The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.
Details remain limited as the FBI continues its preliminary investigation into the incident. The breach reportedly involves an ID verification service, though the specific company has not been publicly identified by federal authorities.
Driver's license scans represent sensitive personal identification documents that typically contain names, addresses, dates of birth, and license numbers. Such information is frequently targeted by criminals for identity theft and fraud schemes.
ID verification companies are increasingly used by banks, retailers, and other businesses to authenticate customer identities during account creation and high-value transactions. The proliferation of these services has made them attractive targets for hackers seeking large datasets of personal information.
The scale of potential exposure—described as affecting millions of Americans—indicates this could rank among the larger data breaches affecting identity verification platforms in recent years.
The FBI spokesperson did not provide additional specifics regarding when the breach occurred, how it was discovered, or the total number of affected individuals. The investigation is ongoing.
Such breaches raise renewed concerns about data security practices at third-party verification services and highlight risks associated with centralized storage of sensitive identity documents. Affected individuals may face increased vulnerability to identity theft and fraud.
This investigation underscores broader challenges facing the identity verification industry as companies balance security requirements with the operational demands of serving high volumes of customers. Previous breaches at similar services have resulted in significant regulatory scrutiny and settlements.
The FBI typically works with affected companies during investigations into data breaches, coordinating notification timelines and remediation efforts. No statement has been released regarding notifications to potentially impacted individuals at this time.
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.
Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.
A US senator has called on the NSA to provide official guidance on virtual private network selection and usage, citing confusion over the growing array of available options.
Utah will not enforce its groundbreaking VPN age-verification law while a legal challenge proceeds through the courts. The state became the first to target VPN usage alongside broader age-verification requirements.