FBI Probes Dark Web Service Selling 153 Million Driver’s License Scans
- The Mess: A new identity-theft service is selling digital scans of more than 153 million driver’s licenses from people in the United States and Canada, triggering an FBI investigation into where the documents came from.
- The Damage: Stolen license scans can give criminals far more than a name and email address — they can fuel identity theft, account fraud, impersonation and increasingly convincing social-engineering attacks.
- The Fix: Don’t treat a driver’s license image as a secure authentication factor, monitor accounts for identity fraud and assume that static identity documents can eventually become reusable criminal inventory.
The dark web doesn’t need another password dump.
It now appears to have something considerably more useful.
Driver’s licenses.
More than 153 million of them, according to a new identity-theft service offering digital scans of documents belonging to people in the United States and Canada.
And this isn’t just another criminal claiming to possess a giant database.
Journalists were able to contact people whose documents appeared to be available through the service.
The FBI is now investigating where the images came from.
That makes this one of the biggest identity-security stories of the year.
153 Million Identity Documents
The newly launched criminal service is offering access to digital scans of more than 153 million driver’s licenses.
The advertised dataset covers people in:
- the United States
- Canada
A driver’s license is considerably more valuable to an identity thief than a leaked email address.
It can contain:
- a full name
- date of birth
- home address
- photograph
- signature
- document number
- other identifying information depending on the jurisdiction
In other words:
a ready-made identity package.
According to the investigation, the FBI’s New Orleans field office has opened an inquiry into the source of the documents.
The exact origin of the data has not yet been publicly confirmed.
This Doesn’t Look Like a Normal Password Leak
Most data breaches create an obvious problem.
Passwords can be changed.
API keys can be revoked.
Sessions can expire.
A driver’s license is different.
You can’t simply rotate your identity.
Even if someone replaces a document, the information printed on the old scan may still remain useful to criminals.
Your:
name
date of birth
address
and
photograph
don’t disappear when the physical card is replaced.
That’s what makes identity-document breaches so persistent.
The Source Appears to Be an Identity Verification Ecosystem
The investigation indicates that the criminal service may be obtaining images collected by a widely used identity-verification company.
That would make this particularly significant.
Modern users are constantly asked to upload identity documents.
Banks ask.
Crypto platforms ask.
Marketplaces ask.
Financial services ask.
Age-verification systems ask.
Employment platforms ask.
Government contractors ask.
The document is uploaded.
The service checks it.
And then the image potentially becomes another permanent copy sitting inside someone else’s infrastructure.
The more companies that collect identity documents, the larger the target becomes.
The FBI Is Investigating
The FBI has reportedly opened an official inquiry into the source of the document images.
That’s important because the current evidence does not justify declaring:
“Company X has been confirmed as the source of a 153-million-record breach.”
That has not been publicly established.
What we have instead is:
a criminal service
offering an enormous collection of identity documents,
plus evidence that at least some records correspond to real people,
plus an active FBI inquiry into where the images originated.
That’s already serious enough without inventing details that haven’t been confirmed.
A Driver’s License Is an Identity-Verification Weapon
Criminals don’t need to use a stolen license to create a physical fake.
The digital scan alone can have enormous value.
It can be used to support:
- identity theft
- account takeover attempts
- fraudulent account creation
- social engineering
- fake KYC verification
- cryptocurrency fraud
- financial fraud
- impersonation
- targeted phishing
The document gives an attacker something that ordinary breached data often lacks:
visual credibility.
The Photo Changes the Attack
Imagine receiving a message from someone claiming to be a financial-service representative.
They know your:
- full name
- address
- date of birth
That is already dangerous.
Now imagine the attacker also possesses a high-quality image of your identity document.
The fraud operation suddenly has much more material to work with.
Static identity information can be copied forever.
That’s the uncomfortable weakness in document-based verification.
Once the image escapes, the image remains useful.
The KYC Industry Has a Massive Concentration Problem
The digital economy has quietly created huge repositories of identity documents.
Every service wants to know who the customer is.
The result is predictable.
A small number of identity-verification providers may end up processing documents belonging to millions of people.
That creates an extraordinary concentration of risk.
One compromise doesn’t necessarily expose:
one company’s users.
It can potentially expose users from hundreds or thousands of businesses relying on the same verification infrastructure.
That’s the supply-chain problem nobody sees when uploading a license.
The customer thinks:
I’m giving my ID to this website.
In reality, the document may pass through:
the website → verification provider → cloud infrastructure → storage systems → third-party services.
Every additional copy increases the attack surface.
Static Documents Are Terrible Long-Term Secrets
Passwords are secrets.
At least in theory.
A driver’s license isn’t.
You show it to:
- employers
- hotels
- banks
- rental companies
- government agencies
- financial services
- verification platforms
The system was designed around the assumption that seeing the document proves something about the person holding it.
Digital identity theft breaks that assumption.
A criminal with a perfect scan may be able to convince poorly designed systems that they are looking at the real document.
The document itself becomes a reusable token.
And reusable tokens eventually get stolen.
This Could Become a Phishing Goldmine
The immediate concern is identity theft.
The second concern is phishing.
Attackers armed with verified identity information can construct messages that look far more convincing than normal spam.
They may know:
- who you are
- where you live
- how old you are
- what your document looks like
The attack doesn’t need to begin with:
Dear customer.
It can begin with information that only appears to come from a trusted organization.
The more personal information criminals possess, the harder phishing becomes to detect.
The Real Scale Could Be Worse Than the Number
153 million is already enormous.
But the number raises another question.
How many copies of the same document exist?
How many versions are older?
How many are duplicated?
How many additional records exist outside the service currently being investigated?
We don’t know.
And that’s exactly why early reporting should remain careful.
The current story isn’t:
“153 million people are confirmed victims of a newly identified breach.”
The story is:
a criminal identity-theft service is selling more than 153 million driver’s-license scans, and the FBI is investigating the source.
Those are not the same claim.
What Can Individuals Actually Do?
Unfortunately, there is no magic button that makes a leaked identity document disappear.
But users can reduce the chances of secondary fraud.
Watch for:
- unexpected account-opening notifications
- suspicious financial activity
- password-reset requests you didn’t initiate
- unexpected credit applications
- messages requesting additional identity verification
- calls claiming your identity has been compromised
Don’t send another copy of your ID simply because an unexpected email claims it is required.
Verify the organization independently.
And remember:
a photograph of your driver’s license should not be treated like a password.
Once copied, it can potentially circulate indefinitely.
Companies Need to Stop Treating ID Uploads as a Security Shortcut
There is a growing habit across the Internet:
Upload your government ID. Problem solved.
Except the ID itself becomes another sensitive asset requiring protection.
Organizations collecting identity documents need to ask:
- Do we actually need to store this image?
- Can the document be deleted after verification?
- Can verification be performed without retaining the full image?
- How long do we keep the data?
- Who can access it?
- Is the storage environment isolated?
- Can a compromise expose documents belonging to customers of multiple companies?
The safest identity document is often the one you no longer need to store.
The Industry Has Created a Permanent Honeypot
Cybersecurity loves the word “crown jewels.”
Identity documents might be the ultimate version.
Passwords can be reset.
Credit cards can be replaced.
API keys can be revoked.
A person’s identity is considerably harder to rotate.
And the Internet is building more centralized collections of those identities every year.
The attacker’s target doesn’t even need to be a government database.
A private verification company processing millions of documents can become just as attractive.
Possibly more attractive.
Bugstoday Opinion
The most uncomfortable part of this story isn’t the number.
It’s what the number represents.
153 million static identity documents.
Documents people were repeatedly told to upload because a website needed to “verify” who they were.
Passwords eventually leak.
That’s almost expected.
But an identity document is supposed to prove you’re a real person.
Once criminals have a copy, that proof becomes part of their toolkit.
Bugstoday verdict: stop pretending that uploading a driver’s license is a harmless verification step. Every company collecting identity documents is building a potential identity-theft honeypot. The FBI investigation may eventually reveal where these 153 million scans came from, but the larger problem is already obvious: the Internet has collected far too many permanent copies of identities that cannot simply be changed after a breach.
Today’s Bugs. Tomorrow’s Breaches.
Sources
- KrebsOnSecurity — FBI Investigation Into 153M+ Driver’s License Scans
- FBI — Identity Theft Resources
- NIST — Digital Identity Guidelines
- FTC — Identity Theft and Fraud Guidance




