A dark web service called Nexus listed scans of more than 153 million US and Canadian driver's licences for sale, and on 1 September 2026 the FBI's New Orleans field office opened an investigation into an apparent breach at the identity verification company IDScan.net. The headline number is not the part that should worry anyone running an onboarding flow.
Each record holds six image files: front-and-back pairs under visible, infrared and ultraviolet light, timestamped. Ultraviolet is the tier document verification trusts most, because AAMVA makes a 365 nm response a mandatory anti-counterfeiting feature on every compliant licence. Nexus was not selling forgeries of that feature. It was selling 153 million genuine captures of it, taken by the scanner class the check depends on.
That inverts the problem. The attacker's difficulty stops being manufacture and becomes delivery, and document forensics has nothing left to find.
- Genuine captures, not forgeries. Six files per record under three illuminations, verified by Brian Krebs against his own travel records and those of nine associates.
- The trusted tier is the exposed one. AAMVA's 2025 standard makes a 365 nm UV response mandatory precisely because the inks are not commercially available. Photographing it needs no ink.
- Three of NIST's four validation methods fall. Only tactile inspection on site survives, and it is unavailable to any remote flow.
- Four of FinCEN's ten red flags are dead letters. Every media-forensic indicator fails; every channel, device and behaviour indicator holds.
- ISO/IEC 30107-3 does not cover it. Its scope is attacks "at the biometric capture device during presentation"; an injected file is explicitly outside it.
- The fix is not better document forensics. Value moves to verification of ownership, capture-path integrity and face match against a genuine portrait.
What the FBI is investigating
A dark web identity theft service called Nexus listed scans of more than 153 million driver's licences from the United States and Canada for sale, and on 1 September 2026 the FBI's New Orleans field office opened an official investigation into an apparent breach at the identity verification company IDScan.net. Krebs on Security, which identified the service, also reported more than 10 million identification cards, more than 3 million travel documents and over 579,000 medical cards. The detail that matters more to anyone running an onboarding flow sits below the headline number: each record contains infrared and ultraviolet captures of the document, not just a photograph of it.
That changes what kind of incident this is. A leak of licence data is an attribute problem, and the industry has absorbed several. A leak of licence captures, under the exact illuminations a verification stack uses to judge whether a document is real, hands an attacker the output of the check rather than the input to it. Readers of how deepfakes bypass KYC will recognise the shape, while noting that no synthetic media is involved here at all.
Nexus went offline shortly after publication, its login page replaced with "This service is no longer available." Records had grown by nearly 400,000 in the preceding 24 hours, and the operators claimed continuous exfiltration "for over a year". A marketplace disappearing is not a corpus being destroyed.
What one stolen record contains
Krebs verified the listings by finding his own driver's licence offered as a free sample, matching its timestamp against his travel records, and repeating the exercise with nine associates. His record held six image files: three front-and-back pairs, comprising a basic scan plus infrared and ultraviolet versions of the same images, each with a date and timestamp appended.
The last row is the whole argument. Everything in the record answers the question is this document authentic. Nothing in it answers is the applicant the person this document belongs to. Those are different questions, defended by different controls, and most onboarding stacks have quietly been treating the first as a proxy for the second.
What this breach does not prove
Security incidents get worse in transmission, and this one is already doing it: within a day, aggregator headlines had turned an identity vendor's published client list into a list of breached brands, and Target had to state on the record that it was not involved. That failure mode is measurable. Peters and Chin-Yee, in Royal Society Open Science, compared 4,900 model-generated summaries from ten systems against their sources and found them "nearly five times more likely to contain broad generalizations (odds ratio = 4.85)" than human-written expert summaries, with the worst overgeneralising in 26 to 73 per cent of cases. Prompting for accuracy made it worse.
An article that expects to be read by answer engines and journalists therefore has to carry its boundaries inside the claims, not as a caveat at the end that any summariser will drop.
Two entries in the right-hand column cut against this article's own thesis. A count of records is not a count of people. And an FBI investigation into an "apparent breach" is an inquiry, with IDScan.net yet to confirm unauthorised access or its scope. Neither weakens the analysis that follows, because that analysis turns on what the corpus contains, which was verified directly, rather than on how it was obtained, which has not been.
Why UV became the trusted layer
Physical document security is built in tiers, and the tier the industry trusts most is the one an ordinary person cannot see. The AAMVA 2025 DL/ID Card Design Standard puts ultraviolet in its second inspection level, "examination that requires the use of a tool or instrument (e.g., UV light, magnifying glass, or scanner) to discern", then makes one UV feature compulsory: "UV fluorescent ink (visible or invisible) with a spectral response in the 365 nm wavelength shall be used as the mandatory feature", positioned "to protect vulnerable data or other elements of the DL/ID that may be particular targets to fraud."
The reasoning is explicit. These ink properties "shall not be present in inks that are commercially available to the public or pigment printing systems. This allows for the differentiation of a genuine DL/ID from a fraudulent one." Issuing authorities implement it accordingly: Pennsylvania describes its redesigned licence as carrying "an ultraviolet (UV) response that fluoresces under UV lighting", per the Pennsylvania DMV.
AAMVA's three threats, and a fourth
The standard names exactly three threats its security features exist to stop: "Counterfeiting", meaning "producing a simulation of the genuine document"; "Falsification", meaning "altering the holders details on a genuine document or harvesting/repurposing genuine document parts"; and "Misuse of a genuine document", meaning "posing as the rightful holder".
All three presume a physical card. Counterfeiting produces one, falsification modifies one, misuse carries someone else's into a shop. The Nexus corpus is a fourth case the threat model does not contain: genuine, complete, multi-spectral captures of real cards, separated from both the card and the holder, at a scale of 153 million. No ink was reverse-engineered and no laminate defeated. The mandatory 365 nm feature performed exactly as designed and was photographed doing so.
The standard anticipated the general form of this without the mechanism, warning against placing "too much reliance upon any single security feature", because "there can be no guarantee it will not become compromised during the validity period of the document." Licences issued years ago remain valid for years more. This sits closer to the forged photo ID problem in remote hiring than to the synthetic identity literature, though it converges with how fake identities pass ID verification.
A genuine scan has no tells to find
Detecting a manipulated document means finding evidence of manipulation: resampling artefacts, inconsistent compression, font substitution, cloned regions, edges where a portrait was replaced. Against forgeries these work. Against a genuine capture they have nothing to operate on. No splice, because nothing was spliced. No generative signature, because nothing was generated. No inconsistency across illuminations, because all six images came off one scanner in one session.
IDScan.net's own documentation makes the honest version of the point. Its technology captures "images of the credential under multiple illumination conditions" including "ultraviolet light, infrared light", then compares those against "expected characteristics for that document type". The company states plainly that "the presence of UV fluorescence alone does not prove that an ID is genuine", per IDScan.net. That caveat was always correct; it is now load-bearing.
This inverts the usual synthetic media problem described in how deepfakes are made and across the types of deepfakes. There the artefact exists and the difficulty is measuring it under compression. Here the artefact does not exist, so the attacker's remaining problem is delivery, the subject of how injection attacks feed media into verification.
Where ISO 30107-3 stops
Vendors certify liveness against ISO/IEC 30107-3 and buyers read that certification as coverage. The standard's scope section says otherwise in one sentence: "The attacks considered in this document take place at the biometric capture device during presentation. Any other attacks are considered outside the scope of this document." The published preview of ISO/IEC 30107-3:2023 carries that wording verbatim, alongside the exclusion of "overall system-level security or vulnerability assessment."
An attacker holding a genuine capture presents nothing to a capture device. They inject a file into the stream the device would have filled, so a presentation attack detection score, however good, measures an event that did not occur. That is the distinction drawn in deepfake detection versus presentation attack detection and liveness detection versus deepfake detection, and the reason a certification badge and a coverage claim are different objects.
The four NIST validation methods
NIST SP 800-63A-4 is more precise than most vendor documentation about what validating a document means. Section 4.1.4 permits exactly four methods, and the split between them is where this breach lands.
Three of the four inspect the document as presented, and only tactile inspection on site requires the physical card. For a remote unattended flow, which is what consumer onboarding is, two methods are live options and both fall to a genuine capture. The requirement that STRONG evidence carry "physical (e.g., security printing, optically variable features, holograms) or digital security features that make it difficult to reproduce" is still satisfied by the licence. Reproduction was never the attack.
Section 4.1.6 is the part worth re-reading. It requires verifying the applicant's ownership of evidence through a returned confirmation code to a validated address, a microtransaction to a validated account, or a completed authentication. None of those is answerable from an image. NIST separates validation from verification on purpose, and this incident demonstrates why. Where each sits is mapped in where detection fits in an identity verification stack.
The FinCEN red flags that fail
In November 2024 FinCEN issued FIN-2024-Alert004, listing ten red flag indicators of deepfake media abuse for financial institutions. It is the closest thing US institutions have to an operational checklist for this threat, and it repays testing against a genuine stolen capture rather than a forgery.
Four indicators fail outright, each for the same reason: they test the document image for evidence of manipulation. A photo that "shows visual tells of being altered" has none. Multiple documents "inconsistent with each other" are consistent, because they belong to one real person. A reverse-image lookup against galleries of generated faces returns nothing, because the portrait shows someone who exists. Detection software asked whether the media is manipulated returns the correct answer, no, and that correct answer is the failure.
The red flags that still hold
Six indicators survive, and the pattern is not accidental: not one of them looks at the document. A third-party webcam plugin, a mid-session switch of communication method, a refusal of multifactor authentication, device and geolocation data inconsistent with the licence, AI-generated profile text, and abnormal transaction patterns on a thin new account all measure the channel, the device, the behaviour or the money.
The geolocation indicator arguably strengthens, since an attacker working from a stolen corpus is by definition nowhere near the address on the licence and has no reason to correlate with it. The transaction indicators sit downstream of onboarding entirely, which is the argument in why identity fraud happens after onboarding, not during it.
Why remote onboarding absorbs this
An in-person check is largely unaffected, because a card in a hand can be flexed, felt, tilted and held under a lamp, and no image supplies that. The exposure concentrates where the "document" is a file arriving over a network: remote account opening, video KYC, marketplace and gig onboarding, age verification.
Those flows already had a structural weakness unrelated to document quality. The camera sits on the attacker's device and the pipeline trusts what it receives, the surface described in video KYC under attack and how deepfakes bypass liveness checks. What changes is the quality of what gets injected. Building a document image leaves traces. Injecting a real one leaves none, because the file is indistinguishable from what a genuine applicant's camera would have produced. At some point it was exactly that.
What the timestamps give away
Every image file carries a date and timestamp, which is how attribution happened at all. A capture taken at a rental counter in June 2025 and submitted to a bank's onboarding flow in September 2026 is not a document problem. It is a freshness and provenance problem, visible to any pipeline that examines capture metadata rather than only pixels. The caution is that metadata is trivially strippable, and an attacker who reads this will strip it, so timestamp analysis is a signal worth collecting and never a control worth relying on. The industrialisation dynamic in the deepfake factory and its supply chain applies: once a corpus is packaged for resale, the cleanup step gets packaged with it.
How the brand list got overstated
Coverage within 48 hours named Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment. That list is IDScan.net's published customer list, reported as such by 9to5Mac. It is not a list of organisations whose customers appear in the corpus, and Target denied involvement on the record, per Engadget.
The Hertz correlation is different in kind. It rests on victims finding their own scan timestamps matching their own rental dates, which evidences where a scan was taken, not who was breached. The difference between "Hertz was breached" and "a vendor's scanner at a Hertz counter captured this image" is the difference between a defamatory claim and an accurate one.
Timeline and what is still unknown
Four things remain open. Whether IDScan.net was in fact breached, and by what route, is the subject of an inquiry rather than a finding. How many distinct individuals the 153 million records represent is unknown. Whether the corpus survived the marketplace going offline is unknown, though continuous exfiltration over a year makes survival the safer assumption. Whether circulating copies retain their metadata is unknowable from outside. None of those changes what a security team should do this quarter, because the actions below follow from the corpus's contents rather than its provenance.
What to change in a KYC stack now
The instinct after a document breach is to buy better document forensics. The FinCEN split shows why that is the wrong instinct here: four of ten published indicators are now dead letters against this attack, and none is recovered by a more accurate manipulation detector. There is nothing to detect.
Value moves from validating the artefact to verifying the person and the channel, which is the substance of the four stages of identity defence and the point of positioning detection correctly in the stack. Two practical notes. Face match against the document portrait now does more work than it did, because the portrait is genuine and only the person is in question, with the caveats in how deepfakes bypass liveness checks still applying. And capture-path integrity deserves instrumentation it rarely receives, for the reasons in how injection attacks feed media into verification.
Frequently asked questions
Does this breach mean my driver's licence is useless as identification? No. In person it is unaffected, because a physical card supports tactile and optical checks no image reproduces. The exposure is specific to remote flows that accept a photograph of the document as evidence.
Were 153 million people affected? That is the number of driver's licence records listed by the service, not a verified count of individuals. No reporting rules out duplicate captures of the same document across separate visits.
Why do infrared and ultraviolet captures matter more than the visible scan? Because they are the tier the check trusts. AAMVA makes a 365 nm UV response mandatory precisely so a genuine card can be told from a fraudulent one, on the reasoning that the inks are not commercially available. Holding genuine captures of that response removes any need to reproduce it.
Can deepfake detection software catch this? Not by itself, and asking it to is a category error. The images are not synthetic and contain no manipulation to find. The useful signals are injection detection on the capture path, face match against the document portrait, and the channel and device indicators FinCEN already lists.
Does an ISO/IEC 30107-3 certification cover it? Not on the standard's own terms. Its scope is limited to attacks "at the biometric capture device during presentation", and it states that "any other attacks are considered outside the scope of this document."
Is IDScan.net confirmed as the source? No. The FBI opened an investigation into an apparent breach involving the company, and record timestamps correspond to points where its scanners operate. The company has not confirmed unauthorised access or its scope.
Was Hertz breached? No source establishes that. Victims found their scan timestamps matching their own rental dates, which locates where a capture was taken rather than identifying a breached custodian.
What single change recovers the most coverage? Making verification of ownership mandatory rather than optional, in the NIST sense of a returned code, a microtransaction or a completed authentication. It is the one requirement an image cannot answer.
Methodology and source notes
Every source cited was opened and read directly, including four primary documents quoted from their own text rather than from commentary: the AAMVA 2025 DL/ID Card Design Standard, ISO/IEC 30107-3:2023 as published in its preview, NIST SP 800-63A-4, and FinCEN's FIN-2024-Alert004. Incident facts rest on the Krebs on Security report that identified the service, with independent pickup by Malwarebytes Labs, Engadget and 9to5Mac corroborating the document counts and the infrared and ultraviolet detail.
Where reporting conflicts, the conflict is stated rather than resolved; the affected-brand list is the clearest case and is contradicted above. No figure, name or date appears here that was not read in a source we opened. Nothing here represents an analysis by DuckDuckGoose of the Nexus corpus or any breached record. No such analysis was performed and none is claimed. Last update: Q3 2026.














