Skip to content
iGaming Times

Independent industry intelligence in your inbox. Unsubscribe any time - every newsletter carries a one-click link.

Regulatory

The FBI Is Investigating the ID Vendor That Checks Casino Customers

Antonina TupikovaBy Antonina Tupikova · Founder, iGaming Times2 min read

A dark web service was selling 153 million driver's licence scans. The suspected source, IDScan.net, runs identity checks at more than 20,000 locations, and Caesars Entertainment is on its customer list.

  • A dark web marketplace called Nexus was offering access to more than 153 million US and Canadian driver's licence scans, plus over 10 million other ID cards, more than 3 million travel documents and over 579,000 medical cards
  • The FBI's New Orleans field office has opened an investigation into an apparent incident involving IDScan.net, the New Orleans identity verification company the data is suspected to have come from
  • IDScan.net has told KrebsOnSecurity that it is investigating, and has not confirmed a breach or its scope
  • Named customers reported as appearing in the material include Caesars Entertainment alongside Hertz, Target, FedEx, Motorola Solutions and Jack Henry; the link is drawn from timestamps on the documents matching when customers presented ID at those locations
  • IDScan says it processes more than 21 million verifications a month across over 20,000 locations worldwide

What Is Established and What Is Not

The material surfaced on 31 August through reporting by the security researcher Brian Krebs. A dark web service operating under the name Nexus was selling access to a collection of identity documents: more than 153 million US and Canadian driver's licence scans, over 10 million other ID cards, more than 3 million travel and international documents and over 579,000 medical cards. The marketplace disappeared after the reporting became public.

The FBI's New Orleans field office has opened an official investigation into an apparent incident involving IDScan.net, an identity verification company based in the same city. IDScan told KrebsOnSecurity it was investigating the information provided to it, and has not issued a detailed response. It has acknowledged looking into a potential security incident. It has not confirmed a breach, and it has not confirmed a scope.

Caesars Entertainment appears among the customers named in reporting on the material, alongside Hertz, Target, FedEx, Motorola Solutions and Jack Henry. The basis for that identification matters and should not be skipped over: it comes from timestamps on the stolen documents matching the times at which customers presented identification at those locations. That places the capture events at those venues. It is not, on the current record, a finding that any of those companies' own systems were compromised, and IDScan has not confirmed that its systems were the source either.

IDScan states that it processes more than 21 million verifications a month across over 20,000 locations.

A Casino's KYC Obligation Does Not Stop at the Vendor's Door

Casinos in the United States are required to identify patrons under Bank Secrecy Act obligations, and the practical execution of that is very often a scanner at a cage, a sportsbook counter or a hotel desk supplied by a third party. The regulatory obligation stays with the licensee. If a verification vendor holds images of every licence its clients have ever scanned, then a casino's anti-money-laundering compliance has created a permanent identity archive somewhere the casino does not control and, in many contracts, cannot audit in detail. That is a live question for every operator, not only the one named here, and it is the sort of thing state regulators can ask about without waiting for the FBI to finish. The right question for a compliance team this week is not whether their vendor was breached but how long that vendor retains a scan after the check clears, and why.

Twenty Thousand Locations Is the Vulnerability

The scale figure IDScan publishes about itself is the reason this matters beyond one industry. Twenty thousand locations and 21 million verifications a month describes a company that has become shared infrastructure across gambling, car rental, retail and logistics. Concentration of that kind is efficient and it is also a single point of failure whose blast radius crosses sectors that have nothing else in common. Gambling regulators assess operators; they do not generally assess the operators' identity vendors, and no gaming licence in the United States is conditioned on the security posture of a scanning supplier. This case is an argument that it should be, in the same way payment processors and platform providers eventually became licensable in most mature jurisdictions.

Nothing Here Is Yet a Finding Against an Operator

It bears repeating because the headline invites the opposite reading. No regulator has made a finding against Caesars, no breach of a casino system has been established, and IDScan itself has not confirmed that a breach occurred. What exists is a criminal investigation, a researcher's analysis of a dark web listing, and timestamp evidence pointing at where documents were captured. Operators reading this should treat it as a prompt to check their own vendor contracts and retention schedules rather than as a story about a competitor's failure, because the exposure it describes is structural and widely shared.

The scanner at the counter is a compliance control. It is also, on this evidence, a data collection point whose downstream custody almost nobody in the industry has examined.

Comments

Be the first to comment.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.