Hackers Leak Scans of 153M Drivers Licenses—FBI Opens Probe

The FBI has launched a formal investigation after digital scans of over 153 million driver’s licenses began appearing for sale on the dark web. The leaked documents — including scans of driver’s licenses, medical cards, and residence cards — are suspected to have been stolen from a major identity verification company serving clients in both the United States and Canada.

What Was Stolen & How

The records in question include scans of driver’s licenses, medical cards, and other personal identity documents from people in the U.S. and Canada. The breach came to light when a criminal operation using the dark web service “Nexus” advertised the massive cache. The hackers claimed the data came from a big identity verification firm whose clientele includes many Fortune 500 companies. Victims have reportedly confirmed the legitimacy of their documents after seeing accurate samples online.

Who’s Affected & What’s Being Investigated

The FBI field office in New Orleans has opened an inquiry into how the documents were exfiltrated. The investigations suggest the breach source may be a Louisiana-based firm that offers identity verification services. Among the company’s clients mentioned by hackers are firms like Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment. Some leaked documents are alleged to come from a verification service used by Hertz, though official confirmation is still pending.

The criminals claim to maintain ongoing access to the document repository. They reportedly added nearly 400,000 new scans in just one 24-hour period, raising concerns the breach is still live.

Broader Context & Risks

Breach of this scale is a major concern for identity theft risks. With scanned copies of IDs being sold, bad actors can impersonate individuals for financial fraud, account takeovers, and more. Verification services are a critical link in many digital systems: when that link breaks, many downstream services from payments to employment verifications are exposed.

Digital verification providers must now face scrutiny over how securely they store sensitive documents. For consumers, it’s time to monitor credit reports, financial statements, and any alerts from identity protection services. Institutions that rely on identity verification—whether in rental services, finance, or employment—will need to tighten internal controls, employee training, and auditing of vendors.

This incident also underscores how threat actors have shifted from targeting social media or data aggregators to going after the pipelines that verify identity. The targeting of verification firms makes sense: they often hold raw, sensitive documents without necessarily having strong defenses against insider threats or advanced ransomware-style breaches.

Ultimately, this breach reveals how deeply our digital systems depend on trust in third-party identity verification. As investigations continue, companies that provide these services are likely to face regulatory pressure, class action risks, and loss of customer trust. What to watch next: whether regulators demand stricter verification standards or security audits; whether victims receive breach notifications; and whether any of the exposed institutions are directly linked to fraud stemming from this data leak.