[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / Data breaches

IDScan acknowledges cloud data breach; affected population remains unclear

IDScan has acknowledged unauthorized access to information in its cloud platform, according to The Record. Reports have linked the incident to a marketplace advertising millions of identity-document scans, but the company has not specified how many people were affected. The distinction between advertised scans and confirmed victims remains important.

All updates
Reported ReportedPublished Date not recorded

Incident timing: Company reportedly became aware around September 1, 2026.

What is known

The Record reports that IDScan published a security notice on September 4 after becoming aware of an incident around September 1. The notice said an unauthorized party may have accessed or copied customer information stored in the company's cloud platform, including names and government-issued identification numbers.

What remains uncertain

The company did not give an affected-person count. The widely reported figure of 153 million refers to driver's-license scans offered through a criminal marketplace; it should not be treated as a company-confirmed count of unique victims.

Business context

Organizations relying on identity-verification providers should follow the provider's notifications and review what information they retain with third parties. This is reporting on a developing investigation, not a finding about every IDScan customer.

Source & attribution

Read the original reporting at The Record

AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.

Editorial policy & corrections