Invest1 distinct publisher3 min readPublished
The infrared and ultraviolet captures a bank reads to prove a license is genuine were reportedly on sale beside the ordinary scans, which leaves the cheapest step in account opening deciding nothing on its own.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
A document check earns its fee by being cheap and hard to fake at once: the features that settle it are invisible under ordinary light and show up only under ultraviolet or infrared, and a bank reads those rather than the front of the card [17]. Copy the captures and the fee survives while the decision does not, which is the narrow point Tim Rawlins, senior adviser and director of security at NCC Group, made to American Banker when he said the document "carries less evidential weight in any process that relies on it alone" [14]. IDScan.net's own figure, more than 21 million verifications a month at more than 20,000 locations [6], works out to roughly 1,050 checks per site per month, call it 35 a day [1], and about 252 million a year [2]. Nexus's claimed catalogue of more than 153 million licenses [1] is around 7.3 months of that stated throughput [3] - a comparison of scale, and nothing about where the records actually came from. American Banker could not confirm the reporting, because the site went offline within hours of publication behind a message reading "This service is no longer available" [4], and it is unclear whether any of the licenses came from banks or credit unions at all [13]. The part that compounds is retention. IDScan's marketing tells its bank and credit union customers it will save an image of every ID it scans [10], and the record Krebs found for his own license listed six files, front and back in ordinary scan, in infrared and in ultraviolet [18]. Verification itself is a flow business, but saved images pile up into a stock, and that stock is what the New Orleans suits will try to size. Distribution is the other half of the puzzle. IDScan reaches some customers through the Jack Henry Fintech Integration Network, whose pitch is that it speeds integration by "removing the financial institution as an intermediary while the work is completed" [19][11]. Jack Henry's spokesperson said IDScan had notified it that Jack Henry is not impacted [12], which is an assurance sourced to a vendor that has not explicitly confirmed a breach [8] and whose partner-integration page now redirects to a contact form carrying a callout for anyone worried their information was in a security incident [9]. If the images came off retail age-check counters rather than account opening, the exposure at banks sits in contract and reputation, apart from fraud loss [13]. A scoped record count from IDScan turns five proposed class actions [7] into a settlement number and caps the tail. And if Rawlins is right that closing a marketplace "does not prove the files were deleted or that they were never copied elsewhere" [16], the captures keep circulating and nothing about the shutdown matters to a bank's controls. The durable cost here falls on the buyers rather than the vendor: any institution that treated the ultraviolet and infrared read as decisive now needs a second factor behind it, and second factors cost more per account than reading a card. What would break that thesis is narrower than it looks. If the timestamp matching on nine licenses against travel and rental records [3] does not hold, the chain to this particular vendor goes with it; or rather, the more interesting version, if the capture read is already one input among several a bank cross-references, then Rawlins's qualifier about a process that relies on the document alone describes a process few banks run, and his line that a customer "cannot reset their face, date of birth or identity document history" [15] is a fair warning about people, separate from any loss estimate for banks.
Ranked by verification strength, evidence, and original report placement.
An illicit service called Nexus claimed to offer more than 153 million driver's licenses from people in the United States and Canada, along with millions of other identity documents, according to cybersecurity journalist Brian Krebs.
The records reportedly for sale paired ordinary scans of a license with its infrared and ultraviolet captures, which are the images a bank's authentication check reads.
Krebs traced the images to IDScan.net, a New Orleans identity verification company, by searching the service for the licenses of more than a dozen friends and family, then matching timestamps on the nine he found against their travel and rental records.
American Banker could not confirm the reporting because the Nexus site went offline within hours of Krebs publishing, replaced by a message reading, "This service is no longer available," according to an update Krebs appended to his report.
The FBI's New Orleans field office "can confirm that it is looking into the incident" and would say no more while the investigation is open, a spokesperson told American Banker.
IDScan.net says it performs more than 21 million verifications a month at more than 20,000 locations.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Krebs traced 153 million leaked driver's licence scans to a single Louisiana ID verifier1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
product
World open-sources ProveKit to keep age checks on the user's own phone1 distinct publisher
security
AFP charges two men near Perth over the self-spreading worm behind the TeamPCP compromises1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Secondhand where it counts most
The sale itself is reported at one remove: American Banker is relaying Krebs's searches and says outright that it could not confirm them, because the site was gone within hours of his post. The checkable material sits around the allegation rather than inside it, and it is real enough: an on-record FBI New Orleans acknowledgement, five docketed complaints, Jack Henry's statement, and the publication's own before-and-after look at IDScan's pages. Krebs's method, matching timestamps on nine found licenses against known trips and rentals, is described well enough to evaluate, but nobody outside his browser ever saw the catalogue.
Vendor-stated footprint, unknown exposure
The scale figures are the sturdiest numbers in the story and they still come from the vendor: 21 million verifications a month at more than 20,000 locations, which works out to about 35 a day per location and roughly 252 million a year. Distribution is documented too, through Jack Henry's integration catalogue. What cannot be counted is the part banks care about, since the client list that would name potentially affected institutions came down after publication and the reporting says plainly that the licenses' origin inside that customer base is unresolved.
A seller's number carries the scale
The 153 million figure that sets the story's size is a shuttered shop's own advertising. No one can audit that number, yet it is doing the headline work; set against IDScan's disclosed throughput it would be about seven months of scanning, which is suggestive rather than corroborating. American Banker keeps the overstatement small by labelling what it could not check in its fourth paragraph and by noting that whether bank customers are in the set is unknown. The gap that remains is between a precise-sounding catalogue count and the absence of anyone who has inspected it.
Every statement here is an interested one
Read the sourcing and the shape of each statement follows from who made it. Jack Henry's "not impacted" reaches the reader through IDScan's own notification to Jack Henry. IDScan sold image retention to banks as a benefit, and its partner page now routes worried visitors to a contact form while the client list Krebs used has changed. Plaintiffs' firms had five complaints filed within two days of a report nobody had verified. The security adviser quoted on the contract clauses banks should demand works for a consultancy that sells assurance against exactly that gap, a conflict worth weighing alongside his judgement.
One desk, one trail, a silent vendor
Our confidence is capped by arithmetic on sources: a single publication, working from a single journalist's search of a marketplace that no longer exists, with the company at the centre declining to say whether anything happened. The three documents that would settle it, a retention schedule, a customer list and a denial or admission, are the three things IDScan's PR agency was asked for and did not provide. Everything downstream of that, including the forecast that copies will resurface, rests on a single adviser's judgement.