153 Million Reasons Document Verification Isn’t Identity Assurance

A government-issued ID has long been treated as one of the strongest forms of proof that someone is who they claim to be.

But what happens when hundreds of millions of those identity documents fall into the wrong hands?

The Scale of the Identity Document Exposure 

A newly discovered identity theft service called Nexus claims to have more than 153 million driver’s license scans from people across the United States and Canada, according to reporting from KrebsOnSecurity. The service also claims to hold more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards.

The individuals behind Nexus have not been publicly identified, but the service’s operators communicated directly with KrebsOnSecurity about the operation. They claimed they had been continuously exfiltrating new data for more than a year into a private database. While Krebs was investigating the service, the number of driver’s license records available reportedly increased by nearly 400,000 in just 24 hours, suggesting that new data was still being added rather than Nexus simply selling a static collection of previously stolen documents.

The apparent source of that data makes the incident even more significant. The FBI’s New Orleans field office has opened an investigation into an apparent breach involving IDScan.net, a Louisiana-based identity verification provider. IDScan.net said it was investigating the matter but had not provided a substantive public response confirming the source of the data at the time of KrebsOnSecurity’s report.

IDScan.net’s reach illustrates how much identity data can flow through a single identity verification provider. According to KrebsOnSecurity, IDScan.net’s website has listed major brands including Hertz, Target, FedEx, Motorola Solutions and Jack Henry among organizations using its identity verification services. The company says its technology performs more than 21 million verifications every month across more than 20,000 locations worldwide. Its technology can also scan identity documents using infrared and ultraviolet light, notable because some of the driver’s license records found on Nexus contained basic, infrared and ultraviolet versions of the same document.

The Nexus operators’ willingness to openly discuss the alleged exfiltration also stands out. Yet that visibility did not last. Shortly after KrebsOnSecurity published its investigation, the Nexus dark web site disappeared and was replaced by a message stating that the service was no longer available.

While the reported scale of Nexus is striking, the underlying threat is not new. Stolen identity documents have circulated on dark web marketplaces for years. A 2024 study published in Forensic Science International found that driver’s licenses were the most commonly listed identity documents for sale across the marketplaces studied, with digital products such as scans and images accounting for roughly 80% of identity-related listings.

Large-scale breaches have added to that exposure. In 2026 alone, AssuranceAmerica disclosed a breach affecting approximately 6.9 million people that included driver’s license information, while another incident involving the Texas state government reportedly exposed at least three million driver’s license and passport numbers.

Nexus demonstrates both the scale of identity data that can become available to attackers and the challenge that creates for organizations relying on that same information to establish trust.

Why Authentic Documents Are Viable Attack Tools

Document authentication still serves an important purpose. It is commonly used as part of identity verification during customer and employee onboarding, account opening, KYC and AML processes, age verification, account recovery, and other high-trust interactions. Trusted digital identities are essential when people open bank accounts, start jobs, rent property, or access age-restricted services.

In many of these moments, a government-issued ID helps establish the identity that an organization will trust moving forward. That makes the strength of the initial identity proofing especially important.

Attackers no longer need to fabricate identity evidence when legitimate documents and personal information are now readily available to them. The accessibility of AI paired with legitimate identity documents on the dark web decreases the burden of socially engineered attacks entirely.

This is the limitation of treating document verification as identity assurance. Document checks can examine security features, expiration status, data consistency, tampering and other indicators of whether the document itself is legitimate. They do not, on their own, establish that the person presenting that document is its rightful owner.

One Verification Method Is Not Enough

The answer isn't to abandon document verification. It is to stop asking one piece of identity evidence to do more than it was designed to do.

This is where multi-factor verification (MFV) becomes critical. MFV brings multiple identity verification factors and risk assessment into the identity process, helping organizations validate the person behind an interaction rather than relying on a single piece of evidence.

Those factors can include document verification, biometrics, behavior, context, device information, and other risk signals, applied dynamically based on the level of risk.

Rather than requiring every person to complete every possible verification step, these signals can help determine the appropriate response based on the risk of the interaction.

Risk signals can also help identify suspicious activity before a suspected bad actor progresses through the identity workflow. These signals can evaluate whether a person’s location matches expected behavior, whether a device or session shows signs of manipulation, whether identity data matches existing records, and whether biometric or document checks reveal inconsistencies. For example, unexpected changes across a device, phone number, and location can indicate greater risk even when each individual check might appear legitimate on its own.

Integrated risk signals can detect techniques designed specifically to bypass identity verification, including virtual camera or injected video feeds, replayed biometric captures, deepfakes, document tampering, and unusual session environments. The goal is to use those signals together to determine what happens next: allow a low-risk interaction to continue, require stronger verification when risk increases, or escalate a suspicious interaction for additional review.

In a scenario like Nexus, that distinction matters. If a legitimate identity document has been compromised, possession of that document should not be enough to establish trust. With MFV, the document is one part of the identity decision, requiring an attacker to overcome additional, independent verification factors before they can successfully impersonate someone.

As identity information becomes easier to access, steal, and replicate, and AI-powered deepfake tools grow more widely available, verifying a single piece of evidence is no longer sufficient. These technologies have lowered the barriers to identity impersonation, enabling even inexperienced threat actors to execute convincing attacks. Organizations must therefore take a risk-based approach to multi-factor verification, carefully determining where, when, and how to apply additional checks to build a more complete and trustworthy picture of an individual’s identity.

When Verification Needs a Human Step Up

Multi-factor verification can also include a human layer of assurance when additional confidence is needed. HYPR Affirm brings risk signals into the verification process to assess the context of each interaction and determine when stronger verification steps or real-time human review is needed. This allows business operations to continue with minimal productivity loss, and also ensures an identity check is performed in a time-bound manner that cannot be manipulated.

With HYPR Affirm, a verification workflow can step up to integrated text or video chat, connecting the individual with a trusted approver who can review the verification results, interact with the requester, and approve or deny the request. That approver can be the individual’s manager, another designated person within the organization, or someone dynamically assigned based on the context of the request.

This provides an additional path when an automated check is inconclusive or risk is elevated. Instead of allowing a single failed or compromised signal to determine the outcome, organizations can bring someone with real organizational context into the verification process before access or credentials are granted.

In a world where identity documents and other personal information can be stolen or replicated, sometimes the strongest additional signal is someone who actually knows who you are.

Where Stolen Identity Data Becomes a Bigger Risk

The danger of stolen identity documents extends beyond the initial exposure of personal information. That data can be used during moments when organizations are actively trying to determine whether they can trust someone.

Consider onboarding, account recovery, help desk interactions, credential resets, or requests for additional access. These are critical points in the identity lifecycle because a successful impersonation can result in something far more valuable than a stolen document: legitimate access.

An attacker who passes an identity check may be issued real credentials, regain control of an account, or receive access intended for someone else.

Once that happens, downstream security controls may see an authorized account rather than the impersonator who obtained it.

That changes the security question. Organizations need to consider not only whether the information being presented is valid, but whether there is enough evidence to trust the person presenting it.

Building Trust Beyond the Document

Document verification still has an important role to play. The lesson from Nexus is that it cannot carry the burden of establishing identity on its own.

Organizations need to build confidence using multiple independent forms of verification, particularly when the risk of getting identity wrong is high. The appropriate signals may vary depending on the interaction, but the objective remains the same: establish a comprehensive view of the individual rather than making a trust decision based on one piece of evidence.

For legitimate users, that can mean a faster path when confidence is high. For higher-risk interactions, it can mean additional verification or human approval. And when threat signals indicate a bad actor, it can mean stopping the interaction before access is granted.

A document can help prove an identity. It shouldn't be expected to prove it alone.


Related Reading

Related Content