FBI Probes Service Selling 153M+ Drivers Licenses

THE BRIEF
A newly reported dark-web identity service is offering digital scans of more than 153 million driver’s licenses belonging to people in the United States and Canada. Interviews with people who found their documents listed led the reporting to suggest that the images may have been collected by a widely used identity-verification company based in Louisiana. An FBI field office in New Orleans has reportedly opened an inquiry into where the images came from. Those are significant signals, but they are not the same as a confirmed breach finding. The reported number, the suspected collection source, and the relationship between individual listings remain subject to investigation. No supplied information establishes which organizations are affected, how the images were obtained, or whether every listed document is authentic and current. Financial institutions should nevertheless treat exposed identity documents as a fraud-enablement risk. A stolen license image can support impersonation, account-opening attempts, social engineering, or efforts to defeat weak document checks. The appropriate response is targeted review of identity-proofing dependencies, vendor assurances, document-reuse detection, and escalation paths for suspected customer exposure.
WHY IT MATTERS
Banks often depend on external identity-verification providers during onboarding, account recovery, lending, and high-risk changes. If document images are exposed, attackers may gain material for convincing impersonation even when passwords and account balances are unaffected. The story does not prove that a particular bank or provider suffered a breach, so broad customer notification or emergency abandonment of a vendor would be premature without evidence. It does justify validating retention, access, subcontractor, deletion, and monitoring controls, and checking whether fraud systems can detect repeated use of the same document or inconsistent identity signals.
WHO SHOULD CARE
Fraud leaders, digital-onboarding owners, privacy officers, third-party-risk managers, customer-support teams, and investigators should care. Boards and senior executives should understand that identity-document exposure can create long-lived fraud pressure without proving direct account compromise.
WHAT TO DO NOW
- Ask identity-verification vendors to confirm current retention, access, deletion, subcontractor, and incident-notification controls for license images.
- Review onboarding and recovery rules for document reuse, image replay, mismatched identity attributes, and manual-review escalation.
- Search fraud telemetry for repeated document identifiers, recurring image characteristics, unusual geographic patterns, and rapid account activity after verification.
- Prepare customer-support guidance that distinguishes suspected document exposure from confirmed account compromise and directs customers to appropriate protective steps.
- Coordinate with legal, privacy, and law-enforcement contacts before making claims about the reported source or scale.
VERIFICATION NOTE
KrebsOnSecurity reports the service and an FBI inquiry; the scale and source of the license images should remain attributed to the reporting.