Maybe it has a short TTL? So it would catch a group of people that all bought fake IDs from the same place.
Generally it's configurable. The one that comes to mind first is TokenWorks's Anti-Passback feature which says "Set your custom timeframe (1 hour to 7 days)"