153 Million Licence Scans Later, the Document Is Not the Evidence
A dark web index held 153m licence scans, infrared and ultraviolet layers included. Why identity documents stopped being proof, and what replaces them.

153 Million Licence Scans Later, the Document Is Not the Evidence
For a few days at the end of August, a dark web service offered a searchable index of more than 153 million US and Canadian driving licences, ten million identity cards, three million travel documents and half a million medical cards. It was growing by roughly 400,000 records a day. As reported by KrebsOnSecurity on 2 September 2026, the service disappeared the day after an FBI field office opened an investigation, replaced by a single line: this service is no longer available.
The headline number is not the interesting part. This is: each record held more than a photograph. Front scan, back scan, and infrared and ultraviolet captures of the same document, with a timestamp recording the moment it was scanned. Those infrared and ultraviolet layers exist for one reason. They are how you prove a licence is genuine rather than printed. They are the security features. And they were in the index, sitting alongside the plain scans, available to anyone with a login. A sitting cabinet secretary, an FBI assistant director and the reporter who broke the story all found themselves in it.
The Document Stopped Being Proof
Compliance teams in investment services have spent two decades building onboarding around an artefact. Ask the investor for a certified copy of a passport or a driving licence, check that it looks right, check that it has not expired, file it, and the identity question is closed. The whole model rests on an assumption that has now quietly failed: that a high-fidelity, security-feature-complete copy of someone's identity document is hard to obtain.
It is not hard to obtain. It is indexed and searchable, and it comes with the ultraviolet layer attached. Whatever an analyst or an automated checker is looking for when it inspects a document for authenticity, a fraudster can now supply, because the authentic article was captured at the point of verification and resold. Combine that with what is already happening to the video call at the other end of the process, where deepfakes have arrived at investor onboarding and the individual on screen may not exist, and the two pillars of traditional identity proof are both compromised at once. A convincing document and a convincing face are no longer scarce.
The correct response is not to inspect documents harder. It is to stop treating the document as the evidence and start treating it as one input among many, weighted accordingly.
The Breach Did Not Happen at the DMV
Here is the second lesson, and it is the one that lands closer to home for a fund.
No state licensing authority was breached. The records appear to have been captured downstream, at the ordinary commercial moments where someone scans a licence and keeps the image: renting a car, checking into a venue, opening an account. The exposure was not created by the issuer. It was created by the twentieth organisation that held a copy.
Every compliance function in investment services is in the business of holding copies. Passports, proof of address, certificates of incorporation, registers of members, trust deeds, and the certified duplicates of all of it. They arrive by email, sit in shared inboxes, get forwarded to the administrator, get uploaded to a portal, get zipped into a folder for the depositary, and get sent again to the bank. Then the direction reverses. A manager receives inbound KYC requests from its own counterparties, roughly three to five per fund per year, and each one is answered by assembling and dispatching yet another pack of the same documents into yet another organisation's storage. Nobody counts these copies. Nobody can recall them. Each is permanent, and each one is a place where the next index can be sourced.
Answering the same request from a single maintained position rather than rebuilding and re-sending a pack every time is usually framed as an efficiency argument. It is now also a data-minimisation argument, and the second one is stronger. The live AML passport reduces the number of uncontrolled duplicates in circulation, which is the only variable in this equation a manager actually controls.
Corroboration Beats Inspection
If a document can be perfectly forged from a stolen original, then verification has to rest on things a fraudster cannot buy in bulk: consistency across independent sources, and provenance.
That is what AI-first onboarding is actually for, and it is not the same thing as faster document review. A document is a claim. The useful work is checking the claim against authoritative sources that were never in the fraudster's possession: company registries, ownership filings, sanctions and PEP data, adverse media, the fund's own history with the counterparty. Does the address on the document match the address on the registry filing? Does the shareholder structure declared in the subscription pack reconcile with the corporate registry, three layers up, and then the layer above that? Does the entity behave like the entity it claims to be? Layered ownership, cross-border structures, offshore trusts and SPVs are the hardest cases to unwind, and they are precisely the cases where a clean-looking document at the bottom of the stack proves the least. The signal is in the agreement between sources, not in the quality of any one of them.
The second half is provenance. Knowing which document arrived when, from whom, through which channel, what was checked against it, who reviewed the result, and what has happened to it since. Human oversight on every decision, recorded in an append-only, hash-chained audit trail, is what turns a pile of files into evidence you can stand behind two years later when a regulator asks. It is also, incidentally, how you answer the only question that matters after a vendor breach: what did we hold, where did it go, and who touched it.
Where This Goes
The industry has treated the identity document as the floor of the AML process, the one thing that was not in dispute. That floor has gone. It did not go because criminals got cleverer. It went because the verification infrastructure built to defend it accumulated tens of millions of perfect copies in one place, and the perimeter around that place failed.
Firms will respond in one of two ways. Some will add another document check, another vendor, another scan, and quietly increase the number of copies in circulation while believing they have tightened control. Others will accept that AML compliance is broken in a specific and now-demonstrated way, and rebuild onboarding around corroboration, minimised duplication and a defensible record of who verified what.
The next index will be assembled from copies that already exist today. The only question worth asking is how many of them your firm put there.
Related Insights

The Best PEP and Sanctions Screening Vendors in 2026
Compare PEP and sanctions screening vendors: which sell data, which sell platforms, and how to run a screening proof of concept
Sanctions Screening Before a Fund Distribution
A UK fund distribution is due and an investor is flagged. Follow the decisions on identity, ownership, payment controls, escalation and evidence.

Former PEP Due Diligence: Reassessing the Investor
How UK investment firms can reassess former PEPs, document continuing risk and update investor controls after a public role ends