153 Million Leaked IDs: Why Access Control Cannot Rely on a Photo | Concerto Networks
Keypad and card reader mounted beside a secured commercial door
Access Control

153 Million Leaked IDs
Why Access Control Cannot Rely on a Photo

September 8, 2026 6 Min Read By Scott MacMartin

For a year, someone was quietly selling scans of 153 million driver's licenses. They came off the counters where a clerk looks at a photo, looks at a face, and waves the person through. That is the same check running at your lobby this morning.

What the IDScan Breach Changed About Access Control

On September 1, 2026, Krebs on Security reported that a dark web service called Nexus had been selling digital scans of more than 153 million United States and Canadian driver's licenses, along with roughly 10 million identification cards, 3 million travel documents, and 579,000 medical cards. Timestamp analysis traced the images to the infrared and ultraviolet scanning systems operated by IDScan.net, a verification provider whose customers include rental car counters, retailers, and more than a thousand dispensaries. The FBI field office in New Orleans opened an investigation. Nexus claimed on a Russian cybercrime forum that it had been pulling fresh records out of the same source for over a year. For any business whose access control still begins with a glance at a photo ID, the ground moved that day.

A Commodity Credential, Not a Criminal Specialty

Forging a convincing license used to take equipment, skill, and time. With 153 million authentic scans in circulation, it takes a purchase. The economics of the attack changed, not the technique.

  • The document is no longer the proof: A scan that verifies as genuine is worthless as identification once copies of it are for sale.
  • The layers meant to stop this were captured too: The stolen images carry the infrared and ultraviolet data that scanning systems check against.
  • Exposure is retroactive: Anyone whose license was scanned at a covered counter over the past year is affected, and none of them were notified at the time.
  • Takedowns do not undo it: Records that have been sold for a year stay sold, whatever later happens to the marketplace.

Why the Front Desk Is Part of Your Access Control System

Very few businesses count reception as part of the security perimeter. It belongs there. Visitor badges, contractor day passes, and vendor sign-ins are almost always issued on the strength of a human glance at a photo ID, and that process rests on two assumptions that the IDScan breach has now retired: the document is authentic, and nobody else is holding a copy of it.

Where Distributed Operations Break

Single-site businesses usually catch this eventually, because one person owns the door. The failures cluster in companies running three, ten, or forty locations, where the standard has to hold identically at every one of them and nobody is watching all of them at once.

  • Vendors are verified once and never revisited: A badge issued in 2023 is still a working badge in 2026 unless somebody actively took it back.
  • Job sites inherit the weakest process: A trailer gate with a clipboard undoes a properly controlled headquarters.
  • A cloned credential gives no signal: It simply works, right up to the point somebody notices that it should not have.
  • Paper logs prove nothing after the fact: A visitor sheet records a name that was never verified against anything durable.

What Static Credentials Actually Cost

Identity fraud is not a rounding error on the risk register. Javelin Strategy and Research, in its 2026 Identity Fraud Study, found that traditional identity fraud cost Americans 27.3 billion dollars in 2025 and affected 18 million victims. New account fraud, meaning credentials or accounts opened in somebody else's name, rose 31 percent year over year, from 4.2 million victims in 2024 to 5.4 million in 2025. Every one of those figures gets worse once the underlying identity documents are already circulating.

The Compliance Version of the Same Problem

For manufacturers and suppliers working toward CMMC, this is a scoping question as much as a security one. The physical protection family in NIST 800-171 expects an organization to know precisely who can enter a facility and to be able to demonstrate it on request. A photocopied license and a paper visitor log do not demonstrate anything an assessor can rely on. Assessors do not fail you for an untidy lobby. They fail you because you cannot produce the answer in the room.

What Modern Access Control Looks Like

Concerto builds access control on the CDVI ATRIUM platform, which replaces photo-based verification with credentials that cannot be lifted off a scan. The management layer carries as much weight as the credential itself, because a credential you cannot withdraw quickly is a key you handed out and stopped tracking.

  • Biometric readers: Fingerprint and facial recognition for the zones that matter most, verifying a person rather than a document.
  • Mobile credentials: Issued to an employee phone over Bluetooth or NFC, with no plastic to copy, lose, or hand over.
  • Encrypted smart cards: Tamper-resistant RFID and Mifare in place of the proximity cards that can be cloned in seconds.
  • Centralized logging and real-time visibility: Every entry point on one dashboard, with the audit trail an assessor or an investigator will ask for.
  • Instant remote revocation: Access ends the moment someone clicks revoke, not whenever the badge finally comes back.
  • Permission rules by role, department, or schedule: The same standard applied to a single office or a multi-building, multi-state campus.

Where to Start This Quarter

The market has already made this decision. Fortune Business Insights values the global access control market at 12.72 billion dollars in 2026 and projects 26.22 billion dollars by 2034, a compound annual growth rate of 9.46 percent. Businesses still running on keys and visual checks are becoming the exception.

  • Audit every entry point that still depends on a visual ID check or an unmanaged key: Include vendor and contractor access in that count rather than treating it as somebody else's list.
  • Replace clonable badges where the exposure is highest first: Server rooms, executive offices, and any room holding regulated material come before the supply closet.
  • Centralize the permission list: One dashboard should show exactly who can enter where, and any credential should be revocable the moment it is in question.

None of this requires a breach notification to matter. The scans are already sold, and the businesses affected are not the ones that were breached. They are the ones that accepted those documents as proof.

Concerto Networks has run more than 500 nationwide deployments since 2006, with BICSI-certified engineers and dedicated project management for single-site and multi-building work alike. If your doors are still trusting a document that may already be for sale, we will walk your entry points and show you which ones are relying on a photo.

Tags: Access Control Security CMMC
Share:

A Photo Is Not a Credential.
Your Doors Should Know It.

See which entry points still rest on a document someone can buy, and what encrypted, revocable access control puts in its place.

Free Access Control Audit
Encrypted Mobile & Biometric Credentials
One Standard, Every Location

Contact form will load here.