AI fraud pushes digital identity toward cryptographic proof
AI-enabled fraud and large-scale breaches are exposing the limits of online identity systems that rely on scanned documents. Nexus, a criminal marketplace, reportedly offered more than 170 million scanned North American identity documents, including 153 million driver’s licenses, 10 million identity cards, and 3 million travel documents. The FBI’s New Orleans field office is investigating, while the source of the data has not been definitively established.
The shift now underway favors cryptographically verifiable credentials over reusable document images. NIST’s draft practice guide SP 1800-42A outlines how banks could use mobile driver’s licenses for customer identification, allowing institutions to verify a state-issued digital signature rather than judge whether an image looks authentic. Properly implemented credentials can also be device-bound, revoked, reissued and designed for selective disclosure.
Washington is moving to support that model through standards, funding proposals and financial-sector guidance. H.R. 7270, the Stop Identity Fraud and Identity Theft Act of 2026, would create Treasury grants for state digital credential programs aligned with NIST guidance. Treasury-backed work involving more than 130 government and industry experts also treats cryptographic credentials as one layer in a broader defense that includes liveness detection, device intelligence, authoritative checks and behavioral analytics.