Dark Web Marketplace Selling 153M+ Stolen Drivers License Scans
First seen Sep 2, 2026 · Updated Sep 2, 2026
A newly launched dark web identity theft service is selling digital scans of over 153 million U.S. and Canadian drivers licenses, apparently sourced from a breach or insider leak at a Louisiana-based identity verification company. The FBI's New Orleans field office has opened a formal inquiry into the origin of the leaked images. This represents a massive PII exposure event impacting identity verification supply chains widely used for KYC and onboarding processes.
Technical Analysis
The leaked dataset consists of high-resolution scans of government-issued drivers licenses, likely exfiltrated from the backend storage or API of an identity verification (IDV) vendor that processes document uploads for KYC/AML compliance. The scale (153M+ records) suggests either a long-term unauthorized data siphon, an exposed cloud storage bucket/API endpoint, or an insider threat within the vendor's infrastructure rather than a single point-in-time breach. Threat actors appear to be reselling these images for synthetic identity fraud, account takeover, and bypassing identity verification checks that rely on document authenticity. Organizations that integrate this or similar IDV vendors into automated onboarding pipelines?including AI agents performing identity verification, document parsing, or KYC decisioning?may unknowingly process or rely on compromised identity data, and any AI agent system using this vendor's API for document verification should treat verification results as potentially untrustworthy until the breach source and scope are confirmed.
Affected Systems
Third-party identity verification (IDV) platform based in Louisiana; downstream systems and applications integrating this vendor's document scanning/verification API; any KYC/onboarding pipeline relying on the compromised vendor
Indicators of Compromise
- Dark web marketplace selling drivers license scans (specific domain/onion address not disclosed in source)
- Affected vendor: unnamed Louisiana-based identity verification company (per FBI New Orleans field office inquiry)
Remediation Steps
- 1
Identify Vendor Exposure
Determine if your organization uses the implicated Louisiana-based identity verification vendor, directly or through a subprocessor, and request breach disclosure details.
- 2
Audit Identity Verification Dependencies
Review all systems, including AI-driven onboarding or KYC agents, that consume this vendor's verification results and flag any decisions made using potentially compromised data.
- 3
Enhance Fraud Monitoring
Increase monitoring for synthetic identity fraud, account takeover attempts, and new account fraud using stolen driver's license data, particularly for U.S. and Canadian customer bases.
- 4
Notify Affected Individuals
If your organization is a customer of the breached vendor, prepare for regulatory notification obligations and customer communication regarding potential PII exposure.
- 5
Strengthen Vendor Risk Management
Reassess third-party risk assessments for identity verification vendors, including data retention practices, encryption at rest, and access controls on document storage.
- 6
Coordinate with Law Enforcement
Cooperate with the FBI New Orleans field office inquiry if your organization is identified as a data source or affected customer.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.