Bank ID vendor traced to a dark web license sale

Lake Elsinore, California, USA - Dec 18, 2022: Closeup of California Real ID driver license focusing on the REAL ID logo
Adobe Stock
  • Key insight: The records reportedly for sale paired ordinary scans of a license with its infrared and ultraviolet captures, which are the images a bank's authentication check reads.
  • Supporting data: IDScan.net says it performs more than 21 million verifications a month at more than 20,000 locations.
  • Forward look: Five proposed class actions were filed against IDScan.net in federal court in New Orleans within two days of the first report.

Overview bullets generated by AI with editorial review.

Processing Content

An illicit website reportedly spent this week selling driver's license scans, including the infrared and ultraviolet images banks use to catch fake IDs, before it went offline.

The service, called Nexus, claimed to offer more than 153 million driver's licenses from people in the United States and Canada along with millions of other identity documents, as cybersecurity journalist Brian Krebs first reported Tuesday.

Krebs traced the images to IDScan.net, a New Orleans identity verification company, by searching the service for the licenses of more than a dozen friends and family, then matching timestamps on the nine he found against their travel and rental records.

American Banker could not confirm the reporting because the Nexus site went offline within hours of Krebs publishing, replaced by a message reading, "This service is no longer available," according to an update Krebs appended to his report.

The FBI's New Orleans field office "can confirm that it is looking into the incident" and would say no more while the investigation is open, a spokesperson told American Banker.

IDScan sells document authentication to banks and credit unions. Its marketing material tells those customers it will save an image of every ID it scans.

IDScan reaches some of its customers through the Jack Henry Fintech Integration Network, a catalog of software that banks and credit unions running Jack Henry's core systems can add without building the connection themselves.

Jack Henry, one of the providers IDScan named as an integration partner, said IDScan had notified it that Jack Henry is not impacted, according to a spokesperson for the core provider. It is unclear whether the licenses offered on Nexus came from any banks or credit unions.

Jack Henry disclosed a data breach of its own this week, which the company attributed to the extortion group ShinyHunters. That incident appears to be separate. No attacker has been identified in the reported IDScan breach.

IDScan has not explicitly confirmed a breach. However, on Thursday, the company added a prompt to its contact page asking visitors "concerned that your information may have been part of a security incident" to submit an inquiry.

The images banks use to catch fakes

Driver's licenses carry security features that are invisible under ordinary light and show up only under ultraviolet or infrared. Banks often authenticate a license by checking those features, not by reading the front of the card.

IDScan sells that check; its identity verification page for banks and credit unions says the check examines security features "only present under ultraviolet or infrared light."

Krebs's own driver's license record listed in Nexus included six image files, according to his Tuesday report: the front and back of his license in an ordinary scan, in infrared and in ultraviolet.

Banks are already struggling with AI-generated fake documents; now, the images that make their authentication checks work have reportedly gotten out.

Once those images are copied, "the document carries less evidential weight in any process that relies on it alone," Tim Rawlins, senior adviser and director of security at NCC Group, told American Banker.

"A driver's license was never designed to operate like a password," Rawlins said. "A customer can reset a password. They cannot reset their face, date of birth or identity document history."

Banks that used the vendor should assume the images could resurface even though Nexus appears to be gone, he said.

"Closing a marketplace disrupts access," he said. "It does not prove the files were deleted or that they were never copied elsewhere."

How IDScan reaches banks

Jack Henry's Fintech Integration Network, or FIN, listed IDScan.net as a member on Friday morning.

FIN "gives fintechs direct access to Jack Henry's technical resources to achieve product integration with our core platforms and complementary solutions," Jack Henry's page for it says, which "significantly" speeds up integration by "removing the financial institution as an intermediary while the work is completed."

In other words, a bank or credit union that already uses Jack Henry software can then consult the FIN list to know the vendors with which it can seamlessly integrate.

IDScan performs more than 21 million verifications a month at more than 20,000 locations, the company said last year. It has not said how many are banks or credit unions.

IDScan has removed or altered at least two pages on its website since Krebs published his report on the security incident.

First, IDScan's list of partner integrations now redirects to the contact form with a callout for anyone concerned that their information was part of a security incident. Second, the client list Krebs cited to list potentially affected customers appears to have been removed.

An archived version of the list of partner integrations said IDScan's software would "scan and authenticate IDs and send data and images directly into" a core system Jack Henry sells to credit unions.

IDScan's outside public relations agency did not immediately answer questions about the webpage removals, the retention period of ID scans and whether bank clients were affected by the reported Nexus breach.

Nobody made banks keep the scans

Federal customer identification rules, known as CIP rules, require a bank to record a description of whatever document it used to verify someone's identity: the type, the number, where and when it was issued and when it expires.

Crucially, these rules do not require the bank to retain a picture of the document.

The examination manual from which bank examiners work says a bank "may keep copies of identifying documents that it uses to verify a customer's identity; however, the CIP rule does not require it."

Keeping copies can be warranted depending on risk, according to the manual.

IDScan sells the retention as a benefit; its page for banks says the software will "save an image of each ID" and "automatically upload an image of the ID directly into the customer profile."

What a vendor retains, how long it keeps it and what happens to the images when a contract ends are not set by the identification rules; they are set by the contract.

That contract should be explicit about "logging, data segregation, retention, deletion, incident notification, access to evidence, audit rights, and independent assurance," Rawlins said.

The weak point is usually enforcement, he said, because retention policies that "look good on paper" are often not reflected in how the systems are actually configured.

If bank customers' documents turn out to be in the breached set, relaying that to victims is the bank's job, per federal rules.

Interagency guidelines put customer notification on the financial institution (not the vendor) when unauthorized access involves customer information a service provider maintains. A bank can hire the vendor to send the notices, but the duty stays with the bank, according to the guidelines.

Only 23% of community and midsize banks hold a contract clause making a vendor liable for a data breach, according to a 2024 Jones Walker survey of 125 banking executives.

What's next

So far, five proposed class actions have been filed against IDScan in federal court in New Orleans, four Wednesday and one Thursday, according to the court's docket.

The first lawsuit accuses the company of "impermissibly inadequate data security" and of failing to tell the people whose information was taken, according to the complaint in Bunch v. IDScan.net.

Banks still running the software should be asking their vendor for evidence rather than assurances, Rawlins said: what data it collected, where it stored it, who could reach it, where it moved after collection and when it was deleted.

"Broad assurances are not enough when the issue concerns identity evidence and customer verification controls," he said.


For reprint and licensing requests for this article, click here.
Cyber Security Data breaches Identity verification Risk management Credit unions Litigation Technology
MORE FROM AMERICAN BANKER
Load More