Skip to content

Leadership4 publishers3 min readPublished Updated

Stolen infrared and UV scans put the document check itself inside the IDScan.net breach

IDScan.net is notifying people about names and ID numbers and offering credit monitoring, while the records Brian Krebs examined each carried infrared and ultraviolet captures, the layer that document authentication actually tests.

The Board Room · Leadership desk

Illustration accompanying Stolen infrared and UV scans put the document check itself inside the IDScan.net breach

What happened

  • On August 31 a newly registered account on the Russian-language forum Exploit began advertising Nexus, a searchable service offering identity records on more than 170 million people across North America.
  • Timestamps on nine volunteers' records matched occasions when they had handed a license to a Hertz counter representative rather than to an airport checkpoint, pointing at IDScan.net's scanning terminals.
  • The FBI's New Orleans field office opened an investigation on September 1, and the Nexus marketplace went offline within hours of Krebs publishing.
  • IDScan.net said it took immediate steps to secure its systems, engaged third-party specialists to scope the incident, and is cooperating with federal law enforcement.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • contradiction The company scopes the loss to names and government-ID numbers, while the records Krebs examined contained multi-spectrum images; those two descriptions call for different remedies, and only the narrower one is being offered.
  • constraint Any onboarding, KYC or age-gating flow that leans on a scanned document plus its infrared and ultraviolet layer now rests on assumptions about an attacker's inventory rather than on the check itself.
  • exposure Rental desks, casinos, dispensaries and retailers that outsourced ID capture inherit an incident they did not run and cannot audit from their own logs.
  • precedent A stash amounting to months of one vendor's verification volume makes retention policy for verification artefacts, not accuracy claims, the term buyers will start negotiating.

A password can be rotated and a card number reissued, which is why the standard remedy after a breach is a reset. The infrared and ultraviolet layers of a driver's license are physical properties of the document, not secrets to be reset, and a multi-spectrum check works by asking whether the artefact in front of it behaves the way a genuine license behaves under those wavelengths. IDScan.net's documentation confirms it captures documents using infrared and ultraviolet light [6], and Krebs found his own record on Nexus held six files: front and back as a plain scan and again in infrared and ultraviolet versions, each with a timestamp appended to the filename [5]. Tech Times reads that inventory as capable of defeating the authentication systems those captures exist to feed [7]; what the public record does not contain is a documented instance of it being used that way.

The scale claims survive their own arithmetic. A blank search of Nexus returned roughly 11.5 million pages at about 15 records a page [3], which multiplies out to about 172.5 million records against an advertised figure of more than 170 million people [4]. The operators said they had been exfiltrating continuously for more than a year [11], and the license count grew by nearly 400,000 in the 24 hours Krebs watched it [12]; spreading 153 million licenses over a year averages about 419,000 a day [13], so the boast and the observed rate describe one operation rather than two. Set against IDScan.net's stated volume of more than 21 million verifications a month [9], 153 million licenses is roughly seven months of throughput [10], which points at retained images rather than a brief tap on live traffic.

IDScan.net's own notice describes a narrower loss. The company said an unauthorized third party may have accessed or copied customer information held in accounts on its cloud, and that the affected data may include full names and driver's license or other government-issued identification numbers [24]; the remedy on offer is free credit monitoring and identity protection [25]. That is a reasonable answer to financial identity theft, but it does nothing for a copied document image, because there is no reissue path for how a card someone has already photographed looks under infrared. The distance between the two descriptions of the loss is the distance between a notification letter a client can forward to customers and the control review a client needs to run.

The objection that the images only matter if an attacker can inject them into a verification pipeline, leaving a clerk holding a physical card untouched, holds at the counter and not in the remote flow: IDScan.net markets age-verified entry to websites as well as venues, plus employee card scanning for building access [26], and in remote onboarding the uploaded image is the artefact under test. The defensible position this quarter is that assurance from image-based document checks is now unverified; it has not been proven broken, and an unverified control should be priced differently from a working one.

The names in the file support the wider read. Fox 8 reported that Defense Secretary Pete Hegseth's Minnesota license was shown as the sales sample [22], and NOLA.com reported an assistant FBI director among those listed [23]. Zach Edwards of InfoBlox, whose own record traced to a Las Vegas dispensary [17], said no breach of driver's license data has occurred at this scale and that the actors appear both sophisticated and financially motivated [18]. Some records carried a source notation of CAC, which Krebs wrote may refer to Common Access Cards used for physical entry to government buildings [29]. The procurement question is narrower than this vendor's incident response: how long a verification vendor may keep the artefacts after the check has already returned a yes, since retained artefacts are what a later breach has to sell.

What to watch

  • Whether IDScan.net's third-party review restates the affected data categories to include stored document images rather than names and ID numbers.
  • Whether any bank supervisor or state regulator issues guidance downgrading image-based document authentication as a standalone control.
  • Whether the Nexus inventory resurfaces under another name after the Exploit listing went dark.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories