- Key insight: The records reportedly for sale paired ordinary scans of a license with its infrared and ultraviolet captures, which are the images a bank's authentication check reads.
- Supporting data: IDScan.net says it performs more than 21 million verifications a month at more than 20,000 locations.
- Forward look: Five proposed class actions were filed against IDScan.net in federal court in New Orleans within two days of the first report.
Overview bullets generated by AI with editorial review.
An illicit website reportedly spent this week selling driver's license scans, including the infrared and ultraviolet images banks use to catch fake IDs, before it went offline.
The service, called Nexus, claimed to offer more than 153 million driver's licenses from people in the United States and Canada along with millions of other identity documents, as cybersecurity journalist Brian Krebs
Krebs traced the images to IDScan.net, a New Orleans identity verification company, by searching the service for the licenses of more than a dozen friends and family, then matching timestamps on the nine he found against their travel and rental records.
American Banker could not confirm the reporting because the Nexus site went offline within hours of Krebs publishing, replaced by a message reading, "This service is no longer available," according to an update Krebs appended to his report.
The FBI's New Orleans field office "can confirm that it is looking into the incident" and would say no more while the investigation is open, a spokesperson told American Banker.
IDScan sells document authentication to banks and credit unions. Its marketing material tells those customers it will save an image of every ID it scans.
IDScan reaches some of its customers through the Jack Henry Fintech Integration Network, a catalog of software that banks and credit unions running Jack Henry's core systems can add without building the connection themselves.
Jack Henry, one of the providers IDScan named as an integration partner, said IDScan had notified it that Jack Henry is not impacted, according to a spokesperson for the core provider. It is unclear whether the licenses offered on Nexus came from any banks or credit unions.
Jack Henry
IDScan has not explicitly confirmed a breach. However, on Thursday, the company added a prompt to its
The images banks use to catch fakes
Driver's licenses carry security features that are invisible under ordinary light and show up only under ultraviolet or infrared. Banks often authenticate a license by checking those features, not by reading the front of the card.
IDScan sells that check; its
Krebs's own driver's license record listed in Nexus included six image files, according to his Tuesday report: the front and back of his license in an ordinary scan, in infrared and in ultraviolet.
Banks are already
Once those images are copied, "the document carries less evidential weight in any process that relies on it alone," Tim Rawlins, senior adviser and director of security at NCC Group, told American Banker.
"A driver's license was never designed to operate like a password," Rawlins said. "A customer can reset a password. They cannot reset their face, date of birth or identity document history."
Banks that used the vendor should assume the images could resurface even though Nexus appears to be gone, he said.
"Closing a marketplace disrupts access," he said. "It does not prove the files were deleted or that they were never copied elsewhere."
How IDScan reaches banks
Jack Henry's
FIN "gives fintechs direct access to Jack Henry's technical resources to achieve product integration with our core platforms and complementary solutions," Jack Henry's page for it says, which "significantly" speeds up integration by "removing the financial institution as an intermediary while the work is completed."
In other words, a bank or credit union that already uses Jack Henry software can then consult the FIN list to know the vendors with which it can seamlessly integrate.
IDScan performs more than 21 million verifications a month at more than 20,000 locations, the company
IDScan has removed or altered at least two pages on its website since Krebs published his report on the security incident.
First, IDScan's list of partner integrations now redirects to the contact form with a callout for anyone concerned that their information was part of a security incident. Second, the client list Krebs cited to list potentially affected customers appears to have been removed.
IDScan's outside public relations agency did not immediately answer questions about the webpage removals, the retention period of ID scans and whether bank clients were affected by the reported Nexus breach.
Nobody made banks keep the scans
Federal
Crucially, these rules do not require the bank to retain a picture of the document.
The
Keeping copies can be warranted depending on risk, according to the manual.
IDScan sells the retention as a benefit; its page for banks says the software will "save an image of each ID" and "automatically upload an image of the ID directly into the customer profile."
What a vendor retains, how long it keeps it and what happens to the images when a contract ends are not set by the identification rules; they are set by the contract.
That contract should be explicit about "logging, data segregation, retention, deletion, incident notification, access to evidence, audit rights, and independent assurance," Rawlins said.
The weak point is usually enforcement, he said, because retention policies that "look good on paper" are often not reflected in how the systems are actually configured.
If bank customers' documents turn out to be in the breached set, relaying that to victims is the bank's job, per federal rules.
Only 23% of community and midsize banks hold a contract clause making a vendor liable for a data breach,
What's next
So far, five proposed class actions have been filed against IDScan in federal court in New Orleans, four Wednesday and one Thursday, according to the court's docket.
The first lawsuit accuses the company of "impermissibly inadequate data security" and of failing to tell the people whose information was taken, according to
Banks still running the software should be asking their vendor for evidence rather than assurances, Rawlins said: what data it collected, where it stored it, who could reach it, where it moved after collection and when it was deleted.
"Broad assurances are not enough when the issue concerns identity evidence and customer verification controls," he said.












