Nexus / IDScan-class breach — operational cheat sheet
As of: 2026-09-02 (day-of disclosure; facts will move)
Purpose: One page for the next call. Not a legal memo. Not an attribution brief.
What this is
A dark-web service (Nexus) advertised on the Russian crime forum Exploit offered searchable digital scans of ~153 million U.S. and Canadian driver’s licenses, plus other IDs (state IDs, travel docs, medical cards, and claimed CAC / employment-auth records). Sellers said they had been continuously exfiltrating for a year+, not dumping a static warehouse. Reporting and timestamps point at IDScan.net (New Orleans) — in-person document authentication used at rental counters, hotels, retail, dispensaries, and some FI / processor integrations (public client names have included Hertz, Planet13, Jack Henry, among others). FBI New Orleans opened an inquiry. The shop went dark after press. Copies were not recalled.
This is a stream compromise of a document-verification hose, not “a file server got copied last Tuesday.”
The one-sentence problem
Documentary CIP, age gates, help desks, and remote IDV all treat “the card is real and the face matches the card” as the trust root. A year of forensic-quality packs (visible + IR/UV, barcode, portrait, often a customer photo, timestamps) means that root is replayable against humans and against other vendors’ document-auth APIs.
Conventional monitoring that looks for wrong data will miss a large share of the damage.
What is not on fire (do not overclaim)
| Still works |
Why |
| Physical card at TSA / in-person poll / bartender glance |
Trust root is issuance + person in front of you, not IDScan |
| REAL ID / passport boarding |
TSA is not this vendor |
| Passkeys / hardware keys / GitHub-style “we will not ID-restore 2FA” |
Possession of enrolled authenticator, not a JPEG |
| Core systems “being up” |
Availability ≠ identity integrity |
No public evidence as of 2026-09-02 that TSA, major rental brands, nicotine e-comm, or social platforms turned off DL acceptance. Physical plastic is still honored. Online age gates are still collecting. That is the problem, not a contradiction.
Major risk points
1. Stock vs stream (the understatement)
A snapshot-at-rest breach is a list. A year-long quiet exfil is a factory.
Public “site is down / small impact” talk collapses those. New records were still being added after first press. Inventory outlives the storefront.
Action: Treat every control as if the adversary had a live feed, not a CSV from one night.
2. True-name new-account fraud (CIP / KYC)
USA PATRIOT CIP minimum is four fields (name, DOB, address, TIN) plus reasonable belief via documentary or non-documentary methods. The 2003 rule rejected mandatory photocopies; examiners and digital onboarding made the image the workpaper anyway.
Replay of a real DL + selfie/liveness against OpenAnywhere / IDV vendors produces accounts that look CIP-clean. Transaction monitoring tuned for synthetic IDs and mismatched data will not light up.
Action: Lookback population = digital (and high-risk branch) originations across the exfil window, not “apps since the news story.” Flag success-path CIP, not just fails.
3. Community banks, CUs, Jack Henry / Alkami-class stacks
Concentration risk: one scanner/IDV vendor sitting under many small FIs’ digital account open, teller imaging, and processor integrations. Hair-on-fire calls will be bilateral (platform + core/processor), not a blame contest.
Action: Inventory every path that sends a DL image off-box. Freeze new vendor writes if you can. Do not wait for the vendor’s SOC letter.
4. Lookback is the hard problem
Stopping the press prevents incremental damage. The mess is accounts and transactions already booked while the document was “correct.”
Action (tier the book):
- A: Digital open + same-day external funding / rapid beneficiary add / device reuse
- B: Any open in-window that used documentary IDV
- C: In-window profile changes (address, phone, email, users, wires, ACH origination) on older accounts
Join core CIF + onboarding vendor logs + device / funding graph. 314(b) and SARs on clusters, not one-off “this name is in the news.”
5. Customer-service and account recovery (often worse than account opening)
Help desks are paid to believe a matching document. Recovery forms at many high-value sites (X-class, LinkedIn/Persona-class, ID.me-class, banks, carriers) still accept government photo ID ± selfie ± KBV.
GitHub is a rare counterexample: lose 2FA and recovery factors, support will not restore on an ID story.
Action: Privileged and high-risk accounts — ID-only restore off. Out-of-band only on a pre-enrolled channel. Queue high-value tickets. Retrain night-shift / BPO scripts this week, not next exam cycle.
6. Phishing and vishing, both directions
- Criminal as customer → institution (“reset my 2FA / release the wire, my license is on file”).
- Criminal as institution → customer (PDF that includes their actual license scan, “re-verify because of the breach”).
- Criminal as vendor / processor / BSA officer → FI staff.
A real DL image in the phish is a step-function in conversion.
Action: One dull customer notice: nobody legitimate will ask you to re-upload a license because of this story. Same sentence for staff. Pre-enroll callback numbers.
7. SIM swap and reset-hub ATO
DL pack does not clone a SIM. It makes carrier CS easier (name, address, photo ID upload). Phone number then resets email, X, cloud, registrar.
Action: Passkeys. No SMS as a factor on anything you care about. Registrar / cloud root / email get hardware keys first.
8. Tax, benefits, insurance, medical admin
Thinner fraud teams than banks; more faith in documents. Medical cards were in the advertised mix. IRS / state / UI / marketplace / PBM call centers use the same KBV + “fax your license” pattern.
Action: If you operate any of those desks, apply §5–6. If you are an FI, expect secondary fraud that does not hit your CIP first.
9. Employment, I-9-adjacent, background, remote online notarization
Remote-hire IDV and RON platforms are “scan + selfie + KBA” with a legal stamp on the PDF. That is how a replayed image leaves the internet and enters a court or HR file.
Action: Treat RON / remote I-9 vendor as in-scope for the same lookback logic. Do not notarize off a vendor score alone for high-risk acts this month.
10. Age gates and online KYC (nicotine, social, cannabis delivery)
Statute is pushing more government-ID collection (state age laws), not less. Online vendors (Persona, Jumio, Onfido, AU10TIX, Veriff, …) are a different lake, same species. They will not turn off DL upload this week. In-person scan-at-door (dispensary / delivery) is closer to the IDScan pattern.
Action: Do not take “we are not the Louisiana company” as an architecture answer. Ask: do you persist the bitmap after the decision? Where does egress go?
11. Targeted physical safety and movement logs
Address + current government portrait + timestamps of scans (rental, hotel, dispensary) is a finder’s kit. Worse for people who depend on not being found (DV, protective orders, some protective programs) and for officials / journalists in the pile.
This will not show up as a SAR. It is still in-scope for “how bad.”
Action: Do not publish or internally gossip victim lists. Law-enforcement / shelter partners get a quiet channel, not a press quote.
12. Deepfakes and lookalikes
A well-lit DMV-quality portrait is the best face most people will ever leak. Pair with existing voice and social. Midterm and CS deepfakes get cheaper. This is additive, not the core crime model.
13. Secondary markets and vendor replay
Shop dark ≠ inventory gone. Packs get sliced (fullz + face + IR) and replayed at other IDV vendors. Those vendors authenticate security features; they do not ask “was this bitmap minted at a DMV this morning.”
Action: Assume other lakes exist. Demand delete-after-decision and pipeline logs from your IDV, not a quarterly SOC.
14. Election-window confidence (Nov 3, 2026 midterms)
Not a tabulation event. In-person poll check-in is not IDScan. Mail-ballot “attach a copy of photo ID” states are a sharper but still bounded edge.
The real electoral product is confidence and targeting: photo-ID-as-sacred-object vs photo-ID-as-honey-pot, SoS/clerk comms, spearphish of election offices, better intimidation kits (photo + address). Both political directions will use the same Krebs paragraph. Do not join a crime-forum rumor to the voter file.
15. Legislative / digital-ID response gap (SEDI as specimen)
Utah SEDI (SB 275 / Title 63A Ch. 20, 2026) is holder-controlled presentation, selective disclosure, verifier minimization, duty of loyalty — and does not drain the mandated, ID-correlated retention lakes at FIs, vendors, and age-gate processors. State tries to avoid being the liability sink; BSA 5-year CIP records and exam culture keep the cabinets.
Action: If someone says “digital ID fixes this,” ask what happens to the existing images and the hose. If the answer is a wallet demo, they missed the incident.
16. The cultural bug that created the lake
2003 CIP: description of the document is enough.
Exam + Red Flags (2008) + imaging systems + digital open: keep the richer object.
SOC 2 / GLBA: protect the cabinet.
PCI: trained the questionnaire muscle; never forbade identity-document retention.
Stream hardening (egress allow-list, volume/destination anomaly, delete-after-decision, scanner/SDK supply chain, right to pipeline logs in hours) was almost never a named, independently tested control. Encryption-at-rest and a SOC report can both be true while someone lives on the hose for a year.
Ranking mitigations (for the call)
- Support / reset / vishing — ID-only restore off for privileged and high-risk; pre-enrolled out-of-band; staff + customer “we will not ask you to re-upload.”
- Lookback — originations and beneficiary / wire / contact changes across the exfil window; device + funding graph; 314(b).
- Instrument the hose — who still scans or receives uploads; freeze writes; demand egress logs; delete-after-decision.
- Passkeys / hardware keys on email, registrar, cloud root, privileged SaaS.
- Do not spend the week on retention-policy punctuation or a digital-wallet RFP unless (3) is in motion.
Confidence loss is the meta-risk
Every constituency reads a different disaster off the same artifact: BSA officers see mule books; CS leaders see ticket queues; privacy counsel sees another lake; clerks see October questions; targeted-harm people see a finder kit; digital-ID vendors see a sales cycle; voters see a Cabinet secretary’s license on a Russian forum.
Those are all real. They are not the same control failure. The shared failure is document-image-as-proof plus unaudited stream. Until that changes, this cheat sheet will keep coming off the shelf.