Free guide: How to use AI in compliance
Back

TSA's identity verification vendor could extract passport images, and nobody tracked it

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published September 19, 2026Reviewed by Charlene Wang
Editorial cover headlined "TSA's identity verification vendor could extract passport images, and nobody tracked it".

A DHS watchdog found TSA's identity verification vendor could extract passport and license images untracked. What it means for your third-party oversight.

Table of contents

A US government watchdog found that TSA's identity verification vendor could pull driver's license and passport images out of the checkpoint system without the agency knowing. TSA had no policy governing that access, no record of what was taken, no proof it was deleted, and told no passenger.

  • The DHS Office of Inspector General released the unclassified summary of report OIG-26-27 on 15 September 2026, covering TSA's identity and biometric technology.
  • Under routine operation, auditors found TSA staff and CAT-2 scanners deleted passenger data on time and in line with federal requirements.
  • Auditors graded the maintenance path "a significant weakness": the CAT-2 vendor could reach and export passenger ID images during troubleshooting, outside TSA's view.
  • TSA agreed with all three privacy recommendations, and one of the three is still open and unresolved.
  • The same day, the OCC, the Federal Reserve, the FDIC and the NCUA proposed replacing the 2023 third-party risk guidance with a risk-tailored text. Comments close 16 November 2026.

What did the DHS watchdog actually find?

The DHS Office of Inspector General audited how TSA's facial recognition and credential systems handle traveller data. Its unclassified summary, dated 15 September 2026, has two halves: screening effectiveness, mostly classified, and privacy, which is public.

On the privacy half the auditors were blunt. They recorded "a significant weakness" in that "the CAT-2 vendor was able to access and extract sensitive passenger information", including driver's license and passport images, during troubleshooting and enhancements, without TSA's knowledge. No policy governed that access. Nobody logged the extractions. Nobody could show that what left was later destroyed. No traveller was told their documents may have been stored. Weak vendor oversight, the report concludes, created a risk that personal information "could be retained or exposed". The three recommendations aim, in the auditors' words, to "strengthen controls, improve oversight, and ensure transparency and the proper handling of passenger data".

What makes the finding uncomfortable is the part that passed, because it shows how narrowly an identity verification vendor problem sits inside an otherwise compliant system. Auditors found TSA personnel and CAT-2 deleted passenger information in a timely manner and in accordance with federal requirements, and that data was "generally protected during routine operations". The designed path worked. The support path around it did not.

Half of the auditFindingsRecommendationsTSA responseStatus
Screening effectiveness, covert tests included36Concurred with 5, non-concurred with 14 resolved, 2 unresolved
Data handling and privacy at CAT-213Concurred with all 32 resolved, 1 unresolved

The summary lists all nine recommendations as open, split between resolved and unresolved, which in DHS OIG usage means three had no agreed corrective action plan at publication. Since only one was refused outright, at least two of the three are fixes TSA accepted and then left without a plan.

How does CAT-2 work, and where did the gap sit?

CAT-2 is the second generation of TSA's Credential Authentication Technology. A traveller presents an ID, a camera takes an optional photo, and the unit compares the two while checking flight and vetting status. TSA's factsheet says photos "are not stored or saved after a positive ID match has been made" outside a limited testing environment, and puts the units in roughly 350 airports. That factsheet covers deletion. It says nothing about who can reach those images during maintenance, and it never uses the word maintenance.

The scale is the point. TSA screened 2,700,658 people on 17 September 2026 alone, on its published daily volumes, though not every lane runs a CAT-2 unit. Even instant deletion moves a vast stream of passport and driver's license images through hardware someone must maintain. The audit did not find that the steady state leaked. It found the maintenance door had no lock.

The documented CAT-2 path, cleared with no finding, beside the support path the auditors called a significant weakness.
The same units, audited twice. Source: DHS OIG, OIG-26-27.

That distinction is the lesson for anyone buying from an identity verification vendor. Production controls get documented, tested and shown to examiners. Support access gets granted informally so a broken unit is fixed by Friday. The IDScan data breach this month is a different event with the same root: a third party holding document images it had no obligation to hold. TSA awarded the CAT-2 contract, worth up to 128 million dollars and covering more than 1,500 units, to Idemia Identity and Security USA in April 2023. The OIG summary names no vendor and makes no finding against any company.

What does this change for your obligations over an identity verification vendor?

Nothing in the DHS OIG audit binds a bank or a fintech. Rules that already apply do, starting with three: FinCEN's Customer Identification Program rule, GDPR Article 28 and DORA Article 30. If a third party can reach identity documents during support work, that capability belongs in your control inventory, your contracts and your examination file, used or not.

What does the CIP rule require you to keep?

Under 31 CFR 1020.220, the record is "a description of any document that was relied on": the type, any identification number, the place of issuance and, if any, the dates of issuance and expiration. That description is kept five years after the record is made, while the customer's identifying information runs five years past account closure. The rule never asks for the image. Every stored scan is a business decision, and every copy an identity verification vendor keeps for debugging is a copy no CIP obligation asked for.

What do GDPR processor duties add?

For EU and UK firms, processor duties bite harder. Article 28(2) bars a processor from engaging another processor without the controller's written authorisation, and Article 28(3)(h) requires it to "allow for and contribute to audits, including inspections". An engineer exporting customer documents into a support environment is processing that your contract must cover, or it is processing outside your instructions. Article 5(1)(c) holds data to "what is necessary", and Article 33(2) obliges the processor to report a breach without undue delay, which it can only do if it knows what left the system.

What does DORA give a financial entity?

Financial entities in scope of DORA have the sharpest lever, split across two paragraphs of Article 30. Every ICT contract must name the locations where data is processed and stored, and say whether subcontracting of a critical or important function is permitted and on what conditions. Contracts supporting critical or important functions must go further and grant "unrestricted rights of access, inspection and audit" whose exercise other contractual terms may not impede. Onboarding usually earns that heavier classification, because a firm that cannot verify customers cannot open accounts, but the assessment is yours to document. If an identity verification vendor cannot produce an access log on request, that clause is decorative.

Which duties do teams usually forget?

Two. Sanctions and PEP screening runs on identity attributes, so a support environment able to alter records threatens integrity as much as confidentiality. And when stolen identity data resurfaces as account takeover, the bank files the suspicious activity report under 31 CFR 1020.320 within 30 days of initial detection, not the supplier that leaked it. Do not assume the incident rules will warn you first. 12 CFR 53.4, matched word for word by the Federal Reserve and FDIC rules, obliges a bank service provider to notify its banking customers only when an incident has materially disrupted or degraded covered services, or is reasonably likely to, for four or more hours. It expressly does not apply to "scheduled maintenance, testing, or software update previously communicated" to the customer, which is the exact path the auditors found unmanaged.

What is still uncertain, and where does the risk sit?

The public record is thin by design. The unclassified summary does not say how many passengers were affected, which airports were involved, when extractions happened, where copies went, or how long they survived. One privacy recommendation was open and unresolved in the 15 September summary, with nothing published since as of 19 September 2026, so the gap is not closed.

Three risks follow. Nobody can rule out copies of identity documents outside the system of record, because deletion was never verified. Passengers were not notified, so nobody can act on exposure they do not know about, the helplessness that followed the Revolut disclosure this month. A private EU controller on these facts would weigh GDPR Articles 33 and 34. A federal agency answers to the Privacy Act, whose safeguard duty at 5 U.S.C. 552a(e)(10) comes with no duty to tell the individual when records leak.

The third risk is supervisory drift. The same day, the OCC, the Federal Reserve, the FDIC and the NCUA proposed new third-party risk guidance at 91 FR 58536, with comments due 16 November 2026. It would replace the 2023 text, partly by "removing broad-based and overly prescriptive language". The agencies make a fair case: they still call the 2023 approach "a relevant tool", they frame the change as consistent with Executive Order 14405, and check-the-box vendor files do crowd out real risk work. The catch is what goes with the checklist. The proposal says subcontractor use alone creates no "presumption of direct banking organization oversight", and that non-compliance "will not result in supervisory action". Firms reading that as permission to drop access and audit clauses will find the clause was the only thing making the question askable.

Legislative cover is not arriving either. The Traveler Privacy Protection Act of 2025 would require affirmative express consent before facial recognition at checkpoints. It was introduced on 8 May 2025, referred to committee the same day, and has not moved since.

How do the 2023 and 2026 third-party rules compare?

Both texts tell banks they own the risk. They differ in how much they spell out, which matters when a supplier's engineer reaches customer documents that no clause covers.

Point2023 guidance, 88 FR 379202026 proposal, 91 FR 58536
StatusFinal, in effectProposed, comments to 16 November 2026
Audit rightsDedicated section on the right to audit and require remediationContract negotiation section kept, but "no generally applicable expected contract terms" and no standalone audit-rights discussion
FramingHeightened oversight for critical activitiesOversight tailored to the assessed risk of each relationship
SubcontractorsPeriodic independent audits of the third party and its subcontractorsSubcontractor use "alone does not typically" create a "presumption of direct banking organization oversight"
Enforcement postureSupervisory expectationsNon-compliance with the guidance "will not result in supervisory action", though law violations still can

Read together, the change moves the burden from checklist to judgement, and narrows the examiner route rather than the liability. The proposal is explicit that a missing contract term is not on its own a basis for an adverse finding, and equally explicit that the agencies may still act on "violations of laws or regulations, unsafe or unsound practices" flowing from insufficient third-party risk management. The audit clause stops being something an examiner asks for and becomes the only evidence you hold when the underlying law is in question.

How should compliance teams respond?

Start with an inventory question you can answer in writing: which suppliers can reach raw identity documents, in what circumstances, and who approves it. Separate production access from support access. Require break-glass access to be ticketed, time-boxed and logged, then ask for the log, not the assurance.

Add extraction and deletion records to due diligence renewals, check that audit rights survive a lighter guidance regime, and make subcontractor disclosure a duty. Then test the uncomfortable question: can you name everyone at an identity verification vendor who touched a customer's passport image last year? Finally, ask whether the copy needs to exist, because the CIP record is a description, not a scan.

Zyphe was built for that last answer, and it changes what an identity verification vendor can lose. Identity data is split across more than 60,000 nodes under a 29-of-100 threshold scheme, the customer holds the key, and there is no master key and no central store of document images to export. Verification uses an NFC chip read of an ICAO 9303 or eIDAS-compatible chip, with two-step liveness and no image upload, and the audit trail stays exportable. See how KYC software and decentralized PII storage change the questionnaire, or book a demo.

The bottom line

Systems holding identity documents usually fail at their edges, not in their designed path. TSA's deletion worked, the maintenance door around it did not, and a federal agency ended up unable to say what left its own checkpoints. Any firm that outsources onboarding faces the same problem with the same unglamorous fix: know who can reach the documents, log it, prove deletion, and keep the contract rights that let you check. The cleanest control is not holding the image at all, because an identity verification vendor cannot export what it never stored.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

CAT-2 is the credential scanner at US airport checkpoints that authenticates a traveller's ID, checks flight and vetting status, and can take an optional photo to compare against the document. It handles driver's license and passport data, images included, at roughly 350 airports. TSA says images are deleted after a positive match, except in a limited testing environment.

No. The DHS Office of Inspector General described an oversight failure, not a confirmed compromise. Its wording cuts both ways: it refers to data having been extracted and untracked, yet says passenger information "may have been stored". Auditors report no misuse, and the summary gives no scope.

No. The unclassified summary refers only to "the CAT-2 vendor" and makes no finding against any named company. TSA separately announced in April 2023 that the CAT-2 production contract went to Idemia Identity and Security USA, but that award is public procurement context and not an allegation about this audit.

No. The rule requires a record describing the document relied on, including its type, identification number, place of issuance and any issue and expiry dates, kept for five years after the record is made. Storing the image itself is a business choice that carries its own security and privacy obligations.

Ask for the support access model in writing: who can reach production data, through which accounts, with what approval, and what is logged. Request a sample access log and deletion evidence, and confirm the contract grants inspection rights and subcontractor disclosure rather than relying on a certification alone.

It reframes it. The agencies would replace the 2023 guidance with a risk-tailored text and say non-compliance will not itself trigger supervisory action. They also keep the power to act on violations of law and unsafe practices, so responsibility stays with the banking organization and thin oversight remains the firm's own exposure.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo