How 153 Million Stolen ID Scans Bypass Document Verification

The FBI is investigating IDScan.net after a dark web service listed 153 million driver's licence scans, infrared and ultraviolet captures included. The security tier built to prove a document is real was photographed proving it.
By Sukrit Bhatia
l
16
 min read
What are deepfakes — business risk overview article
Table of Content
No items found.

A dark web service called Nexus listed scans of more than 153 million US and Canadian driver's licences for sale, and on 1 September 2026 the FBI's New Orleans field office opened an investigation into an apparent breach at the identity verification company IDScan.net. The headline number is not the part that should worry anyone running an onboarding flow.

Each record holds six image files: front-and-back pairs under visible, infrared and ultraviolet light, timestamped. Ultraviolet is the tier document verification trusts most, because AAMVA makes a 365 nm response a mandatory anti-counterfeiting feature on every compliant licence. Nexus was not selling forgeries of that feature. It was selling 153 million genuine captures of it, taken by the scanner class the check depends on.

That inverts the problem. The attacker's difficulty stops being manufacture and becomes delivery, and document forensics has nothing left to find.

  • Genuine captures, not forgeries. Six files per record under three illuminations, verified by Brian Krebs against his own travel records and those of nine associates.
  • The trusted tier is the exposed one. AAMVA's 2025 standard makes a 365 nm UV response mandatory precisely because the inks are not commercially available. Photographing it needs no ink.
  • Three of NIST's four validation methods fall. Only tactile inspection on site survives, and it is unavailable to any remote flow.
  • Four of FinCEN's ten red flags are dead letters. Every media-forensic indicator fails; every channel, device and behaviour indicator holds.
  • ISO/IEC 30107-3 does not cover it. Its scope is attacks "at the biometric capture device during presentation"; an injected file is explicitly outside it.
  • The fix is not better document forensics. Value moves to verification of ownership, capture-path integrity and face match against a genuine portrait.

What the FBI is investigating

A dark web identity theft service called Nexus listed scans of more than 153 million driver's licences from the United States and Canada for sale, and on 1 September 2026 the FBI's New Orleans field office opened an official investigation into an apparent breach at the identity verification company IDScan.net. Krebs on Security, which identified the service, also reported more than 10 million identification cards, more than 3 million travel documents and over 579,000 medical cards. The detail that matters more to anyone running an onboarding flow sits below the headline number: each record contains infrared and ultraviolet captures of the document, not just a photograph of it.

That changes what kind of incident this is. A leak of licence data is an attribute problem, and the industry has absorbed several. A leak of licence captures, under the exact illuminations a verification stack uses to judge whether a document is real, hands an attacker the output of the check rather than the input to it. Readers of how deepfakes bypass KYC will recognise the shape, while noting that no synthetic media is involved here at all.

DateEventSource
June 2025Earliest timestamps found on records in the corpus.Krebs on Security
Over a yearOperators state: "We have been continuously exfiltrating new data for over a year into our private database."Krebs on Security
1 September 2026The FBI's New Orleans field office opens an official investigation into an apparent breach involving idscan.net.Krebs on Security
Within 24 hoursListed licence records increase by nearly 400,000, indicating collection was still running.Krebs on Security
Shortly after publicationThe Nexus site vanishes from the dark web, its login page replaced with "This service is no longer available."Krebs on Security
2 September 2026Independent pickup repeats the infrared and ultraviolet detail.Malwarebytes Labs
3 September 2026Target states on the record that it is not involved.Engadget

Table 1: Disclosure timeline for the Nexus listings and the FBI investigation into IDScan.net.

Nexus went offline shortly after publication, its login page replaced with "This service is no longer available." Records had grown by nearly 400,000 in the preceding 24 hours, and the operators claimed continuous exfiltration "for over a year". A marketplace disappearing is not a corpus being destroyed.

What one stolen record contains

Krebs verified the listings by finding his own driver's licence offered as a free sample, matching its timestamp against his travel records, and repeating the exercise with nine associates. His record held six image files: three front-and-back pairs, comprising a basic scan plus infrared and ultraviolet versions of the same images, each with a date and timestamp appended.

File in the recordWhat a verifier reads from itStatus in the corpus
Basic scan, frontPortrait, name, date of birth, licence number, address, expiry date.Present, genuine
Basic scan, backPDF417 barcode carrying the same attributes in machine-readable form.Present, genuine
Infrared, frontIR-drop-out and IR-fluorescent ink response, and the B900 spectral region the machine-readable layer depends on.Present, genuine
Infrared, backSubstrate and laminate behaviour under infrared, used to distinguish card stock.Present, genuine
Ultraviolet, frontThe 365 nm fluorescent response that AAMVA makes a mandatory feature.Present, genuine
Ultraviolet, backCovert UV artwork positioned over the data fields most often altered.Present, genuine
Date and timestampAppended to every image file, recording when the capture was taken.Present
The holderA live face, possession of the card, or control of an address or account tied to it.Absent

Table 3: Contents of a single Nexus record, as described in the Krebs on Security report.

The last row is the whole argument. Everything in the record answers the question is this document authentic. Nothing in it answers is the applicant the person this document belongs to. Those are different questions, defended by different controls, and most onboarding stacks have quietly been treating the first as a proxy for the second.

Anatomy of one record

Six genuine captures, and the one thing the record does not contain

Brian Krebs reported that his own listing on the Nexus service held six image files: three front-and-back pairs, taken under visible, infrared and ultraviolet light, each with a date and timestamp appended. Every pane below is a real capture of a real document. None of it is forged, which is exactly why document forensics has nothing to find.

.
Visible light
Infrared
Ultraviolet
Front

Basic scan, front

Portrait, name, date of birth, licence number, address, expiry.

Reads as genuine

Infrared, front

IR-drop-out and IR-fluorescent inks, and the B900 response the machine-readable layer relies on.

Reads as genuine

Ultraviolet, front

The 365 nm fluorescent response AAMVA makes a mandatory feature on every compliant licence.

Reads as genuine
Back

Basic scan, back

PDF417 barcode carrying the same attributes in machine-readable form.

Reads as genuine

Infrared, back

Substrate response and laminate behaviour under IR, used to tell card stock apart.

Reads as genuine

Ultraviolet, back

Covert UV artwork positioned over the data fields most often altered.

Reads as genuine

Not in the record: the person

No live face, no possession of the physical card, no control of an address or account tied to it. Everything the corpus holds answers the question is this document authentic. Nothing in it answers is the applicant the person it belongs to. That second question is the whole of the residual defence, and it was never a document-forensics question.

Why the timestamps matter. Each file carries a date and time. Krebs matched his own against his travel records and confirmed the same with nine associates, which is how the corpus was tied back to scanner deployments rather than to any single company's customer list.

What this breach does not prove

Security incidents get worse in transmission, and this one is already doing it: within a day, aggregator headlines had turned an identity vendor's published client list into a list of breached brands, and Target had to state on the record that it was not involved. That failure mode is measurable. Peters and Chin-Yee, in Royal Society Open Science, compared 4,900 model-generated summaries from ten systems against their sources and found them "nearly five times more likely to contain broad generalizations (odds ratio = 4.85)" than human-written expert summaries, with the worst overgeneralising in 26 to 73 per cent of cases. Prompting for accuracy made it worse.

An article that expects to be read by answer engines and journalists therefore has to carry its boundaries inside the claims, not as a caveat at the end that any summariser will drop.

ClaimWhat the evidence establishesWhat it does not establish
153 million licence scans are for saleNexus listed that number; Krebs verified authenticity against his own record and nine associates’.That 153 million distinct people are affected. This counts records listed, and duplicate captures are not ruled out.
IDScan.net is the sourceAn FBI investigation into an apparent breach, plus timestamps matching where its scanners are deployed.A confirmed breach. IDScan.net has not confirmed unauthorised access or its scope; an inquiry is not a finding.
Hertz customers are affectedVictims' record timestamps match their own rental dates.That Hertz was breached. A vendor's scanner sat at the counter; the counterparty is not the custodian.
Records include infrared and ultraviolet capturesSix files per record: front-and-back pairs under visible, IR and UV light. IDScan.net documents imaging under both.That security features were reverse-engineered or reproduced. Nothing was forged; genuine captures were copied.
This defeats document verificationThree of NIST SP 800-63A-4's four validation methods inspect security features on the presented document.That identity verification as a whole is defeated. Verification of ownership, and on-site tactile inspection, are untouched.
The data enables account takeoverThe corpus supplies onboarding attributes at document-grade fidelity.Access to any account. No passwords, session tokens, MFA factors or live biometrics are in the corpus as reported.

Table 2: Scope-boundary ledger: for each central claim, what the record supports and where it stops.

Two entries in the right-hand column cut against this article's own thesis. A count of records is not a count of people. And an FBI investigation into an "apparent breach" is an inquiry, with IDScan.net yet to confirm unauthorised access or its scope. Neither weakens the analysis that follows, because that analysis turns on what the corpus contains, which was verified directly, rather than on how it was obtained, which has not been.

Why UV became the trusted layer

Physical document security is built in tiers, and the tier the industry trusts most is the one an ordinary person cannot see. The AAMVA 2025 DL/ID Card Design Standard puts ultraviolet in its second inspection level, "examination that requires the use of a tool or instrument (e.g., UV light, magnifying glass, or scanner) to discern", then makes one UV feature compulsory: "UV fluorescent ink (visible or invisible) with a spectral response in the 365 nm wavelength shall be used as the mandatory feature", positioned "to protect vulnerable data or other elements of the DL/ID that may be particular targets to fraud."

The reasoning is explicit. These ink properties "shall not be present in inks that are commercially available to the public or pigment printing systems. This allows for the differentiation of a genuine DL/ID from a fraudulent one." Issuing authorities implement it accordingly: Pennsylvania describes its redesigned licence as carrying "an ultraviolet (UV) response that fluoresces under UV lighting", per the Pennsylvania DMV.

AAMVA's three threats, and a fourth

The standard names exactly three threats its security features exist to stop: "Counterfeiting", meaning "producing a simulation of the genuine document"; "Falsification", meaning "altering the holders details on a genuine document or harvesting/repurposing genuine document parts"; and "Misuse of a genuine document", meaning "posing as the rightful holder".

All three presume a physical card. Counterfeiting produces one, falsification modifies one, misuse carries someone else's into a shop. The Nexus corpus is a fourth case the threat model does not contain: genuine, complete, multi-spectral captures of real cards, separated from both the card and the holder, at a scale of 153 million. No ink was reverse-engineered and no laminate defeated. The mandatory 365 nm feature performed exactly as designed and was photographed doing so.

The standard anticipated the general form of this without the mechanism, warning against placing "too much reliance upon any single security feature", because "there can be no guarantee it will not become compromised during the validity period of the document." Licences issued years ago remain valid for years more. This sits closer to the forged photo ID problem in remote hiring than to the synthetic identity literature, though it converges with how fake identities pass ID verification.

A genuine scan has no tells to find

Detecting a manipulated document means finding evidence of manipulation: resampling artefacts, inconsistent compression, font substitution, cloned regions, edges where a portrait was replaced. Against forgeries these work. Against a genuine capture they have nothing to operate on. No splice, because nothing was spliced. No generative signature, because nothing was generated. No inconsistency across illuminations, because all six images came off one scanner in one session.

IDScan.net's own documentation makes the honest version of the point. Its technology captures "images of the credential under multiple illumination conditions" including "ultraviolet light, infrared light", then compares those against "expected characteristics for that document type". The company states plainly that "the presence of UV fluorescence alone does not prove that an ID is genuine", per IDScan.net. That caveat was always correct; it is now load-bearing.

This inverts the usual synthetic media problem described in how deepfakes are made and across the types of deepfakes. There the artefact exists and the difficulty is measuring it under compression. Here the artefact does not exist, so the attacker's remaining problem is delivery, the subject of how injection attacks feed media into verification.

Where ISO 30107-3 stops

Vendors certify liveness against ISO/IEC 30107-3 and buyers read that certification as coverage. The standard's scope section says otherwise in one sentence: "The attacks considered in this document take place at the biometric capture device during presentation. Any other attacks are considered outside the scope of this document." The published preview of ISO/IEC 30107-3:2023 carries that wording verbatim, alongside the exclusion of "overall system-level security or vulnerability assessment."

An attacker holding a genuine capture presents nothing to a capture device. They inject a file into the stream the device would have filled, so a presentation attack detection score, however good, measures an event that did not occur. That is the distinction drawn in deepfake detection versus presentation attack detection and liveness detection versus deepfake detection, and the reason a certification badge and a coverage claim are different objects.

The four NIST validation methods

NIST SP 800-63A-4 is more precise than most vendor documentation about what validating a document means. Section 4.1.4 permits exactly four methods, and the split between them is where this breach lands.

NIST SP 800-63A-4 §4.1.4 validation methodWhat it inspectsOutcome against a genuine capture
Interrogating digital security features, such as signatures on assertionsCryptographic evidence, not an imageHolds. Not applicable to a photographed card, and the reason mobile driving licences differ structurally.
Automated scanning technology that can detect physical security featuresThe presented image, under multiple illuminationsDefeated. The corpus supplies exactly the illuminations this method reads.
Visual inspection by a proofing agent, real-time or asynchronousThe presented image, by a trained humanDefeated. The agent inspects a genuine capture and finds nothing wrong.
Physical and tactile inspection by a proofing agent on siteThe card itself, in a handHolds. The only one of the four the corpus cannot reach.

Table 5: The four evidence-validation methods in NIST SP 800-63A-4, tested against a stolen genuine capture.

Three of the four inspect the document as presented, and only tactile inspection on site requires the physical card. For a remote unattended flow, which is what consumer onboarding is, two methods are live options and both fall to a genuine capture. The requirement that STRONG evidence carry "physical (e.g., security printing, optically variable features, holograms) or digital security features that make it difficult to reproduce" is still satisfied by the licence. Reproduction was never the attack.

Section 4.1.6 is the part worth re-reading. It requires verifying the applicant's ownership of evidence through a returned confirmation code to a validated address, a microtransaction to a validated account, or a completed authentication. None of those is answerable from an image. NIST separates validation from verification on purpose, and this incident demonstrates why. Where each sits is mapped in where detection fits in an identity verification stack.

The FinCEN red flags that fail

In November 2024 FinCEN issued FIN-2024-Alert004, listing ten red flag indicators of deepfake media abuse for financial institutions. It is the closest thing US institutions have to an operational checklist for this threat, and it repays testing against a genuine stolen capture rather than a forgery.

FinCEN red flag indicator (FIN-2024-Alert004)What it testsAgainst a genuine capture
Customer's photo is internally inconsistent or shows visual tells of being alteredThe document imageDefeated
Customer presents multiple identity documents inconsistent with each otherThe document imagesDefeated
Reverse-image lookup matches an online gallery of GenAI-produced facesThe portraitDefeated
Photo or video flagged by deepfake detection softwareThe mediaDefeated
Third-party webcam plugin used during a live verification checkThe capture channelHolds
Communication method changed mid-check over technical glitchesBehaviour in sessionHolds
Customer declines to use multifactor authenticationWillingness to prove controlHolds
Geographic or device data inconsistent with the identity documentsIndependent contextHolds, and strengthens
GenAI-detection software flags AI text in the profile or responsesFree text, not the documentHolds
Rapid transactions or heavy chargebacks on a thin new accountPost-onboarding behaviourHolds

Table 6: FinCEN's ten deepfake red flag indicators, sorted by whether a genuine stolen capture would trip them.

Four indicators fail outright, each for the same reason: they test the document image for evidence of manipulation. A photo that "shows visual tells of being altered" has none. Multiple documents "inconsistent with each other" are consistent, because they belong to one real person. A reverse-image lookup against galleries of generated faces returns nothing, because the portrait shows someone who exists. Detection software asked whether the media is manipulated returns the correct answer, no, and that correct answer is the failure.

FinCEN FIN-2024-Alert004, tested against a genuine stolen capture

Every media-forensic red flag falls. Every channel red flag holds.

FinCEN published ten red flag indicators for deepfake media abuse in November 2024. Sorting them by whether a genuine, unaltered scan of a real licence would trip them produces a clean split, and the split is not random: it falls exactly along the line between examining the document and examining the person delivering it.

0 of 10

Defeated

Each of these tests the document image for signs of manipulation. A genuine capture has none, because none were introduced.

  • Customer's photo is internally inconsistent or shows visual tells of being altered
  • Customer presents multiple identity documents that are inconsistent with each other
  • Reverse-image lookup matches an online gallery of GenAI-produced faces
  • Photo or video is flagged by commercial or open-source deepfake detection software
0 of 10

Still holds

None of these looks at the document. They test the channel, the device, the profile and the behaviour, which the corpus does not supply.

  • Third-party webcam plugin used during a live verification check
  • Communication method changed mid-check over suspicious technical glitches
  • Customer declines to use multifactor authentication
  • Geographic or device data inconsistent with the identity documents
  • GenAI-detection software flags AI text in the profile or prompt responses
  • Rapid transactions, risky payees or heavy chargebacks on a thin new account

The instruction this gives a KYC team. The response to a 153-million-record document corpus is not a better document forensics model. Four of the ten indicators a US regulator published are now dead letters against this attack, and buying more of what produced them recovers none of the four. The six that survive were already in the stack, usually weighted lowest, and they are the ones worth re-weighting.

The red flags that still hold

Six indicators survive, and the pattern is not accidental: not one of them looks at the document. A third-party webcam plugin, a mid-session switch of communication method, a refusal of multifactor authentication, device and geolocation data inconsistent with the licence, AI-generated profile text, and abnormal transaction patterns on a thin new account all measure the channel, the device, the behaviour or the money.

The geolocation indicator arguably strengthens, since an attacker working from a stolen corpus is by definition nowhere near the address on the licence and has no reason to correlate with it. The transaction indicators sit downstream of onboarding entirely, which is the argument in why identity fraud happens after onboarding, not during it.

Why remote onboarding absorbs this

An in-person check is largely unaffected, because a card in a hand can be flexed, felt, tilted and held under a lamp, and no image supplies that. The exposure concentrates where the "document" is a file arriving over a network: remote account opening, video KYC, marketplace and gig onboarding, age verification.

Those flows already had a structural weakness unrelated to document quality. The camera sits on the attacker's device and the pipeline trusts what it receives, the surface described in video KYC under attack and how deepfakes bypass liveness checks. What changes is the quality of what gets injected. Building a document image leaves traces. Injecting a real one leaves none, because the file is indistinguishable from what a genuine applicant's camera would have produced. At some point it was exactly that.

What the timestamps give away

Every image file carries a date and timestamp, which is how attribution happened at all. A capture taken at a rental counter in June 2025 and submitted to a bank's onboarding flow in September 2026 is not a document problem. It is a freshness and provenance problem, visible to any pipeline that examines capture metadata rather than only pixels. The caution is that metadata is trivially strippable, and an attacker who reads this will strip it, so timestamp analysis is a signal worth collecting and never a control worth relying on. The industrialisation dynamic in the deepfake factory and its supply chain applies: once a corpus is packaged for resale, the cleanup step gets packaged with it.

How the brand list got overstated

Coverage within 48 hours named Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment. That list is IDScan.net's published customer list, reported as such by 9to5Mac. It is not a list of organisations whose customers appear in the corpus, and Target denied involvement on the record, per Engadget.

The Hertz correlation is different in kind. It rests on victims finding their own scan timestamps matching their own rental dates, which evidences where a scan was taken, not who was breached. The difference between "Hertz was breached" and "a vendor's scanner at a Hertz counter captured this image" is the difference between a defamatory claim and an accurate one.

Timeline and what is still unknown

Four things remain open. Whether IDScan.net was in fact breached, and by what route, is the subject of an inquiry rather than a finding. How many distinct individuals the 153 million records represent is unknown. Whether the corpus survived the marketplace going offline is unknown, though continuous exfiltration over a year makes survival the safer assumption. Whether circulating copies retain their metadata is unknowable from outside. None of those changes what a security team should do this quarter, because the actions below follow from the corpus's contents rather than its provenance.

What to change in a KYC stack now

The instinct after a document breach is to buy better document forensics. The FinCEN split shows why that is the wrong instinct here: four of ten published indicators are now dead letters against this attack, and none is recovered by a more accurate manipulation detector. There is nothing to detect.

ControlCurrent typical weightingWhat this breach implies
Document authenticity scoringPrimary, often decisiveDemote. It answers a question the attacker no longer has to lie about.
Capture-path integrityRarely instrumentedPromote. Whether the image came from the camera or was injected is now load-bearing.
Liveness and face match to the document portraitPresent, sometimes optionalPromote and make mandatory. The portrait is genuine, so only the person is in question.
Attribute validation against an authoritative sourceCommonKeep, but discount. The corpus supplies real attributes, so consistency proves less.
Verification of ownership, such as a code to a validated addressOften skipped for frictionPromote. NIST separates it from validation because it survives a compromised document.
Device, geolocation and network contextFraud-team signal, not identity signalPromote into the identity decision. One of the six FinCEN flags still standing.
Repeat-document detection across applicationsUncommonAdd. Duplicates in the corpus make cross-tenant collisions a cheap signal.

Table 7: Where re-weighting a document-first onboarding stack actually recovers coverage.

Value moves from validating the artefact to verifying the person and the channel, which is the substance of the four stages of identity defence and the point of positioning detection correctly in the stack. Two practical notes. Face match against the document portrait now does more work than it did, because the portrait is genuine and only the person is in question, with the caveats in how deepfakes bypass liveness checks still applying. And capture-path integrity deserves instrumentation it rarely receives, for the reasons in how injection attacks feed media into verification.

Frequently asked questions

Does this breach mean my driver's licence is useless as identification? No. In person it is unaffected, because a physical card supports tactile and optical checks no image reproduces. The exposure is specific to remote flows that accept a photograph of the document as evidence.

Were 153 million people affected? That is the number of driver's licence records listed by the service, not a verified count of individuals. No reporting rules out duplicate captures of the same document across separate visits.

Why do infrared and ultraviolet captures matter more than the visible scan? Because they are the tier the check trusts. AAMVA makes a 365 nm UV response mandatory precisely so a genuine card can be told from a fraudulent one, on the reasoning that the inks are not commercially available. Holding genuine captures of that response removes any need to reproduce it.

Can deepfake detection software catch this? Not by itself, and asking it to is a category error. The images are not synthetic and contain no manipulation to find. The useful signals are injection detection on the capture path, face match against the document portrait, and the channel and device indicators FinCEN already lists.

Does an ISO/IEC 30107-3 certification cover it? Not on the standard's own terms. Its scope is limited to attacks "at the biometric capture device during presentation", and it states that "any other attacks are considered outside the scope of this document."

Is IDScan.net confirmed as the source? No. The FBI opened an investigation into an apparent breach involving the company, and record timestamps correspond to points where its scanners operate. The company has not confirmed unauthorised access or its scope.

Was Hertz breached? No source establishes that. Victims found their scan timestamps matching their own rental dates, which locates where a capture was taken rather than identifying a breached custodian.

What single change recovers the most coverage? Making verification of ownership mandatory rather than optional, in the NIST sense of a returned code, a microtransaction or a completed authentication. It is the one requirement an image cannot answer.

Methodology and source notes

Every source cited was opened and read directly, including four primary documents quoted from their own text rather than from commentary: the AAMVA 2025 DL/ID Card Design Standard, ISO/IEC 30107-3:2023 as published in its preview, NIST SP 800-63A-4, and FinCEN's FIN-2024-Alert004. Incident facts rest on the Krebs on Security report that identified the service, with independent pickup by Malwarebytes Labs, Engadget and 9to5Mac corroborating the document counts and the infrared and ultraviolet detail.

Where reporting conflicts, the conflict is stated rather than resolved; the affected-brand list is the clearest case and is contradicted above. No figure, name or date appears here that was not read in a source we opened. Nothing here represents an analysis by DuckDuckGoose of the Nexus corpus or any breached record. No such analysis was performed and none is claimed. Last update: Q3 2026.

By Sukrit Bhatia
DuckDuckGoose AI

About the author

By Sukrit Bhatia
DuckDuckGoose AI

Discover the Power of Explainable AI (XAI) Deepfake Detection

Schedule a free demo today to experience how our solutions can safeguard your organization from fraud, identity theft, misinformation & more