Industry News

FBI Investigates Dark Web Service Selling 153 Million Stolen Driver's Licenses

Krebs on Security · 2 Sept 2026
Key Takeaway Before using any third-party identity verification service, ask detailed questions about how they store and protect scanned ID documents, and avoid retaining copies of customer IDs longer than necessary.

A new identity theft service appeared on the dark web this week, offering for sale digital scans of over 153 million driver's licenses belonging to residents of the United States and Canada. According to research from Krebs on Security, interviews with individuals whose license images were found on the service suggest the data was siphoned from a widely-used identity verification company based in Louisiana.

The FBI's New Orleans field office has confirmed it has opened an official inquiry into the source of the leaked images. While the exact method used to obtain this data has not yet been disclosed, the scale of the breach—spanning millions of individuals across two countries—highlights the risks businesses take on when they rely on third-party identity verification providers to store sensitive personal documents.

For Australian small businesses, this incident is a reminder that any organisation using overseas or third-party identity verification services should understand exactly how that provider stores, secures, and disposes of customer identification documents. Breaches like this can expose customers to identity fraud long after the original transaction is complete, and businesses that share customer data with vendors may face reputational and regulatory fallout even if the breach wasn't their direct fault.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Krebs on Security. We link back to every original so you can read it yourself.