:

150M DRIVER'S LICENSE PHOTOS STOLEN IN ID SERVICE BREACH

SECURITY DESK1 MIN READ
WED, SEP 2, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

An identity theft search site claimed to possess over 150 million driver's license photos stolen from a major ID verification service. The crime site has since been shut down.

The breach exposes a significant vulnerability in identity verification infrastructure. An underground marketplace advertising the stolen data claimed access to driver's license photos from a leading ID verification provider, though the specific service has not been officially confirmed. The scale of the theft—150 million records—suggests widespread exposure affecting individuals across multiple states. Such databases are commonly used by financial institutions, government agencies, and online platforms for identity verification and age confirmation. The takedown of the crime site hosting the data does not guarantee the stolen information has been fully removed from circulation. Law enforcement agencies have reportedly been notified, though no official statement has been released confirming the breach or identifying the compromised service. This incident adds to a growing pattern of breaches targeting biometric and identity data, which remains more valuable to criminals than standard personal information due to its permanence and broad applications in fraud schemes.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A massive data breach at an unspecified car rental company exposed customer driver's licenses and personal information within hours of rental. The FBI is investigating the incident as data stolen from customers appears for sale online.

2H AGOIndustry Desk

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.

4H AGOIndustry Desk

Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.

7H AGOSecurity Desk

Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.

7H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.