CRITICAL: Massive USA Govt ID Data Breach (some CAN too)

For those who haven’t seen yet:

This is not so much an issue for Moqui proper, but various Moqui users rely on KYC systems that depend on this sort of data.

I don’t know that there are any changes to Moqui that could help with this sort of thing, but we may need to start looking at the digital ID systems that are emerging… both defensively and strategically. The US and CA are almost certainly going to require online digital ID now…

Nexus / IDScan-class breach — operational cheat sheet

As of: 2026-09-02 (day-of disclosure; facts will move)
Purpose: One page for the next call. Not a legal memo. Not an attribution brief.

What this is

A dark-web service (Nexus) advertised on the Russian crime forum Exploit offered searchable digital scans of ~153 million U.S. and Canadian driver’s licenses, plus other IDs (state IDs, travel docs, medical cards, and claimed CAC / employment-auth records). Sellers said they had been continuously exfiltrating for a year+, not dumping a static warehouse. Reporting and timestamps point at IDScan.net (New Orleans) — in-person document authentication used at rental counters, hotels, retail, dispensaries, and some FI / processor integrations (public client names have included Hertz, Planet13, Jack Henry, among others). FBI New Orleans opened an inquiry. The shop went dark after press. Copies were not recalled.

This is a stream compromise of a document-verification hose, not “a file server got copied last Tuesday.”

The one-sentence problem

Documentary CIP, age gates, help desks, and remote IDV all treat “the card is real and the face matches the card” as the trust root. A year of forensic-quality packs (visible + IR/UV, barcode, portrait, often a customer photo, timestamps) means that root is replayable against humans and against other vendors’ document-auth APIs.

Conventional monitoring that looks for wrong data will miss a large share of the damage.


What is not on fire (do not overclaim)

Still works Why
Physical card at TSA / in-person poll / bartender glance Trust root is issuance + person in front of you, not IDScan
REAL ID / passport boarding TSA is not this vendor
Passkeys / hardware keys / GitHub-style “we will not ID-restore 2FA” Possession of enrolled authenticator, not a JPEG
Core systems “being up” Availability ≠ identity integrity

No public evidence as of 2026-09-02 that TSA, major rental brands, nicotine e-comm, or social platforms turned off DL acceptance. Physical plastic is still honored. Online age gates are still collecting. That is the problem, not a contradiction.


Major risk points

1. Stock vs stream (the understatement)

A snapshot-at-rest breach is a list. A year-long quiet exfil is a factory.
Public “site is down / small impact” talk collapses those. New records were still being added after first press. Inventory outlives the storefront.

Action: Treat every control as if the adversary had a live feed, not a CSV from one night.

2. True-name new-account fraud (CIP / KYC)

USA PATRIOT CIP minimum is four fields (name, DOB, address, TIN) plus reasonable belief via documentary or non-documentary methods. The 2003 rule rejected mandatory photocopies; examiners and digital onboarding made the image the workpaper anyway.

Replay of a real DL + selfie/liveness against OpenAnywhere / IDV vendors produces accounts that look CIP-clean. Transaction monitoring tuned for synthetic IDs and mismatched data will not light up.

Action: Lookback population = digital (and high-risk branch) originations across the exfil window, not “apps since the news story.” Flag success-path CIP, not just fails.

3. Community banks, CUs, Jack Henry / Alkami-class stacks

Concentration risk: one scanner/IDV vendor sitting under many small FIs’ digital account open, teller imaging, and processor integrations. Hair-on-fire calls will be bilateral (platform + core/processor), not a blame contest.

Action: Inventory every path that sends a DL image off-box. Freeze new vendor writes if you can. Do not wait for the vendor’s SOC letter.

4. Lookback is the hard problem

Stopping the press prevents incremental damage. The mess is accounts and transactions already booked while the document was “correct.”

Action (tier the book):

  • A: Digital open + same-day external funding / rapid beneficiary add / device reuse
  • B: Any open in-window that used documentary IDV
  • C: In-window profile changes (address, phone, email, users, wires, ACH origination) on older accounts

Join core CIF + onboarding vendor logs + device / funding graph. 314(b) and SARs on clusters, not one-off “this name is in the news.”

5. Customer-service and account recovery (often worse than account opening)

Help desks are paid to believe a matching document. Recovery forms at many high-value sites (X-class, LinkedIn/Persona-class, ID.me-class, banks, carriers) still accept government photo ID ± selfie ± KBV.

GitHub is a rare counterexample: lose 2FA and recovery factors, support will not restore on an ID story.

Action: Privileged and high-risk accounts — ID-only restore off. Out-of-band only on a pre-enrolled channel. Queue high-value tickets. Retrain night-shift / BPO scripts this week, not next exam cycle.

6. Phishing and vishing, both directions

  • Criminal as customer → institution (“reset my 2FA / release the wire, my license is on file”).
  • Criminal as institution → customer (PDF that includes their actual license scan, “re-verify because of the breach”).
  • Criminal as vendor / processor / BSA officer → FI staff.

A real DL image in the phish is a step-function in conversion.

Action: One dull customer notice: nobody legitimate will ask you to re-upload a license because of this story. Same sentence for staff. Pre-enroll callback numbers.

7. SIM swap and reset-hub ATO

DL pack does not clone a SIM. It makes carrier CS easier (name, address, photo ID upload). Phone number then resets email, X, cloud, registrar.

Action: Passkeys. No SMS as a factor on anything you care about. Registrar / cloud root / email get hardware keys first.

8. Tax, benefits, insurance, medical admin

Thinner fraud teams than banks; more faith in documents. Medical cards were in the advertised mix. IRS / state / UI / marketplace / PBM call centers use the same KBV + “fax your license” pattern.

Action: If you operate any of those desks, apply §5–6. If you are an FI, expect secondary fraud that does not hit your CIP first.

9. Employment, I-9-adjacent, background, remote online notarization

Remote-hire IDV and RON platforms are “scan + selfie + KBA” with a legal stamp on the PDF. That is how a replayed image leaves the internet and enters a court or HR file.

Action: Treat RON / remote I-9 vendor as in-scope for the same lookback logic. Do not notarize off a vendor score alone for high-risk acts this month.

10. Age gates and online KYC (nicotine, social, cannabis delivery)

Statute is pushing more government-ID collection (state age laws), not less. Online vendors (Persona, Jumio, Onfido, AU10TIX, Veriff, …) are a different lake, same species. They will not turn off DL upload this week. In-person scan-at-door (dispensary / delivery) is closer to the IDScan pattern.

Action: Do not take “we are not the Louisiana company” as an architecture answer. Ask: do you persist the bitmap after the decision? Where does egress go?

11. Targeted physical safety and movement logs

Address + current government portrait + timestamps of scans (rental, hotel, dispensary) is a finder’s kit. Worse for people who depend on not being found (DV, protective orders, some protective programs) and for officials / journalists in the pile.

This will not show up as a SAR. It is still in-scope for “how bad.”

Action: Do not publish or internally gossip victim lists. Law-enforcement / shelter partners get a quiet channel, not a press quote.

12. Deepfakes and lookalikes

A well-lit DMV-quality portrait is the best face most people will ever leak. Pair with existing voice and social. Midterm and CS deepfakes get cheaper. This is additive, not the core crime model.

13. Secondary markets and vendor replay

Shop dark ≠ inventory gone. Packs get sliced (fullz + face + IR) and replayed at other IDV vendors. Those vendors authenticate security features; they do not ask “was this bitmap minted at a DMV this morning.”

Action: Assume other lakes exist. Demand delete-after-decision and pipeline logs from your IDV, not a quarterly SOC.

14. Election-window confidence (Nov 3, 2026 midterms)

Not a tabulation event. In-person poll check-in is not IDScan. Mail-ballot “attach a copy of photo ID” states are a sharper but still bounded edge.

The real electoral product is confidence and targeting: photo-ID-as-sacred-object vs photo-ID-as-honey-pot, SoS/clerk comms, spearphish of election offices, better intimidation kits (photo + address). Both political directions will use the same Krebs paragraph. Do not join a crime-forum rumor to the voter file.

15. Legislative / digital-ID response gap (SEDI as specimen)

Utah SEDI (SB 275 / Title 63A Ch. 20, 2026) is holder-controlled presentation, selective disclosure, verifier minimization, duty of loyalty — and does not drain the mandated, ID-correlated retention lakes at FIs, vendors, and age-gate processors. State tries to avoid being the liability sink; BSA 5-year CIP records and exam culture keep the cabinets.

Action: If someone says “digital ID fixes this,” ask what happens to the existing images and the hose. If the answer is a wallet demo, they missed the incident.

16. The cultural bug that created the lake

2003 CIP: description of the document is enough.
Exam + Red Flags (2008) + imaging systems + digital open: keep the richer object.
SOC 2 / GLBA: protect the cabinet.
PCI: trained the questionnaire muscle; never forbade identity-document retention.

Stream hardening (egress allow-list, volume/destination anomaly, delete-after-decision, scanner/SDK supply chain, right to pipeline logs in hours) was almost never a named, independently tested control. Encryption-at-rest and a SOC report can both be true while someone lives on the hose for a year.


Ranking mitigations (for the call)

  1. Support / reset / vishing — ID-only restore off for privileged and high-risk; pre-enrolled out-of-band; staff + customer “we will not ask you to re-upload.”
  2. Lookback — originations and beneficiary / wire / contact changes across the exfil window; device + funding graph; 314(b).
  3. Instrument the hose — who still scans or receives uploads; freeze writes; demand egress logs; delete-after-decision.
  4. Passkeys / hardware keys on email, registrar, cloud root, privileged SaaS.
  5. Do not spend the week on retention-policy punctuation or a digital-wallet RFP unless (3) is in motion.

Confidence loss is the meta-risk

Every constituency reads a different disaster off the same artifact: BSA officers see mule books; CS leaders see ticket queues; privacy counsel sees another lake; clerks see October questions; targeted-harm people see a finder kit; digital-ID vendors see a sales cycle; voters see a Cabinet secretary’s license on a Russian forum.

Those are all real. They are not the same control failure. The shared failure is document-image-as-proof plus unaudited stream. Until that changes, this cheat sheet will keep coming off the shelf.

Here is an updated risk assessment, incorporating ID verification event unreliability across the industry.

Gov-ID verification events after the Nexus/IDScan reporting — operator note

As of: 2026-09-03
Incident facts: See Krebs / subsequent press. Dark-web service advertised a large corpus of U.S. and Canadian driver’s-license scans (plus other IDs), claimed continuous exfil over ~a year from a commercial identity-verification hose, not a one-night warehouse copy. FBI inquiry reported. Storefront went dark. Copies were not recalled.

This note is for people who run onboarding, KYC, help desks, or document-scan widgets — including stacks in the Moqui/OFBiz neighborhood. It is not a how-to, not attribution, not legal advice.

Canonical claim

Not: every identity database is wrong.
Not: DMV / SSA issuance tables are poisoned.
Yes: every identity-verification event in the reported window that treated a government-issued ID image or scan as proof of presence is an unreliable event. Downstream systems that stored that event as a fact — “CIP complete,” a bureau inquiry that exists because of the open, a reusable “already verified” / age token, “log into the bank we opened last year” — inherited unreliability without holding a bad byte.

Issuance-valid (“this license number belongs to this name”) is what a stolen real card is. It does not prove the person at the endpoint is that person.

Sort key: time × event type, then treat caches of those events as tainted. You cannot find this with a data-quality rule that hunts for misspelled names.

In the event class: remote upload or an in-person scan that wrote an image into a vendor hose (rental-counter class), not only phone-camera apps.
Out: pre-window events; possession factors not derived from that act; issuance lookups that were never treated as presence.

What this is not

Physical cards still work at a human checkpoint (TSA, bartender, poll worker looking at plastic and a face). Passkeys and hardware keys still work. State mDL issuer signatures are a different root than a JPEG of a plastic card. Cores being “up” is availability, not identity integrity. Nobody serious should claim tabulation-level election impact from this; confidence and help-desk risk are the election-adjacent issues.

Why “the other vendor” does not save you

Commercial document-auth was built to catch counterfeits. A genuine card image is supposed to pass. A second vendor running the same test is not an independent root. A cryptographic wrapper around “we checked a card at time T” signs the binding; it does not create presence.

Non-documentary checks that only ask whether name / DOB / address / TIN exist as a file were always true-name-passable. Documentary CIP was the increment that made remote open feel safe. That increment is what this incident breaks.

After months of quiet opens, other systems cache those opens as “existing relationship.” Time launders the event into the graph. That is why this gets worse toward the present, not better when the shop goes dark.

Lookback (events, not open_date)

The damage is not only accounts opened since the news story.

  • Binding acts in the window: digital open, and also re-KYC, address/phone/email change, recovery, scan-to-transact on an old customer.
  • If the core says “CIP complete” and you never stored vendor request id + timestamp, you cannot list your own events. That join is the first job.
  • Do not hunt “wrong” attributes. Hunt the acts and the caches they wrote.
  • Do not publish victim lists.

Do not mint another event of the same class

The reflex — “step up: upload your license again” — reproduces the failure with your name on it.

Customer and staff sentence, one line: nobody legitimate will ask you to re-upload a government ID because of this story.

Step-up has to be a different class: a factor enrolled before the window, a pre-enrolled out-of-band channel, in-person that does not dump another image into the same class of hose, or a graph used as a veto (new device + new payee + old name), not as a second copy of the four CIP fields.

ID-only account restore for privileged or high-risk accounts should go off until that different class exists.

What you can still treat as an oracle (short)

  • Pre-window events (when the act happened), not merely pre-window attributes.
  • Possession bound without creating another image-pass.
  • Multi-year cash-flow from a stable counterparty into an instrument (not “a deposit account exists”).
  • Description-only teller events that never wrote an image into a hose — weak evidence, not this artifact.

Absence from this lake is not proofed. Thin-file / new-to-country / young-adult digital open is not proofable at the assurance many shops were selling. That is a business-model fact, not only a compliance finding.

You cannot send the bureaus a file that says “these identities are false.” You can mark relationships and events: do not treat this proofing act as independent corroboration.

Hose, not cabinet

Encryption at rest and a SOC report do not speak to a year on the pipe. Ask whoever still takes a government-ID image: do you persist the bitmap after the decision, where does egress go, can we see pipeline logs in hours, can we default to delete-after-decision. Digital-ID wallets do not drain lakes that law and exam practice already required someone to keep.

If you ship this kind of widget (Moqui / OFBiz / commerce)

  • Inventory every path that sends a government-ID image off-box.
  • Stop treating “vendor said pass” as presence for high-risk acts (account open, payout, recovery, age-gated fulfillment that you will have to defend).
  • Do not add a scan-to-verify feature this month to “be safer.”
  • Join verification metadata to the customer record now, or you will not be able to sort later.