highOther

Dark Web Marketplace Selling 153M+ Stolen Drivers License Scans

First seen Sep 2, 2026 · Updated Sep 2, 2026

data-breachidentity-theftPII-exposuredark-webidentity-verificationKYCthird-party-risk

A newly launched dark web identity theft service is selling digital scans of over 153 million U.S. and Canadian drivers licenses, apparently sourced from a breach or insider leak at a Louisiana-based identity verification company. The FBI's New Orleans field office has opened a formal inquiry into the origin of the leaked images. This represents a massive PII exposure event impacting identity verification supply chains widely used for KYC and onboarding processes.

Technical Analysis

The leaked dataset consists of high-resolution scans of government-issued drivers licenses, likely exfiltrated from the backend storage or API of an identity verification (IDV) vendor that processes document uploads for KYC/AML compliance. The scale (153M+ records) suggests either a long-term unauthorized data siphon, an exposed cloud storage bucket/API endpoint, or an insider threat within the vendor's infrastructure rather than a single point-in-time breach. Threat actors appear to be reselling these images for synthetic identity fraud, account takeover, and bypassing identity verification checks that rely on document authenticity. Organizations that integrate this or similar IDV vendors into automated onboarding pipelines?including AI agents performing identity verification, document parsing, or KYC decisioning?may unknowingly process or rely on compromised identity data, and any AI agent system using this vendor's API for document verification should treat verification results as potentially untrustworthy until the breach source and scope are confirmed.

Affected Systems

Third-party identity verification (IDV) platform based in Louisiana; downstream systems and applications integrating this vendor's document scanning/verification API; any KYC/onboarding pipeline relying on the compromised vendor

Indicators of Compromise

  • Dark web marketplace selling drivers license scans (specific domain/onion address not disclosed in source)
  • Affected vendor: unnamed Louisiana-based identity verification company (per FBI New Orleans field office inquiry)

Remediation Steps

  1. 1

    Identify Vendor Exposure

    Determine if your organization uses the implicated Louisiana-based identity verification vendor, directly or through a subprocessor, and request breach disclosure details.

  2. 2

    Audit Identity Verification Dependencies

    Review all systems, including AI-driven onboarding or KYC agents, that consume this vendor's verification results and flag any decisions made using potentially compromised data.

  3. 3

    Enhance Fraud Monitoring

    Increase monitoring for synthetic identity fraud, account takeover attempts, and new account fraud using stolen driver's license data, particularly for U.S. and Canadian customer bases.

  4. 4

    Notify Affected Individuals

    If your organization is a customer of the breached vendor, prepare for regulatory notification obligations and customer communication regarding potential PII exposure.

  5. 5

    Strengthen Vendor Risk Management

    Reassess third-party risk assessments for identity verification vendors, including data retention practices, encryption at rest, and access controls on document storage.

  6. 6

    Coordinate with Law Enforcement

    Cooperate with the FBI New Orleans field office inquiry if your organization is identified as a data source or affected customer.

Industries Most Exposed

identity verificationfinancial servicesfintechbankinginsurancegovernmenthealthcaregig economye-commerce

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.