The past seven days confirmed a pattern that should concern every small and mid-size business owner: the weakest point in your security is rarely your own network. It is the vendor you signed up with two years ago and stopped thinking about. Between an identity-verification provider's breach notice, a file-transfer vendor's emergency shutdown, and a wave of state-mandated breach notification letters tracing back to a single healthcare data vendor, this week's threat landscape was defined less by sophisticated hacking and more by supply-chain exposure that businesses inherited without realizing it.

Identity Verification Vendor Breach Exposes 153 Million Driver's License Scans

Louisiana-based IDScan.net, which processes ID checks for car rental companies, retailers, and cannabis dispensaries, confirmed that an unauthorized third party may have accessed and/or copied certain customer information, including full names and driver's license or other government-issued identification numbers. The breach came to light after a criminal-targeting source called Nexus began offering access to more than 153 million scanned driver's licenses from the US and Canada, along with 10 million ID cards, 3 million travel documents and 579,000 medical cards. The FBI's New Orleans field office has since opened a formal investigation into the incident. For business owners, the lesson is structural: IDScan.net serves businesses such as Hertz, FedEx, Target, and marijuana dispensaries, meaning any company that outsources age or identity verification to a shared platform is only as secure as that platform's weakest customer account. When large identity-verification providers retain those records across many customers, a single breach can potentially expose credentials collected through businesses that victims may never have realized were connected to the same underlying platform.

File-Transfer and Remote-Access Vendors Under Active Attack

Two infrastructure vendors that businesses rely on to move sensitive files and grant remote access both triggered emergency responses this week. Secure file-transfer provider Kiteworks issued a notice on September 25 explaining that Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems, prompting a nine-hour global shutdown window before the shutdown recommendation was lifted for all customers on September 27. Separately, Citrix disclosed that two of eight vulnerabilities in NetScaler ADC and NetScaler Gateway have been exploited in zero-day attacks to plant webshells on compromised devices, with Dutch authorities warning that this vulnerability gives attackers full control of the gateway, providing direct access to the internal corporate network behind it. CISA added both flaws to its Known Exploited Vulnerabilities catalog with a remediation due date of 2026-09-30. Any business running a NetScaler VPN gateway, or using a managed file-transfer platform for client documents and invoices, faces an immediate patching deadline this week.

The Vendor Cascade: One Breach, Dozens of Businesses on the Hook

A third pattern reinforced why vendor risk is now a compliance issue, not just a technical one. Healthcare data vendor Aesto disclosed that Aesto experienced a network security incident that impacted a limited portion of their Amazon Web Services infrastructure back in December 2025, but notification letters are still landing on desks this week, months later, because more than two dozen healthcare provider clients across at least six states were affected through the single vendor relationship. This mirrors the earlier Klue incident, where attackers used a dormant credential to obtain OAuth tokens and subsequently accessed data within a number of connected customer environments, ultimately reaching close to 200 companies. For any business connected to CRM, marketing, or data-processing vendors, the exposure clock started the moment the vendor was breached, not the moment you were told.

What Individuals Should Do This Week

If you have ever handed your driver's license to a rental counter, dispensary, or retailer for age or identity verification, assume that record may now sit in a breach database. Place a fraud alert or credit freeze with the major bureaus, and check your email addresses against breach notification services. Reused passwords remain the single biggest amplifier of these incidents once account details enter circulation.

What Businesses Should Do This Week

Build and maintain a vendor inventory that tracks which third parties hold customer identity data, financial records, or CRM access, and who owns the relationship. Patch any Citrix NetScaler appliance immediately and review logs for signs of prior compromise before applying updates. Finally, tighten payment-verification processes: a growing number of business email compromise attacks now involve compromising trusted third-party vendor email addresses to insert fraudulent payment instructions, with vendor email compromise attacks rising sharply as attackers exploit exactly the kind of vendor trust exposed this week.