On September 1, 2026, security journalist Brian Krebs reported that a dark web marketplace called Nexus was selling more than 170 million identity documents, including roughly 153 million U.S. and Canadian driver's licenses, and had traced the source to IDScan.net, an identity verification provider based in Louisiana. IDScan.net posted a notice on its website on September 4 acknowledging that certain customer data may have been accessed without authorization - a notice that wasn't indexed by search engines and wasn't added to its press releases page. On September 10, TechCrunch reported that IDScan.net had moved from “may have accessed” to confirming the theft outright: full names, driver's license numbers, and other government-issued identification numbers. The FBI is investigating. The marketplace listing claims the data had been exfiltrated for over a year before anyone outside the company noticed.
That's a nine-day gap between the breach becoming public and the company confirming it - and the confirmation only came after outside reporting made the “investigating” posture untenable.
IDScan.net's client base spans retail, car rental, gaming, and age-restricted commerce, but its reach into financial services goes well beyond any single institution's own vendor list. It connects directly to banks and credit unions through the Jack Henry Fintech Integration Network, the channel Jack Henry describes as giving third-party fintechs and financial institutions shared access to core banking data. It also sits a layer down: IDScan.net's DIVE identity verification is built into GOLDPoint Systems' loan origination and servicing software, used by lenders across the country, and into Herbo Pay, a payments platform operated by Eco Science Solutions for merchant onboarding. A lender using GOLDPoint's platform, or a merchant onboarded through Herbo Pay, may never have evaluated IDScan.net directly. It inherited the relationship through a fintech platform it did choose.
That's the shape of an open finance chain, not a single vendor relationship. The exposure doesn't stop at whichever institution signed IDScan.net's contract. It runs through every fintech platform that built IDScan.net into its own product, and every institution, lender, or merchant using one of those platforms without visibility into what's running underneath it.
This is the same structural problem this blog keeps returning to. A third-party provider embedded inside an onboarding flow, however many hops removed from the institution that ultimately relies on it, is a node that chain is trusting with identity data none of the parties above it directly hold themselves.
None of this required a sophisticated breach. It required treating a one-time attestation as a permanent guarantee, whether that attestation came from IDScan.net directly or from a platform partner vouching for what it built its own product on. Neither one gives an institution ongoing visibility into who actually holds its data, how well it's protected, or what's happening to it right now. An institution that adopted a lending or payments platform two years ago has had no reason to look again at what that platform runs underneath it - not until something forces a review, and by then the exposure has already occurred.
Today, risk in an open finance chain is continuous. And it moves at the pace of whichever company in the chain is slowest to disclose, not the pace of the institution actually holding the customer relationship. That means everyone downstream finds out about a material risk exactly when that company decides to say so, or when a journalist forces the issue first. A one-time assessment, covering only the entity an institution can see directly, never reaches the sub-processor operating two layers down. The gap this breach exposes isn't that IDScan.net had a security incident. It's that the platforms and institutions relying on it, directly or through another platform entirely, had no independent way to know their exposure was changing until IDScan.net's hand was forced.
That's the argument for monitoring that sits outside any single relationship: continuous visibility into a third-party provider's risk posture, security signals, and incident history that doesn't depend on that provider's own disclosure schedule, and that extends to the sub-processors sitting underneath. An open finance chain is only as trustworthy as its least visible link.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.