An illicit website reportedly offered millions of driver’s license scans, including the infrared and ultraviolet images banks rely on to detect fake IDs, before going offline. The service, called Nexus, claimed to have more than 153 million driver’s licenses from the U.S. and Canada, as first reported by cybersecurity journalist Brian Krebs.

How the Leak Was Traced

Krebs traced the images to IDScan.net, a New Orleans-based identity verification company, by searching for licenses of friends and family and matching timestamps against travel records. The Nexus site went offline shortly after the report, displaying a message that the service was no longer available. The FBI’s New Orleans field office confirmed it is investigating the incident.

What Makes These Images Critical

Driver’s licenses contain security features invisible under normal light, visible only under ultraviolet or infrared. Banks often authenticate IDs by checking these features, not just the front of the card. IDScan.net markets this capability, stating it examines security features present only under UV or IR light. The leaked records reportedly included front and back scans, plus infrared and ultraviolet captures.

Once these images are exposed, the document’s reliability in verification processes diminishes. As Tim Rawlins, senior advisor at NCC Group, noted, “A driver’s license was never designed to operate like a password. A customer can reset a password. They cannot reset their face, date of birth or identity document history.” Even if the marketplace is closed, the files may still exist elsewhere.

IDScan.net’s Role and Reach

IDScan.net provides document authentication to banks and credit unions, often through integrations like the Jack Henry Fintech Integration Network. The company claims to perform over 21 million verifications monthly at more than 20,000 locations. Jack Henry stated that IDScan.net notified it that Jack Henry is not impacted, though it’s unclear if any bank customers were affected.

IDScan.net has not explicitly confirmed a breach but added a prompt on its contact page for those concerned about a security incident. It also removed or altered some web pages, including its partner integrations list and client list.

Regulatory and Contractual Gaps

Federal Customer Identification Program (CIP) rules require banks to record a description of the ID used for verification, but not to retain a copy of the document. The examination manual states that keeping copies is optional, not required. However, IDScan.net markets image retention as a benefit, saving an image of each ID and uploading it to customer profiles.

What a vendor retains, how long, and what happens after a contract ends are determined by the contract, not by regulation. Contracts should specify logging, data segregation, retention, deletion, incident notification, and audit rights. Rawlins emphasized that enforcement is often weak, with policies not reflected in actual system configurations.

If customer documents are involved, the bank—not the vendor—is responsible for notifying affected individuals, per interagency guidelines. Only 23% of community and midsize banks have contract clauses holding vendors liable for breaches, according to a 2024 survey.

Legal and Next Steps

Five proposed class actions have been filed against IDScan.net in federal court in New Orleans, accusing the company of inadequate data security and failure to notify victims. Banks using the software should demand evidence from the vendor about data collection, storage, access, movement, and deletion, rather than relying on broad assurances.

By Ryan

Leave a Reply

Your email address will not be published. Required fields are marked *