1. United States
  2. Ariz.
  3. Letter

Investigate IDScan.net Breach and Pass Strong Data Security Legislation

To: Sen. Kelly, Sen. Gallego, Rep. Stanton

From: A verified voter in Chandler, AZ

September 4

Congress needs to act immediately on the IDScan.net breach that has put 153 million American and Canadian drivers license scans up for sale on the dark web. The FBI's New Orleans field office has already opened an investigation, but that's not enough. We need congressional hearings, and we need legislation that makes companies like IDScan.net criminally liable when they fail to protect the sensitive identity data they profit from collecting. This isn't a hypothetical threat. The stolen records include infrared and ultraviolet scans of licenses, government CAC cards, and medical documents — everything needed to open fraudulent lines of credit, defeat two-factor authentication, and locate people in witness protection or fleeing domestic violence. IDScan.net processes over 21 million verifications monthly across 20,000 locations, serving Hertz, Target, FedEx, and others. That scale of data collection demands that scale of accountability. A company that vacuums up this much sensitive PII and then loses it to a year-long active breach should face consequences that match the damage — not a fine and an apology. Pass legislation that ties penalties to the volume of records exposed. If you store tens of millions of identity documents and lose them, the financial consequences should be existential. Right now there is no deterrent strong enough to force these companies to take security seriously. That has to change.

Share on BlueskyShare on TwitterShare on FacebookShare on LinkedInShare on WhatsAppShare on TumblrEmail with GmailEmail

Write to Mark Kelly or any of your elected officials

Send your own letter

Or text write to 50409

Resistbot is a chatbot that delivers your texts to your elected officials by email, fax, or postal mail. Tap above to give it a try or learn more here!