The ID Check Worked. It Left 153 Million Copies Behind.


A dark web service spent the final days of August advertising digital scans of more than 153 million United States and Canadian driver's licenses, according to reporting by Brian Krebs. The FBI's New Orleans field office opened an investigation into the service on September 1, and the listing disappeared from the forum a day later.
The scale is worth sitting with. Alongside the driver's licenses were more than 10 million identification cards, more than 3 million passports and international travel documents, and hundreds of thousands of medical cards. Ontario alone accounted for over 473,000 Canadian records.
What was actually for sale
The service was selling photographs of documents rather than the data printed on them, and each record reportedly carried several: front and back captures, a basic scan, and infrared and ultraviolet captures of the security features that make a license hard to counterfeit. Filenames carried dates and timestamps.
According to the reporting, the records were collected over roughly a year from the identity verification pipelines of customers of IDScan.net, a New Orleans vendor that processes more than 21 million verifications a month across more than 20,000 locations. The captures were traced to ordinary transactions: a rental car counter, a hotel front desk, an age check at a retail counter.
Most of the 153 million people in that database did nothing unusual, having handed over a license simply because the process asked for one. The check itself worked as designed, and the exposure lies entirely in what it left behind.
A license is a bearer credential
A driver's license carries no cryptographic binding to the person holding it, because its security model is physical: it assumes a human being is looking at the real card in real light, checking the hologram, the microprint, and the ultraviolet layer.
Strip away the physical card and that model collapses, because whoever holds a sufficiently complete copy of a license can present it as their own. The infrared and ultraviolet captures matter for exactly this reason. They are the layers a remote verification system checks to decide whether a document is genuine, which makes a database of those captures a database of answers to the test.
There is also no remediation path. A breached password can be rotated and a compromised payment card reissued, but no state is going to reissue 153 million driver's licenses, and the numbers, names, addresses, and dates of birth in those images stay valid for years.
Why a working process produced the exposure
This is the part that deserves more attention than the breach itself.
Scanning a document to verify someone does two things at once: it answers the question the business actually asked, and it manufactures a durable, reusable image of a government credential that nobody asked for and almost every process quietly creates.
That second artifact then accumulates, sitting in a vendor's storage, replicated across environments and retained under a policy nobody revisits, for a verification event that concluded in four seconds two years ago. A single vendor operating at 21 million checks a month becomes a concentration of that risk on behalf of every business that integrated it.
The organizations whose counters produced these scans were following a process considered good practice across hospitality, retail, gaming, and mobility, which is precisely what makes the outcome worth examining. The process itself produced the exposure.
Verification does not require retention
There is a different architecture available, and it separates the answer from the artifact.
Proof verifies a person once at NIST IAL2, the federal standard for identity assurance, using government ID capture, liveness detection, and biometric comparison, with live human review available for high-consequence transactions. That verified identity is then issued as a cryptographic identity credential anchored in PKI and bound biometrically to the person it belongs to.
What that changes downstream is the shape of what a business holds. A relying party receives cryptographic evidence that a named authority verified this person to a published standard, and it does not need to capture, transmit, or store the document to get that assurance. The credential is portable, tamper-evident, court-admissible, and revocable, which is the one property a leaked image can never have.
The distinction is between a copy and a proof. A copy is a bearer instrument, valuable to anyone who obtains it and impossible to withdraw. A proof is bound to a person and to an issuing authority, which means it can be checked, relied on, and revoked.
Proof has spent a decade doing this work in transactions where the money does not come back, with more than $640 billion in real estate transactions secured.
What to ask of any identity vendor
Three questions surface most of the exposure.
Where do the document images go after the check returns, and how long are they kept? What is the retention policy for infrared and ultraviolet captures specifically? And if that vendor were breached tomorrow, what would an attacker hold, and what could be revoked?
For most identity processes running today, the honest answer to the last question is that an attacker would hold usable copies of government credentials, and nothing could be revoked at all.
If you'd like to see how Proof verifies identity without leaving a document copy behind, you can book time with our team here.




































.jpg)





























































.jpg)






































