Brian Krebs found his driver’s licence on the dark web because the criminals had chosen it for their advertisement.
They wanted buyers to see the quality of their product.
Krebs opened the dark-web service, called Nexus, and searched for himself. Six files appeared. The collection included the front and back of his licence under ordinary light, infrared and ultraviolet.
He searched for his mother. Nexus had her licence too.
The timestamps gave the records away. Someone had scanned both licences seconds apart. Krebs remembered exactly where it happened: a Hertz counter, where he and his mother had rented a car together.
He tried more names, with permission. Nine people found genuine identity documents. Dates and locations pointed back to car rentals, hotels and a Las Vegas cannabis dispensary.
The people behind Nexus claimed to hold more than 153 million driver’s licences, 10 million identity cards, three million travel documents and 579,000 medical cards from the United States and Canada.
Krebs tested the service. It returned genuine documents belonging to nine people he searched with permission. An empty search exposed roughly 11.5 million pages of results. A Canadian search produced approximately 1.1 million records, including 473,673 from Ontario.
Later that week, IDScan.net said an unauthorized third party may have accessed or copied certain customer information held on its cloud platform.
By then, Nexus had disappeared.
They did not steal a list of names
A name, address and date of birth can help someone impersonate you.
A complete driver’s licence gives them the evidence other companies ask you to produce when they want proof.
* Legal names
* Dates of birth
* Residential addresses
* Government document numbers
* Current portraits
* Signatures and physical descriptions
* Issue and expiry dates
* Machine-readable barcode data
* Front-and-back images
* Infrared and ultraviolet scans of document security features
Criminals spend enormous amounts of time trying to manufacture convincing identity documents. Nexus gave them genuine ones.
That difference matters inside a bank.
A fraudster trying to open an account can submit a real licence belonging to a real person. Someone calling a private bank’s service desk can read back the correct document number, address and date of birth. A team preparing a deepfake can train it on the portrait printed on the licence. A criminal targeting a family office can place the principal’s genuine ID inside a larger package containing forged bank statements, utility bills and corporate records.
The licence gives every other lie a foundation.
FinCEN has warned financial institutions about fraudsters combining identity documents with synthetic photographs, deepfake video and manipulated audio. FINRA’s 2026 regulatory report describes stolen identity information from dark-web markets driving new-account fraud, account takeovers and impersonation.
That machinery already exists. Nexus gives it higher-quality fuel.
One document. Four decisions.
Banks routinely ask for a passport or driver’s licence during onboarding. Hotels, casinos, car-rental companies, property firms and visitor-management systems do the same.
The scan often travels through several companies. One business asks for the document. Another provides the scanner. A third hosts the software. Additional providers inspect the barcode, compare the face or store the file.
Each handoff creates another place where the image can survive.
Many businesses then make a more dangerous mistake. They allow one convincing document to answer four separate questions.
Is the document genuine?
Infrared and ultraviolet captures help verification systems inspect physical security features. Barcode checks compare encoded information against text printed on the card.
Nexus allegedly possessed those specialized captures.
A verification system can correctly identify a document as genuine and still approve an attacker. The software has authenticated the licence. It has learned nothing about who controls it now.
Is this the person named on it?
Facial comparison links the applicant to the portrait. Liveness testing looks for a human being in front of the camera. Manipulation detection tries to catch face swaps, prerecorded video and generated images.
NIST separates document validation from verification of the person for good reason. They answer different questions.
A dark-web buyer begins with the real portrait. Modern face-generation tools can animate it. A recruited accomplice with a similar appearance can present it. Weak liveness testing gives both attempts a chance.
Does this person control a trusted channel?
A private bank already has years of relationship history: registered telephone numbers, known devices, established email addresses, prior locations, usual behaviour and trusted contacts.
That history carries enormous defensive value. Banks throw it away when they allow a new device and a freshly uploaded licence to override the existing relationship.
Attackers often aim for a smaller first victory. They replace the telephone number. They add an email address. They enrol a new device. They persuade a service employee to reset an authenticator.
Once the bank accepts the new channel, future requests arrive through a route the bank now considers legitimate.
What are they asking you to change, move or hand over?
Someone has passed the identity check. Now look at what they want.
They want to replace the telephone number the client has used for six years. They want a new email address added to the account. They want to enrol another device, change a beneficiary or send €8 million to a bank the client has never used before.
Stop the transaction.
Call the number already on file. Speak to another authorized person. Bring the client into the office. Hold the transfer long enough for the real client to discover it.
Never confirm a change through the telephone number, email address or device that the stranger is asking you to approve.
A genuine licence can help someone look like your client. It cannot explain why your client has suddenly abandoned every trusted part of the relationship.
Private wealth gives the document a longer reach
A criminal targeting a wealthy family wants far more than a new credit card.
The licence can reveal where the principal lives, what they look like, how they sign their name and when the document expires. Its scan history can connect them to a hotel, casino, rental-car office or private venue.
Add corporate filings, property records and exposed communications. The criminal now has enough material to study the family.
They can identify the principal’s spouse, children, assistant, trustee, lawyer and investment adviser. They can learn which person handles payments, who travels with the family and who answers urgent requests outside office hours.
Then they choose the weakest human connection.
The call to the family office sounds credible because the caller knows the principal’s full name, date of birth and licence number.
The email to the private banker arrives with a perfect scan attached.
The video meeting shows the right face.
The request mentions a real address and an actual journey.
Every correct detail reduces suspicion. The attacker needs the employee to make one mistake.
Credit monitoring will catch some new borrowing. It will not see a request inside a private bank. It will not warn a trustee that someone has submitted forged instructions. It will not tell a family that a criminal is using the principal’s identity to approach an assistant.
It also cannot retrieve a document from a criminal archive.
A replacement licence changes the document number and expiry date. The old scan still contains the person’s face, signature, date of birth and historical address. Criminals can keep using those details long after the issuing authority replaces the card.
Why were these files still there?
IDScan.net said an unauthorized third party accessed or copied customer information held inside customer accounts on its cloud platform.
That wording raises a blunt question: why were complete identity records still available?
Companies need to inspect identification. Retaining every image creates a separate decision with a separate risk.
Krebs traced his scan back to a car rental. The rental ended. The verification had already served its purpose. Yet the images remained somewhere in the chain.
Caesars Entertainment told Krebs that it had stopped using IDScan’s VeriScan product and had never authorized IDScan to retain its data. That statement exposes the contractual mess surrounding identity systems. The business collecting the ID can believe one thing. The provider can configure another. Backups, customer accounts and default retention settings can preserve the files for years.
The customer sees a scanner on a counter. Behind it sits a database.
The Federal Trade Commission tells businesses to keep sensitive information only for as long as a legitimate business need exists. The advice is simple because the mathematics are simple.
A platform that deletes an image after verification gives an intruder little history to steal.
A platform that keeps every scan becomes an identity warehouse.
What to do today
Start with the vendors.
List every company that receives passports, licences or residence permits from your clients, principals, relatives and employees. Include onboarding platforms, visitor systems, property managers, insurers, travel providers and software embedded inside another vendor’s service.
Then ask each one:
* Do you retain the raw document image?
* Do you keep the front, back, barcode, portrait, signature, ultraviolet scan or infrared scan?
* Where do you store those files?
* Which employees and contractors can see them?
* Can an administrator export them in bulk?
* Do customer environments share any infrastructure?
* Which subcontractors receive them?
* How long do backups preserve deleted records?
* Can you prove when a specific file was destroyed?
* Will your monitoring detect a mass download?
Do not accept a privacy policy as an answer. Ask for configuration records, retention schedules, audit logs, deletion evidence and the contract clauses that govern the data.
Then attack your own identity process.
Give your security team a genuine driver’s licence scan and tell them to take over a test account. Let them attempt to replace the registered telephone number, reset the authenticator, enrol a new device and issue a payment instruction.
Watch where they succeed.
That exercise will expose the real control far faster than a policy review. The weak point often sits inside account recovery, where an employee wants to help and the customer appears to know every answer.
Finally, protect the people whose documents have already escaped.
Notify their bankers and advisers. Establish a trusted callback number. Add an agreed verbal passphrase. Require a second authorized person for sensitive changes. Record which devices and channels belong to the client. Escalate any attempt to replace them.
Treat a licence image as exposed identity material. Stop treating it as the final word on who stands behind a request.
The licence still looks real because it is real
That is the brutal part of this incident.
The documents sold through Nexus did not need to fool an authentication engine. They belonged to real people. Companies had scanned them during ordinary transactions and stored the results.
Criminals then acquired the same evidence banks ask customers to present.
The FBI is investigating. The RCMP says it is monitoring the case. IDScan has begun notifying affected customers and offering identity-protection services.
Private banks, family offices and wealth managers already have enough information to act.
Assume a capable attacker can buy a genuine image of your client’s identity document.
Then design the account, the relationship and every high-value instruction so that the document alone gets them nowhere.
