Skip to content
-
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
News Pulse
News Pulse
  • Home
  • News
  • Sport
  • tech
  • Home
  • News
  • Sport
  • tech
Subscribe
Close

Search

News

Dark Web Sale of Driver’s License Scans Traced to ID Verification Vendor

By ZIZO
September 4, 2026 5 Min Read
0

An illicit website reportedly spent this week offering driver’s license scans, including the infrared and ultraviolet images banks use to detect fake IDs, before the site went offline. The service, called Nexus, claimed to hold more than 153 million driver’s licenses from the United States and Canada, along with millions of other identity documents, as cybersecurity journalist Brian Krebs first reported Tuesday.

How the Data Was Traced to IDScan.net

Krebs traced the images to IDScan.net, a New Orleans-based identity verification company, by searching the service for the licenses of more than a dozen friends and family members. He matched timestamps on the nine licenses he found against their travel and rental records. American Banker could not independently confirm the reporting because the Nexus site went offline within hours of Krebs’s publication, replaced by a message reading, “This service is no longer available,” according to an update Krebs appended to his report.

The FBI’s New Orleans field office confirmed it is looking into the incident but declined further comment while the investigation is open, a spokesperson told American Banker.

What Makes These Images Sensitive

Driver’s licenses contain security features that are invisible under ordinary light and appear only under ultraviolet or infrared. Banks often authenticate a license by checking these features rather than reading the front of the card. IDScan sells that check; its identity verification page for banks and credit unions says the process examines security features “only present under ultraviolet or infrared light.”

Krebs’s own driver’s license record listed on Nexus included six files, according to his Tuesday report: the front and back of his license in ordinary scan, infrared, and ultraviolet formats.

Banks are already struggling with AI-generated fake documents; now, the images that make their authentication checks work have reportedly been exposed. Once those images are copied, “the document carries less evidential weight in any process that relies on it alone,” Tim Rawlins, senior adviser and director of security at NCC Group, told American Banker.

“A driver’s license was never designed to operate like a password,” Rawlins said. “A customer can reset a password. They cannot reset their face, date of birth or identity document history.”

Rawlins advised banks that used the vendor to assume the images could resurface even though Nexus appears to be gone. “Closing a marketplace disrupts access,” he said. “It does not prove the files were deleted or that they were never copied elsewhere.”

How IDScan Reaches Banks

Jack Henry’s Fintech Integration Network, or FIN, listed IDScan.net as a member on Friday morning. FIN “gives fintechs direct access to Jack Henry’s technical resources to achieve product integration with our core platforms and complementary solutions,” Jack Henry’s page for it says, which “significantly” speeds up integration by “removing the financial institution as an intermediary while the work is completed.” In other words, a bank or credit union already using Jack Henry software can consult the FIN list to know which vendors integrate seamlessly.

IDScan performs more than 21 million verifications a month at more than 20,000 locations, the company said last year. It has not disclosed how many of those are banks or credit unions.

Jack Henry, one of the providers IDScan named as an integration partner, said IDScan had notified it that Jack Henry is not impacted, according to a spokesperson for the core provider. It is unclear whether the licenses offered on Nexus came from any banks or credit unions. Jack Henry disclosed a separate data breach this week, attributed to the extortion group ShinyHunters, which appears unrelated. No attacker has been identified in the reported IDScan incident.

IDScan's Response and Website Changes

IDScan has not explicitly confirmed a breach. However, on Thursday, the company added a prompt to its contact page asking visitors “concerned that your information may have been part of a security incident” to submit an inquiry.

IDScan has also removed or altered at least two pages on its website since Krebs published his report. First, its list of partner integrations now redirects to the contact form with the security incident callout. Second, the client list Krebs cited to identify potentially affected customers appears to have been removed. An archived version of the partner integrations list said IDScan’s software would “scan and authenticate IDs and send data and images directly into” a core system Jack Henry sells to credit unions.

IDScan’s outside public relations agency did not immediately answer questions about the webpage removals, the retention period of ID scans, or whether bank clients were affected by the reported Nexus breach.

Regulatory Context: No Requirement to Keep Scans

Federal customer identification rules, known as CIP rules, require a bank to record a description of whatever document it used to verify someone’s identity: the type, the number, where and when it was issued, and when it expires. Crucially, these rules do not require the bank to retain a of the document.

The examination manual used by bank examiners states that a bank “may keep copies of identifying documents that it uses to verify a customer’s identity; however, the CIP rule does not require it.” Keeping copies can be warranted depending on risk, according to the manual.

IDScan markets retention as a benefit; its page for banks says the software will “save an of each ID” and “automatically upload an of the ID directly into the customer profile.” What a vendor retains, how long it keeps it, and what happens to images when a contract ends are not set by identification rules—they are set by the contract.

Rawlins said that contract should be explicit about “logging, data segregation, retention, deletion, incident notification, access to evidence, audit rights, and independent assurance.” The weak point is usually enforcement, he said, because retention policies that “look good on paper” are often not reflected in how systems are actually configured.

If bank customers’ documents turn out to be in the breached set, notifying victims is the bank’s job under federal rules. Interagency guidelines place customer notification on the financial institution (not the vendor) when unauthorized access involves customer information maintained by a service provider. A bank can hire the vendor to send notices, but the duty remains with the bank, according to the guidelines.

Only 23% of community and midsize banks hold a contract clause making a vendor liable for a data breach, according to a 2024 Jones Walker survey of 125 banking executives.

Legal and Next Steps

So far, five proposed class actions have been filed against IDScan in federal court in New Orleans—four on Wednesday and one on Thursday, according to the court’s docket. The first lawsuit, Bunch v. IDScan.net, accuses the company of “impermissibly inadequate data security” and of failing to notify people whose information was taken, according to the complaint.

Rawlins advised banks still running the software to ask their vendor for evidence rather than assurances: what data it collected, where it stored it, who could reach it, where it moved after collection, and when it was deleted. “Broad assurances are not enough when the issue concerns identity evidence and customer verification controls,” he said.

Author

ZIZO

Follow Me
Other Articles
Previous

Barcelona’s Unprecedented Midfield Dilemma: Flick Faces a Decision That Won’t Please Everyone

Next

Al-Hilal’s Record-Breaking Deal Pushes Club’s Market Value Past One Billion Riyals

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Copyright 2026 — News Pulse. All rights reserved. Blogsy WordPress Theme