Digital scans of over 153 million driver's licenses have appeared on the dark web, potentially exposing sensitive identity data. The FBI is investigating a possible breach involving an ID verification service based in Louisiana.
The leaked dataset contains high-resolution scans of driver's licenses, according to reports from security researchers monitoring dark web activity. The scope of the breach—affecting over 153 million individuals—makes it one of the largest identity document leaks on record.
Investigators are currently examining whether the breach originated from an ID verification service operating in Louisiana. Such services typically handle digital identity checks for financial institutions, government agencies, and other organizations requiring document verification. The company's identity has not yet been publicly confirmed.
The FBI's involvement signals the severity of the incident. Driver's license scans contain multiple sensitive data points including names, addresses, dates of birth, and identification numbers—all valuable information for identity theft, fraud, and social engineering attacks.
The dark web listing has raised immediate concerns among security experts about downstream risks. Bad actors could use the data for creating fraudulent documents, opening accounts in victims' names, or conducting targeted phishing campaigns.
No statement has been released regarding notification procedures for affected individuals. The investigation remains ongoing, with federal authorities working to determine how the data was accessed and when the breach occurred.
This incident underscores persistent vulnerabilities in identity verification infrastructure. Major breaches of personal documents have surfaced repeatedly in recent years, highlighting the challenges organizations face in securing sensitive data at scale.
Individuals concerned about their information should monitor credit reports and consider placing fraud alerts with credit bureaus. Further details are expected as the FBI investigation progresses.
Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.
Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.
A critical authentication bypass vulnerability in JFrog Artifactory is being actively exploited to create administrative access tokens. The flaw (CVE-2026-82329) grants attackers full control over software repositories.
Spyware was used against Serbian student activists and politicians organizing anti-corruption protests ahead of March local elections, according to a new report. The targeting allegedly focused on opponents of President Aleksandar Vucic.