After You Verify: What Happens to Your ID, and What the IDScan Breach Means for Creators

Last reviewed: September 11, 2026. Reporting and the investigation are developing. The figures below distinguish reported document counts from what the company has confirmed.
You upload your driver's license, take a selfie, and wait for the approval message. Once your account is verified, you move on to the work you came to do: publish, collaborate, or receive a payout.
But the approval screen does not tell you what happened to the files. Does the platform have a copy? Does its verification vendor? How long will either retain it? What happens when you close the account?
Identity and age checks serve legitimate purposes, including establishing adulthood, preventing fraud, and meeting applicable onboarding and recordkeeping duties. Protecting the information collected for those checks belongs in the same conversation. The IDScan incident makes that responsibility concrete for anyone whose business depends on submitting sensitive documents.
What is known about the IDScan incident
TechCrunch reported IDScan's breach confirmation on September 10. The underlying chronology starts earlier:
- September 1: Brian Krebs reported a service offering more than 153 million driver's license records. His investigation included US and Canadian records and inspection of his own license images. Some records contained multiple images; some had no photos. Krebs' original investigation.
- A company notice dated September 4: IDScan says it received information around September 1, began investigating, and determined that an unauthorized party may have accessed or copied customer information in its cloud. It identifies possible exposure of full names and driver's license or other government-issued identification numbers. It offers potentially affected people free credit monitoring and identity protection. IDScan's incident notice.
- September 8: Biometric Update reported more than 170 million scanned identity documents, including 153 million driver's licenses, and described the company's acknowledgment. Biometric Update's coverage.
The company notice reviewed here does not establish a final number of affected people. Documents, database records, image files, and unique individuals are different units. The reported 150M-plus scale is significant, but it should not become a claim that IDScan has confirmed an exact unique-person total. Likewise, September 10 is the date of the TechCrunch article, not the date printed on the company's notice.
The company describes government-issued ID numbers broadly. That does not establish that passport images, selfies, or every possible identity field were exposed for every person. Krebs reported finding no passports in the dataset he examined. Keep your own response tied to the information a service confirms was involved in your record.
This reporting also does not establish that any particular adult creator platform or payment processor was affected. The connection to creator work is the shared dependency: another business may hold documents you supplied to complete a legitimate check.
What can happen after you press Submit
There is no universal verification pipeline. Treat the following as a map of possibilities to investigate, rather than a description of IDScan's breached system or a promise about your platform.
- Collection. You provide an accepted document and, in some flows, a selfie or short video. Collection may happen inside the platform or on a vendor's hosted page. A familiar logo alone does not identify every company receiving the information.
- Checks. Depending on the service, software or a reviewer may examine document authenticity, extract identity fields, compare a face with the document portrait, or perform a liveness check. Ask which checks your particular flow uses.
- A result returns. The platform might receive a status, selected verified fields, a reference number, or access to more detailed records. An approval result and an image of your license are different things. Find out which the platform receives.
- Information may remain. The original files, extracted fields, verification reports, review notes, or biometric representations may have different retention periods. Ask about each category separately.
- Closure or deletion follows a policy. Closing your account does not itself demonstrate that every verification record, export, or backup has been erased. A deletion request needs an answer about scope, timing, and any required retention.
A concrete example of these distinctions appears in Stripe Identity's verification-session documentation: it separates verification status from accessible verified data and documents a separate redaction process. This illustrates why approval and deletion are different events. It is not evidence of Stripe involvement in the IDScan incident or a recommendation of a processor for adult content.
The useful question is therefore more specific than whether a platform is secure: which information exists, who can access it, for what purpose, and until when?
Keep the compliance purposes separate
A viewer's age check, a creator's identity check, payment onboarding, and performer recordkeeping can involve different parties and different obligations. One completed upload does not automatically satisfy all of them.
For covered production, 18 U.S.C. 2257 establishes identity and age recordkeeping requirements. Do not assume a platform's verified badge fulfills your own applicable duties, or delete required performer records as a privacy cleanup. Determine what your role requires and maintain those records securely.
For payment onboarding, ask the processor what it requires for your account and jurisdiction. For audience age assurance, ask what the service needs to establish and what evidence it retains. Using the word compliance for every request should not prevent a provider from explaining the specific purpose and retention basis.
How to identify and vet the vendor
Start from your signed-in account. Read the verification screen, linked privacy notice, biometric consent language if present, and the platform's service-provider or subprocessor list. A subprocessor is another company engaged to help process data. Save the policy URL and review date; policies and vendor relationships can change.
If the vendor is unclear, ask support or the privacy contact for the legal company name and the provider used for your country, verification type, and submission date. A platform may use different providers for different flows. Today's logo may not identify the company that handled your ID two years ago.
Use these questions to make the answer useful:
- Recipients: Which company collects my documents, and which additional providers can receive them? Does the platform retain its own copy?
- Data: What do you retain: original images, document numbers, extracted address or birth date, selfies, video, face templates, or only a verification result?
- Access: Which staff or contractors can view or export raw files? How is access limited, reviewed, and logged?
- Retention: What is the period for each data category, when does the clock start, and what purpose or requirement justifies it?
- Deletion: What happens after account closure or a deletion request? How are copies, subprocessors, and backups handled? What exceptions remain?
- Other uses: Is the information used for product improvement, model training, marketing, or shared fraud databases? Which optional uses can I decline?
- Incidents: Who would notify me, through which contact details, and how would I verify that a notice is authentic?
A security certification can be one piece of evidence, but ask what service and time period it covers. A badge does not answer whether an employee can download your ID or whether the vendor keeps images after verification. A clear, bounded response is more useful than a broad reassurance.
You can send this without attaching another document:
I completed creator verification through my account around [month/year]. Please identify the verification provider for that submission, what identity information your company and the provider retain, the retention periods and their basis, and the process for requesting deletion of information no longer required. Please also confirm how I would be notified of an incident affecting those records.
If they need to authenticate you, begin with the existing account and ask for the approved secure process. Do not turn a general privacy question into an unsolicited email containing your license.
Minimize unnecessary exposure while completing required checks
Use the approved submission flow. Open the service directly or through a saved bookmark, sign in, and navigate to verification. Confirm unexpected requests inside the account before following a link. A message that knows your legal name is not proof that the sender is legitimate.
Choose among accepted options deliberately. Where multiple documents or methods are officially supported, compare what each exposes and what the provider retains. No document is universally the safest choice. Do not submit extra documents just in case, and do not conceal required information.
Check before redacting or watermarking. Ask whether either is accepted and exactly how to do it. Altering a document image can cause rejection and further submissions. Use accurate documents through an approved process; obtain permission before modifying the copy.
Review optional permissions. Separate what is needed to perform the check from any optional additional use. Decline optional collection or use you do not want where the service permits it. If the distinction is unclear, ask before submitting.
Clean up your own spare copies. Review downloads, camera rolls, shared folders, email attachments, and automatic photo backups. Remove unnecessary temporary copies after successful submission, subject to applicable recordkeeping and evidence-preservation needs. Keep required records in restricted storage with an intentional backup policy.
Keep an inventory, not another ID archive. Record the platform, verification date, vendor, document type, policy link, support contact, and deletion-request status. Leave full document numbers, scans, and selfies out of this planning sheet. Treat even the inventory as private because it links you to services you use.
Why the risk goes beyond a credit application
Consider a hypothetical attacker who obtains a creator's document image and finds the creator's public profile. They might attempt impersonation, send convincing account-recovery messages, or threaten to connect a legal identity with a stage name. These are possible misuse scenarios, not documented outcomes established here for IDScan victims.
A stolen portrait does not guarantee that an attacker can defeat a liveness check or access an account. It can still make a fake support request or extortion message look more credible. A legal name and likeness also cannot be replaced as easily as a password.
That makes account protection part of the response: use unique passwords, enable strong multifactor authentication or passkeys where supported, secure the email used for recovery, and review account sessions and payout-change notifications. These steps reduce other routes into your business; they cannot retrieve a document already stolen from a vendor.
Credit protection: US and Canadian steps differ
United States
A credit freeze restricts access to your credit file and can make new-account fraud harder. You can freeze proactively, without waiting for a breach. Contact Equifax, Experian, and TransUnion separately. Placing or lifting a freeze is free, it does not affect your score, and it stays until lifted. Arrange a temporary lift when a legitimate application needs access.
An initial fraud alert is also free and lasts one year, with renewal available. It tells lenders to take identity-verification steps; it does not block access like a freeze. If you suspect you are or may become an identity-theft victim, contact one bureau; it must notify the other two. An alert can coexist with a freeze. FTC instructions and bureau links.
Neither tool removes leaked photos, prevents blackmail, or secures your existing platform accounts. Monitoring reports possible trouble; it is not the same as restricting credit-file access.
Canada
Contact Equifax Canada and TransUnion Canada about fraud alerts and review both credit reports for unfamiliar activity. Do not assume the US one-bureau alert process applies. Financial Consumer Agency of Canada guidance.
Freeze availability depends on your province. At this review, TransUnion's guidance lists Ontario and Quebec and says a freeze there does not automatically freeze your Equifax file. Check both bureaus' current eligibility and procedures for your location. TransUnion Canada security-freeze guidance.
If a service you verified with is breached: a response checklist
First, establish what happened
- Verify the notice independently. Navigate to the company's official website or your account. Save the notice and its date. Avoid links in unexpected messages offering urgent re-verification or paid removal from a leak.
- Ask whether your submission was affected. Provide an account reference and approximate date through official support. Ask which fields and files were involved, including document images, numbers, selfies, and account credentials. Record what remains unknown.
- Check the vendor connection. If you used a platform rather than the vendor directly, ask whether that vendor handled your particular verification. Not recognizing a vendor's name does not settle whether it processed your information.
- Preserve a small incident record. Keep case numbers, confirmed facts, correspondence, and follow-up dates in restricted storage. Do not buy stolen records or upload your ID to an unofficial breach-search service.
Then protect the information and accounts involved
- Use the relevant credit controls above. Review reports and bank or card statements. If the company offers monitoring, verify the enrollment route, eligibility, duration, and any deadline on its official notice. IDScan's notice links this assistance to its incident-response contact.
- Contact the document issuer. For an exposed license number or image, ask the issuing motor-vehicle agency what reporting, flags, or replacement options apply. For a passport, contact the passport authority. Describe a compromised copy accurately; do not report a physically missing document unless it is missing. A replacement card does not necessarily change its number.
- Secure account access. If passwords were exposed or you entered credentials into a suspicious page, change them from the genuine service and replace any reused passwords. Review recovery details, sessions, and payout destinations. An ID-only breach does not itself prove your platform password was stolen.
- Report actual misuse. In the US, use IdentityTheft.gov for a recovery plan and contact affected businesses. In Canada, follow the Canadian Anti-Fraud Centre's victim guidance, including contacting financial institutions and police as appropriate.
If someone threatens or impersonates you
Preserve messages, account handles, URLs, timestamps, and payment demands before reporting and blocking the account. Do not send money or more identity documents in response to a threat. Report impersonation through the affected platform's official process and report extortion to law enforcement. The Canadian Anti-Fraud Centre's extortion guidance describes common pressure tactics.
For a creator business, decide in advance who can help you respond and where customers can verify your official accounts. If a public clarification is needed, keep it focused on the fake account or payment request. Publishing your own ID as proof would create another exposure.
Keep following up
Put review dates on your calendar for bureau alerts, incident updates, outstanding disputes, and document-issuer advice. Ask for deletion of data no longer needed where available, with written confirmation of exceptions. Deletion can reduce future exposure; it cannot recall copies an attacker already obtained.
A manageable task for this week
Choose the three services most important to your publishing or payouts. Identify their verification providers, record the retention answers you can find, and send one focused request for each unresolved gap. Then set up the credit protections available to you and secure your primary recovery email.
Use the Dependency Inventory to record who your business relies on and the Threat Model Worksheet to choose practical responses. Keep raw identity documents out of those worksheets.
Required verification and careful data stewardship belong together. Complete the checks your business needs, understand where the evidence goes, and have a response ready if a company holding it fails.
