Identity Verification Is Broken. A Quiet Regulatory Shift Points Toward a Fix.

By Yaya J. Fanusie, Global Head of Policy at the Aleo Network Foundation
On August 31, a new listing appeared on a Russian cybercrime forum called Exploit. The seller was advertising a service called Nexus. The inventory: more than 153 million U.S. and Canadian driver's license scans.These were high-resolution images, front and back, including infrared and ultraviolet layers that pass bank-grade fraud checks. To prove the goods were real, the seller included a free sample: cybersecurity journalist Brian Krebs's own Virginia driver's license.
By September 2, the FBI's New Orleans field office had opened a formal investigation. Among the records available for purchase was the driver's license of Defense Secretary Pete Hegseth. The likely source, per Krebs and independent security researchers, was IDScan.net — a Louisiana-based identity verification company whose scanners sit at car rental counters, casinos, cannabis dispensaries, and retail locations across the country.
Every time someone showed their license to pick up a rental car or enter a venue, a copy landed in IDScan's cloud. That archive, built one scan at a time over more than a year, has now been raided. IDScan confirmed unauthorized access on September 10. At least nine class-action lawsuits have been filed.
This is a story about what happens when compliance infrastructure becomes a honeypot, when the systems built to verify who you are accumulate copies of your most sensitive identity documents, and someone figures out the archive is there. It is a familiar story. Data breaches involving identity documents have become a background condition of modern life, each one adding to the aggregate exposure of millions of people whose information flows through verification systems they never chose and can't control.
The underlying dynamic is the same everywhere this model is deployed: regulated institutions collect and store copies of identity documents because the rules require verification, and the default method of verification is document inspection and storage. Every institution you open an account with holds a copy of your passport or driver's license. Every vendor those institutions use to process those documents holds them too. The exposure compounds invisibly, across thousands of institutions and their vendors, each one a potential target.
A Quiet Development That Connects
Most people aren't connecting the IDScan breach to a regulatory development that happened the same week. They should. On September 8, while the IDScan story was still breaking, FinCEN and the federal banking agencies quietly issued new guidance clarifying that banks and credit unions can use verifiable digital credentials — including state-issued mobile driver's licenses — to verify customer identities. The significance is straightforward: verification methods exist that don't require institutions to collect and store copies of your documents at all. Regulators just confirmed that banks can use them.
In crypto policy circles this development was largely overshadowed by the CLARITY Act's failure to clear a Senate cloture vote. That's understandable since the CLARITY Act has been a major legislative priority. But for anyone thinking about the future of identity, privacy, and data security, the FinCEN guidance may matter more.
The guidance addresses two questions that regulated institutions have been hesitant to act on without explicit confirmation. First: can a bank accept a state-issued mobile driver's license — a cryptographically signed digital credential stored on a phone — as a valid form of identification? Yes, the agencies say, provided the institution has the appropriate technology and its internal policies permit it. Second: can a bank use a verifiable digital credential issued by a private identity provider rather than a state government? Also yes, with an important condition: the institution must ensure the private issuer applies the same standard of authentication the institution itself would use.
Regulators have never said institutions couldn't use digital credentials. But in the absence of explicit confirmation, compliance teams stay conservative. This guidance removes that hesitation.
The convergence doesn't stop there. On September 23, departing SEC Commissioner Hester Peirce gave a speech at SIFMA's Digital Assets Conference making a broader version of the same argument. She described the existing know your customer (KYC) and anti-money laundering (AML) framework as building "ever bigger data haystacks on the theory that we will find a needle or two inside." Peirce argued that zero-knowledge proofs and attribute-based credentials offer a genuine alternative, and called for moving the government and its regulated institutions "away from prescriptive collection requirements and toward attribute-based verification wherever technologically feasible."
A departing commissioner speaking candidly is not a policy commitment. But when a senior regulator uses her final weeks in office to articulate, on the record, that the current model of data accumulation is failing and that cryptographic tools offer a better path, it is worth noting.
What This Means for Stablecoins — and Beyond
The FinCEN guidance applies only to banks and credit unions under the existing rules. A new category of regulated institution is coming online under the GENIUS Act — permitted payment stablecoin issuers, or PPSIs — and a separate proposed rulemaking is establishing customer identification requirements for them. The Aleo Network Foundation filed a comment letter with FinCEN and the banking agencies in August arguing that the PPSI rule should similarly recognize cryptographic verification tools. The September guidance signals the agencies' thinking is moving in that direction.
The stablecoin context makes this especially consequential. Unlike banks, stablecoin issuers will handle virtually all customer onboarding online with no in-person option. And blockchain programmability means a customer's verified credential status can govern account access and transaction authorizations throughout the account relationship — not just at the moment of opening. The architecture is built for this.
This is also where zero-knowledge proof technology becomes relevant. For example, zPass, built on Aleo, allows a user to generate a cryptographic proof from an identity document on their own device. An institution vetting users receives confirmation that the credential is valid. The underlying document is never transmitted.
Acknowledging this sort of technology shows that regulators are attuned to what’s technically possible. Under current AML rules, financial institutions still need to collect certain identifying information — name, address, date of birth, identification number. But accepting a verifiable digital credential would eliminate the need to keep copies of the documents that verify that information. The honeypot gets smaller.
The more ambitious horizon goes further. Zero-knowledge proofs allow a user to prove they satisfy a verification requirement — they are a verified adult, a U.S. person, not on a sanctions list — without transmitting the underlying data at all. Getting to a place where customers do not have to share any private personal information with financial institutions would require regulators and eventually Congress to revisit what "customer identification" fundamentally means in the realm of financial services. That is a longer arc. But it is a coherent one, and the technology to support it already exists.
The Door Is Open
The IDScan breach is a vivid illustration of what the current model costs — not as an anomaly, but as a foreseeable consequence of building compliance on document custody. FinCEN’s regulatory clarification is a first step toward a different model, one where verification doesn't require accumulation. And the stablecoin ecosystem, coming online now under the GENIUS Act, is where that model can be built from the ground up rather than retrofitted onto legacy infrastructure.
The door is open. The architecture to walk through it exists. The question is how quickly the rest of the regulatory framework and the institutions operating within it will follow.
Yaya J. Fanusie is Global Head of Policy at the Aleo Network Foundation.




