FBI Opens Probe Into License Data Sale
A dark web service is selling 153M+ driver's license images, prompting an FBI inquiry.
An identity theft service that surfaced on the dark web this week is advertising access to more than 153 million driver's license scans belonging to people in the United States and Canada. The service appears to be powered by images harvested from a Louisiana-based identity verification company, according to individuals whose own licenses are listed for sale. That discovery has prompted the FBI's New Orleans field office to open an official inquiry into where the images came from.
A New Service on the Dark Web
The service, which KrebsOnSecurity reports is new, is offering digital scans of driver's licenses for sale. The scale is staggering: over 153 million records, covering a significant portion of the adult population in the U.S. and Canada.
KrebsOnSecurity, which first reported the story, says it verified the authenticity of the data by interviewing people whose licenses are included in the trove. Those individuals confirmed that the scans are real and appear to be sourced from a specific identity verification firm based in Louisiana.
Identity Verification Industry Under Scrutiny
The alleged source of the images—a widely used identity verification company—plays a critical role in the digital economy. Such firms are trusted to confirm that people are who they say they are, often by collecting sensitive documents like driver's licenses.
If the breach is confirmed, it would represent a major failure in the security of a system designed to protect identities. The fact that the source appears to be a single company suggests that attackers may have compromised a central repository of personal data.
FBI Launches Official Inquiry
KrebsOnSecurity learned that the FBI's New Orleans field office has initiated an official investigation into the source of the images. The inquiry is in its early stages, and no further details have been released.
This development adds a federal layer to what could be one of the largest identity-related data exposures in recent memory. The FBI's involvement signals that the issue is being treated with the seriousness it warrants.
What's at Stake
Driver's licenses are a goldmine for identity thieves. They contain not just a photo and name, but also date of birth, address, and often a license number that can be used to open accounts or commit fraud.
With over 153 million records, the potential for abuse is enormous. The victims may include individuals from all walks of life, and the long-term consequences could be severe.
Protecting Yourself
While the investigation is ongoing, experts say individuals should monitor their credit reports and be alert for signs of identity theft. If you suspect your information has been compromised, you can place a fraud alert or freeze on your credit files.
It's also wise to be cautious about sharing your driver's license information online, and to question why a company needs it in the first place.
Questions That Remain
There are many unanswered questions. How did the attackers obtain the images? Was it a breach of the verification company's systems, or an insider job? How long was the data exposed before being put up for sale?
The FBI's inquiry will hopefully answer these questions, but it may take time. In the meantime, the affected individuals are left in a precarious position, unsure of how their data was compromised or what steps to take next.
Why This Matters to You
This incident underscores the fragility of the systems that hold our most sensitive personal data. It suggests that even companies entrusted with protecting our identities are not immune to compromise.
For consumers, this could mean a higher risk of identity theft, not just now but for years to come, as the stolen data may be used in future fraud schemes. For businesses, it raises the stakes on data security, especially for those that collect and store government-issued IDs.
The ripple effects of this breach could be felt across the economy, as individuals and organizations alike grapple with the consequences of having their trust betrayed.
Sources
- Krebs on Security Original source
Continue Reading
RMM Phishing Campaign Zeroes In on US Targets
A phishing campaign spanning 46 countries uses fake documents to push RMM tools, with 45% of activity aimed at the US.
Node.js Abuse Signals Shift in Malware Delivery
Threat actors are hijacking the trusted Node.js runtime to deliver malware, evading detection in targeted attacks since early 2026.
Ransom Refusal Exposes 8.8M in Airport Breach
Manchester Airports Group data leak exposes 8.8M records after refusing ransom.