FBI Investigates Dark Web Service Selling 153+ Million Driver's Licenses
Service appears to source data from Louisiana-based identity verification company; victims span U.S. and Canada

Key Takeaways
- A dark web service is selling scanned driver's licenses of over 153 million individuals.
- The data appears to originate from a Louisiana-based identity verification company.
- The FBI New Orleans field office has launched an official inquiry into the source.
- The method of exfiltration and the company's awareness of the breach are unverified.
- Affected individuals should monitor financial accounts and consider credit freezes.
Quick answers
- What happened?
- A dark web service is offering digital scans of over 153 million driver's licenses for sale. Based on interviews with affected individuals, the data appears to originate from images collected by a widely-used identity verification company headquartered in Louisiana. The FBI's New Orleans field office has launched an official inquiry into the source of the images, as reported by KrebsOnSecurity. The full scope of Canadian licenses and the method of data exfiltration remain unverified.
- What should defenders do?
- Affected individuals should monitor financial and online accounts for suspicious activity, consider placing fraud alerts or credit freezes with major bureaus, and be vigilant against phishing attempts using personal details. The identity verification company should conduct a thorough internal investigation and improve data security measures.
According to KrebsOnSecurity, a new identity theft service launched on the dark web this week is selling digital scans of more than 153 million driver's licenses from individuals in the United States and Canada. Interviews with affected individuals suggest the data is being siphoned from images collected by a widely-used identity verification company based in Louisiana. The publication also reports that the New Orleans field office of the Federal Bureau of Investigation (FBI) has today launched an official inquiry into the source of the images. The exact method of data exfiltration from the verification company, whether the company was aware of the breach, and the full extent of Canadian licenses included in the dump are currently unverified. The scale of 153 million records is specific, but the name of the Louisiana-based company has not been disclosed in the initial reporting. No patch is available; the breach source requires investigation and data hardening. Affected individuals are advised to monitor accounts and consider credit freezes.
Security Details
The breach involves the unauthorized collection and sale of digital driver's license scans. The data is alleged to have been exfiltrated from a Louisiana-based identity verification company's systems. The FBI is investigating the origin. No patch or fix is available as the vulnerability lies in the source company's data handling practices.
Mitigation
Affected individuals should monitor financial and online accounts for suspicious activity, consider placing fraud alerts or credit freezes with major bureaus, and be vigilant against phishing attempts using personal details. The identity verification company should conduct a thorough internal investigation and improve data security measures.
Sources
Krebs on Security
FBI Probes Service Selling 153M+ Drivers Licenses
Sep 1, 2026 · 22:40
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



