FBI Probes Theft of 153 Million Driver's License Scans
Federal investigators are tracking a dark web operation selling digital images of government IDs linked to a Louisiana verification firm.
The FBI has launched a major investigation into the sale of more than 153 million digital scans of driver's licenses from the United States and Canada. The breach represents a critical escalation in identity theft, as the stolen assets are high-resolution images rather than simple text records.
According to reports from Krebs on Security and 9to5Mac, the stolen data is currently being marketed on the dark web. The FBI's New Orleans field office has opened an official inquiry to determine the exact source of the images. Investigators have linked the breach to IDScan.net, an identity verification company based in Louisiana. In addition to driver's licenses, the stolen cache includes residence, travel, and medical cards, providing criminals with a comprehensive toolkit for impersonation. The scale of the exposure is highlighted by the fact that the stolen data includes the driver's license of U.S. Defense Secretary Pete Hegseth, as reported by NBC News.
The Vulnerability of Digital Verification
This breach targets the very infrastructure designed to prevent fraud. Identity verification companies like IDScan.net are employed by various sectors to ensure that the person presenting an ID is who they claim to be. By siphoning these images directly from the verification source, hackers have bypassed the security layers intended to protect sensitive government-issued documentation. While threat actors on the Exploit forum claim the exfiltration has been ongoing for over a year, this specific timeline remains unverified by federal investigators.
Why Image-Based Leaks Differ
Traditional data breaches typically involve databases of names, Social Security numbers, and addresses. While dangerous, those text-based leaks are often easier for financial institutions to flag. This breach is significantly more potent because it involves actual digital scans of physical IDs.
These images can be used to deceive "Know Your Customer" (KYC) protocols, which are the gold standard for digital onboarding at banks, cryptocurrency exchanges, and government agencies. When a service asks a user to upload a photo of their ID to prove their identity, a high-quality stolen scan can often bypass these automated checks, allowing fraudsters to open fraudulent accounts or access secure government services with a level of authenticity that text data cannot provide.
The Path Forward
As the FBI continues its probe in New Orleans, the industry is facing a reckoning over how identity verification firms store and protect the images they process. The primary concern for security experts is whether other verification providers are susceptible to similar siphoning attacks. For now, the focus remains on identifying the full scope of the compromised records and determining if the leak is still active or if the vulnerability has been patched.