Let me tell you what happened when you signed up for ID.me.

You uploaded a photo of your driver's license or passport. You recorded a video selfie. The system scanned your face, mapped your facial geometry, and created a biometric template unique to you. It cross-referenced that against your Social Security number, your credit bureau records, and data pulled from telecommunications networks and financial institutions. Then it stored all of that. For up to seven and a half years after you close your account.

You did this because the IRS told you to. Or the VA. Or your state unemployment office. Or Medicare. As of 2026, ID.me provides identity verification services to 20 federal agencies, 45 state government agencies, and over 70 healthcare organizations. The US Treasury just awarded the company a one-billion-dollar five-year contract.

ID.me is not the government. It is a private company headquartered in McLean, Virginia. It operates under different privacy rules than a federal agency. And its privacy policy reserves the right to share your data in ways that are loosely defined.

During the COVID-19 pandemic, unemployment fraud exploded and ID.me pitched itself as the solution. States signed contracts quickly, under pressure, with limited vetting. The problems surfaced fast. Americans trying to access legitimate benefits found themselves stuck in queues for weeks. The facial recognition system struggled with darker skin tones. A congressional investigation in 2022 found that ID.me had overstated both its fraud-prevention capabilities and its capacity to handle volume.

The IRS announced it would transition away from ID.me. It did not. As of mid-2025, the IRS still relies on ID.me for identity verification on several key platforms.

Here is the technical problem that does not get enough attention: biometric data is not a password. If your password leaks, you change it. If your facial geometry is compromised in a data breach, you cannot change your face. The biometric template ID.me holds on you is permanent. A breach of that database would be categorically different from any previous identity theft scenario — it would be irrecoverable.

The government alternative — Login.gov — exists and works. It meets the same security standards as ID.me. It does not use facial recognition. It is run by the government and accountable to Congress. It is not, however, a billion-dollar private contract. That last detail probably tells you everything you need to know about why ID.me keeps winning.

You signed up because you had to. Your face is in a private database, retained for nearly a decade, covered by a privacy policy written by lawyers whose job is to maximize flexibility. This is not science fiction. This is procurement.