You cannot reset your face
At the end of August a service called Nexus appeared on the dark web, promoted on a Russian cybercrime forum. It was not a data dump. It was a storefront: a searchable database claiming more than 153 million driver's licenses from the United States and Canada, plus over 10 million ID cards, 3 million travel documents, and about 579,000 medical cards, including marijuana dispensary cards. Brian Krebs, who broke the story, tested the scale claim the direct way: a blank search returned 11.5 million pages of results, 15 records per page. Then he searched for himself, and found his own license.
Each record held up to six files. Front and back photographs of the license, a basic scan, an infrared scan, an ultraviolet scan, and timestamps. The sellers said they had been quietly exfiltrating from a live breach for over a year, and the inventory grew by roughly 400,000 records in a single day while Krebs watched. The evidence he assembled points to IDScan.net, a New Orleans identity verification company that processes more than 21 million verifications a month for clients like Hertz, Target, and FedEx. The timestamps told the story better than any forensic report: Krebs's own scan matched the date of a flight he took, his mother's scan sat a few seconds from his, matching the day they rented a car together at Hertz, and a security researcher matched his record to a Las Vegas dispensary visit. The FBI's New Orleans field office opened an investigation, reportedly after learning that an FBI assistant director's license was in the inventory too. Within a day of publication, Nexus went dark.
Do not take comfort in that last part. The storefront is gone. The 153 million scans are not.
Why this is worse than another breach
We have all developed calluses about breach announcements. Another hundred million records, another year of free credit monitoring. This one deserves your attention for three reasons that have nothing to do with the number.
First, a driver's license is not a password. When credentials leak you rotate them; that is annoying but survivable. There is no rotation for your face, your date of birth, or the document design of your state. The license photo is the anchor that everything else hangs on, and for most adults it will be valid, and matched to their real face, for decades. A password breach is a leak. This is closer to a birth defect the whole population just acquired.
Second, the infrared and ultraviolet layers. This detail is easy to skim past and it is the most consequential thing in the story. Modern ID verification doesn't just look at the printed front of a license; it checks the hidden security features that only appear under IR and UV light, because those are what separate a genuine document from a good counterfeit. The verification industry's whole pitch is that it can see what fraudsters can't reproduce. Nexus was selling the answer key: authentic multi-spectral scans of real documents, in bulk, indexed by name. Anyone building counterfeit documents, physical or digital, now has 153 million reference templates showing exactly what a passing document looks like under every wavelength the checkers check.
Third, the timestamps. Each scan is stamped with when it was captured, which means the database records not just who you are but where your ID has been presented: the rental counter, the airport, the casino floor, the dispensary. That is the aggregation problem I wrote about in A warrant for the mosaic, built this time not by the government but by the compliance industry, and now owned by criminals. For most of us that is a privacy insult. For someone in witness protection, or hiding from a violent ex, a searchable database matching their face to recent locations is a different kind of emergency, and one Krebs's sources raised explicitly.
The deepfake multiplier
Now put this breach next to the generative tools that matured over the last three years, because the two are made for each other.
Remote identity verification, the kind used to open a bank account, claim unemployment benefits, or recover a locked account, generally rests on two legs. Show us your document, and show us your face. Take a photo of your license, then take a live selfie, and software checks that the document is genuine and the face matches.
Nexus breaks both legs at once. The document check fails because the fraudster isn't uploading a forgery; they are uploading a scan of the real document, the same pixels a legitimate verification produced. And the selfie check fails because the license photo in the scan gives a face-swap model exactly the target it needs. Deepfake tooling that animates a single portrait into a blinking, head-turning, "live" video has been commodity software for a while now; the hard part for a fraudster was always getting a clean source image tied to real, verifiable identity data. That was the scarce ingredient. It is not scarce anymore.
The result is a complete remote-onboarding kit: genuine document, matching synthetic liveness, real name, real address, real date of birth. Fraud teams call the traditional version of this synthetic identity fraud, stitching fake attributes onto fragments of real ones. This is the industrialized successor, where nothing about the identity is fake except the person presenting it.
And notice the recursion. When this wave of fraud arrives, the reflexive institutional response will be to demand more identity verification, which means more scans, collected and retained by more vendors, any of which can become the next Nexus. We are watching the loop close in real time: the thing we deployed to stop fraud has become the supply chain for it.
The paradox we built
Which brings me to the uncomfortable question nobody in the compliance chain wants asked: why did a verification vendor have retained scans to steal?
Verification is a moment. The bouncer looks at your license, confirms you're of age, and hands it back; he does not photocopy it for his files. Somewhere along the way, digital verification quietly abandoned that model. Every scan at a rental counter, casino, or dispensary became a stored record, aggregated at vendors most of the scanned people have never heard of. The medical and dispensary cards in the Nexus inventory make the point painfully: people showed ID to prove a birthdate, and the transaction left a permanent copy of their most sensitive documents in a third party's database. The consumer advice now circulating says to ask businesses why they need your ID and what happens to the copy. Good advice, thirty years too late for 153 million people.
This matters right now because legislatures across the US and abroad are mandating age verification for social media and adult content, which in practice means requiring millions more people to upload identity documents to third-party checkers. Every one of those mandates, whatever its merits, is also an order to construct another honeypot. Nexus is what the honeypot looks like when it tips over.
What survives contact
For individuals, the honest list is short. Freeze your credit with all the bureaus, since new-account fraud is where a stolen license does its best work. Treat any message that quotes your real license details as a manipulation attempt, not proof of legitimacy; expect account-recovery scams that helpfully "verify" you with your own stolen data. And start declining scans you can decline. You will be surprised how often a glance is still accepted when a scan is refused.
For institutions, the design principle was stated cleanly by one security consultant in the aftermath: build identity systems on the assumption that identity evidence is already compromised. A static image of a document can no longer serve as proof of anything, because both the genuine article and a perfect deepfake of its holder are now purchasable. What still works is verification that involves cryptography rather than pictures: mobile driver's licenses that present signed, minimal claims, so a bar learns you're over 21 without ever seeing or storing the document, and challenge-response checks that a replayed scan cannot answer. Those systems exist today. They have been slow to deploy because scanning a plastic card was cheap and worked well enough.
It no longer works well enough. The plastic card's picture is in a criminal database with its infrared soul attached, and there is no recall notice, no forced reset, no patch. The document model of identity assumed copies were hard to make and harder to use. Both assumptions are now false, and the 153 million people in that inventory are going to spend years living inside the gap between the identity system we have and the one we knew we needed.