Reassessing Your Identity Verification Vendor?
Recent public reporting has prompted many businesses to take a closer look at how identity verification vendors handle sensitive data, retention settings, account controls, and incident response. If your team is reviewing its current provider, this page is intended as a practical resource to help guide that evaluation.
EXPLORE YOUR OPTIONS FOR AN ALTERNATIVE PROVIDER AFTER THE IDSCAN BREACH
If your team is reassessing its current setup, the right comparison usually starts with a few basics: retention controls, least-privilege access, auditability, incident response discipline, and migration readiness.
Key Takeaways After the IDScan Data Breach
Timeline of Events
August 31, 2026 — Reporting indicates the “Nexus” marketplace listing was already active on a cybercrime forum. (zyphe.com)
September 1, 2026 — Public reporting linked the incident to IDScan, and IDScan later stated it received information on or around this date indicating certain data may have been accessed without authorization. (zyphe.com)
September 2, 2026 — The first class-action complaints related to the incident were filed in federal court in Louisiana. (zyphe.com)
September 3, 2026 — Additional litigation followed as more complaints were filed. (zyphe.com)
September 4, 2026 — Additional complaints were filed, bringing the reported total to nine within three days. (zyphe.com)
September 8, 2026 — Public reporting indicated IDScan had published a security-incident notice and was offering support services to potentially impacted individuals. (biometricupdate.com)
Vendor Risk Check-List
-
What categories of personal data does the vendor collect?
-
What data is stored versus processed temporarily?
-
How long is data retained by default?
-
Can retention settings be customized by account, workflow, or document type?
-
Is sensitive data encrypted in transit and at rest?
-
Who can access stored customer data, and under what controls?
- Are admin actions, exports, and policy changes logged and reviewable?
- Does the vendor support role-based access controls and SSO
- What subprocessors or third parties handle the data?
- What is the vendor’s customer notification process after a confirmed incident?
- What audit reports, certifications, or independent assessments are available?
- Can customer data be deleted on demand or automatically after review?
Questions to Ask Your Current Provider
-
Were any of our records, users, images, or transactions affected?
- What specific data elements do you store for our account?
- What was our retention configuration at the time of the incident?
- Can we shorten retention periods or reduce stored document data going forward?
- What internal controls limit employee or contractor access to stored records?
- What logs can you provide showing access, exports, policy changes, and submissions?
- When did you first detect the issue, and when were customers notified?
- What outside forensic, legal, or incident-response partners have been engaged?
- What remediation steps have already been completed?
- What additional remediation steps are still in progress?
- Can you provide a written incident summary relevant to our account?
FraudFighter ID Solution
Safely and quickly authenticate the identity of your clients and constituents - no matter where or how they are transacting with you.
In Person Transactions
Choose from a variety of in-store scanners for the solution that best fits your needs
Remote client Authentication
Create workflows easily to enable your clients to self-authenticate their identity when transacting remotely.
Include ID Auth in Your Mobile POS
Don't have a fixed point-of-sale or checkout counter? No problem, FraudFighter ID Mobile can give you the power to authenticate right from your mobile device.
You Need Secure Control Over Your Data
You need to clearly understand what customer data is being saved and to have full management of these settings. You also need to know who has privileges to change these settings and a full log review of any changes made.
FraudFighter ID Portal Built to Secure Your Data
The FraudFighter ID portal was built with cybersecurity at its core. WE DO NOT OWN YOUR DATA! You do. You control it. You decide whether to save it, when to save it, where to save it and for how long you want to save it. YOU control who in your organization is able to view the data.
$43,000 of potential loss prevented on the first day of use!!
We installed the FraudFighter ID system in July 2019 as part of a program to address member identity authentication. On the first day FraudFighter was implemented, a suspect attempting to withdraw $3,000 from a Shared Branching member account - and also was trying to initiate a HELOC check withdrawl in the amount of $40,000 - was foiled when the authentication of his state issued driver's license came back as "failed". The perpetrator did not object and rapidly left the branch. One of our employees observed the person climbing into a car waiting by the curb with the engine running and drove away.
Frank Kobel - Vice President, Branch Operations
People's Alliance Federal Credit Union (Member of Co-Op Shared Branching Network)
Need to Know More About FraudFighter ID?
Download the FraudFighter ID Brochure for a general overview of the solution.

