
A federal investigation is underway after millions of people’s driver’s licenses may have been swept up in a huge data breach.
This comes after a Russian cybercrime site was reported to be offering access to an enormous collection of identity documents belonging to people in the US and Canada.
The operators claimed their database contained more than 153 million driver's license records, alongside millions of other documents including ID cards, travel documents and medical cards.
Cybersecurity journalist Brian Krebs discovered the service after being shown a sample of his own driver’s license. He subsequently searched the database for people he knew, with their permission, and found records that appeared to match them.
Advert
According to Krebs, the Russian site read: “We have been continuously exfiltrating new data for over a year into our private database. Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

What made the discovery particularly significant was the timing information attached to some of the documents as Krebs found that the timestamps on several licenses appeared to correspond with occasions when the people involved had actually presented their IDs in the real world.
Now, the FBI New Orleans field office has launched an investigation, with Krebs having reportedly uncovered a preview of US Secretary of Defense Pete Hegseth’s information as well as the driver’s license of an FBI assistant director.
But as soon as an investigation was made public, the service disappeared from the dark web completely.
Still, that’s not to say that all of the data is gone forever, as the FBI is still able to look into information that has been stolen and distributed.

Many people have taken to social media to share their own reactions to the shocking news, with one user writing on Reddit: “This is why I won't provide ID foe silly things that are necessary, They say your photos are safe on their server, I've never believed that and this is why.”
Another said: “Exactly why age verification services are so dangerous. They keep your papers and you have no idea to what level they take cybersecurity seriously.”
A third person commented: “It is a shocking-but-not-surprising level of incompetence to have personally identifiable information stored unencrypted for long after the information is no longer needed for the original verification task.”
And a fourth added: “When the last tangible thing is sold, you become the commodity.”