vendor's Vendor Gets Hacked: The IDScan.net Breach Is a Wake-Up Call for Third-Party Risk
Most people have never heard of IDScan.net. That's exactly the problem. This week, the identity-verification vendor confirmed what security researcher Brian Krebs first reported on September 1: attackers had been quietly siphoning data from its systems for roughly a year, and a dark-web marketplace called “Nexus” was openly selling searchable scans of more than 150 million driver's licenses, passports, and government IDs belonging to North Americans. IDScan formally acknowled












