Federal investigators are looking into a potentially massive cybersecurity incident after digital copies of more than 153 million driver’s licenses were reportedly offered for sale on the dark web. The alleged driver’s license leak could become one of the largest known exposures of government-issued identification documents in North America if investigators confirm its reported scale. According to KrebsOnSecurity, independent cybersecurity journalist Brian Krebs discovered a dark web marketplace offering digital scans tied to people in the United States and Canada.
Krebs reported finding records belonging to several friends and relatives. According to his investigation, multiple people whose licenses appeared in the database said they had rented vehicles around dates that appeared alongside the scanned documents.
Krebs reported that some businesses used by those individuals worked with IDScan.net, a Louisiana-based company that provides identity verification services. However, neither Krebs nor federal investigators have publicly established IDScan.net as the confirmed source of the driver’s license leak. Krebs reported that a company representative said the situation was being investigated.
The FBI has confirmed that it is examining the incident. The agency’s New Orleans field office said, “The FBI can confirm that it is looking into the incident. Due to the ongoing nature of the investigation, we decline to comment further.”
The dark web marketplace highlighted by Krebs reportedly disappeared shortly after his findings became public. Krebs also reported that a driver’s license belonging to Defense Secretary Pete Hegseth appeared among the records. Nexstar said it could not independently verify that claim. An official told the outlet that the War Department is “aware of these reports and is evaluating them.”
The potential scale of the driver’s license leak is raising concerns because scanned identification documents can contain information useful to criminals attempting identity fraud or account takeovers.
Cybersecurity researcher Zach Edwards told Reuters that, if the reported scope is confirmed, the incident could rank among the largest exposures of its kind. Reuters also reported that the precise source of the data had not been confirmed.
Seemant Sehgal, founder and CEO of cybersecurity company BreachLock, explained the potential danger to Infosecurity Magazine, saying driver’s license information can provide “enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable.”
For consumers worried about whether they may have been caught up in the driver’s license leak, federal agencies recommend several steps that can make stolen information harder to exploit.
According to USAGov, consumers can place a credit freeze with Equifax, Experian, and TransUnion at no cost. A freeze restricts access to a person’s credit report, making it harder for someone to open a new credit account in that person’s name. Consumers can later temporarily or permanently lift the freeze.
The Federal Trade Commission’s IdentityTheft.gov also recommends contacting the nearest Department of Motor Vehicles office if someone has used a person’s driver’s license information. Depending on the state, officials may be able to flag the license number or recommend getting a replacement. The FTC additionally advises consumers to review, freeze, and monitor their credit.
Data exposure does not automatically mean someone will become an identity theft victim. Kyle Hanslovan, CEO of cybersecurity firm Huntress, previously told Nexstar that criminals often prioritize victims who offer the largest potential payoff.
“If you’re a high-value individual that maybe has a high net worth or works at a company that they can extort you, you might actually be a real target,” Hanslovan said. “For the masses though, the everyday common person, you’re more of a target of opportunity.”
Hanslovan recommended monitoring important accounts and being prepared to respond quickly if suspicious activity appears.
“It stinks for privacy, but it kind of normalizes just what’s happening,” Hanslovan said. “It doesn’t make it right, and it definitely doesn’t wave, you know, a company’s true fiduciary responsibilities to protect your data.”
The FBI investigation remains ongoing, and the full scope, origin, and authenticity of all records connected to the reported driver’s license leak have not yet been publicly confirmed.
