# Massive Identity Theft Service Exposed on Dark Web, Selling Scans of Over 150 Million U.S. and Canadian Drivers Licenses
A massive identity theft operation surfaced on the dark web this week, offering digital scans of identity documents belonging to more than 153 million individuals in the United States and Canada. The service, which appeared on a prominent Russian-language cybercrime forum, has triggered federal interest and raised serious questions about how sensitive personal data is being collected, stored, and exploited by third-party verification companies.
## The Scale of the Breach
The operation, which has been referred to by cybersecurity researchers, advertises an enormous catalog of stolen identity documents. In addition to drivers licenses, the service claims to possess more than 10 million state identification cards, over three million travel documents or international IDs, and at least 579,000 medical cards. Some records even include marijuana dispensary cards, and others are labeled with the notation “CDL,” presumably standing for commercial drivers licenses, while a subset carries “CAC,” the acronym for Common Access Cards issued to government employees.
Analysts who have examined the database note that the volume of records is difficult to dispute. Running a search with no filters returns millions of pages of results, with the vast majority pertaining to American citizens. Canadian records represent a smaller fraction, concentrated most heavily in the province of Ontario.
## How the Data Was Likely Collected
Investigative efforts point toward a widely-used identity verification provider headquartered in Louisiana, one that processes ID checks for a sprawling network of businesses. The company reportedly works with clients across multiple industries, including car rental agencies, retail chains, federal contractors, financial services firms, and hospitality companies. Its technology is designed to scan identity documents using both infrared and ultraviolet light, capturing detailed images that include the front and back of a license along with embedded security features.
According to early analysis, the stolen records appear to correlate with moments when individuals handed over their drivers licenses in person at various businesses. Timestamps embedded in the image files suggest the data was collected over an extended period, and freshly uploaded records are being added at a rate of nearly 400,000 in a single day. Some records include six separate image files per license — front and back scans in standard, infrared, and ultraviolet formats — each with a precise date and time stamp.
Several individuals who consented to have their licenses checked against the database confirmed that the timestamps aligned with recent trips where they had presented their licenses, including at car rental counters, airport security checkpoints, and retail locations. In at least one case, a car rental company was identified as a common factor among multiple victims whose license data appeared on the platform.
## Federal Investigation Underway
The Federal Bureau of Investigation has confirmed that it has launched an inquiry into the incident. The agency’s New Orleans field office opened an official investigation into what appears to be a significant breach at the identity verification company. Agents from the FBI’s cyber division have been briefed on the matter, and the scope of the investigation is said to be ongoing.
The identity theft service itself was rendered inaccessible shortly after news of the breach began circulating, with its dark web login page replaced by a plain text notice stating that the service was no longer available. The operators behind the platform have not publicly commented.
## Why This Matters
State-issued drivers licenses are among the most commonly used forms of identification in the United States. They are routinely required to open bank accounts, apply for credit, pass through airport security, and access a growing number of digital services. The exposure of high-quality scans — complete with security features captured in infrared and ultraviolet wavelengths — presents a uniquely dangerous threat, as these images can potentially be used to forge documents or bypass identity verification systems that rely on document authenticity checks.
Privacy advocates have also raised concerns about the disproportionate impact on vulnerable populations, including survivors of domestic violence and individuals enrolled in federal witness protection programs, who may have limited ability to change their appearance or identity in ways that would fool modern AI-powered image recognition tools.
Cybersecurity professionals warn that the incident underscores a broader systemic risk: as more businesses offload identity verification to third-party vendors, the number of potential points of failure in the data supply chain multiplies. Oversight and accountability for these vendors remain insufficient, experts say, leaving millions of people exposed.
—
## Frequently Asked Questions (FAQ)
**Q: What kind of documents were sold on this identity theft service?**
A: The service offered digital scans of drivers licenses, state identification cards, travel documents, medical cards, marijuana dispensary cards, and government-issued Common Access Cards.
**Q: How many people were affected?**
A: The service claimed to have records for more than 153 million drivers licenses in the United States and Canada, along with millions of additional identity documents.
**Q: How were the identity documents stolen?**
A: Investigators believe the data was siphoned from an identity verification company based in Louisiana that processes ID scans for a wide range of businesses. The company’s systems scan licenses using infrared and ultraviolet light, and the stolen images appear to match the timing and circumstances of when individuals handed over their licenses at various establishments.
**Q: Which businesses were connected to the breached verification company?**
A: The identity verification provider reportedly services clients including car rental agencies, retail chains, federal contractors, financial services companies, and hospitality and entertainment enterprises. Its network spans more than 20,000 locations worldwide.
**Q: What is the FBI doing about this?**
A: The FBI’s New Orleans field office has opened an official investigation into the apparent breach. Agents from the cyber division have been engaged, and the inquiry is ongoing.
**Q: Can people protect themselves after their data has been exposed in this way?**
A: Once high-quality scanned images of drivers licenses are circulating on the dark web, it is extremely difficult to reverse the exposure. Affected individuals are advised to monitor their financial accounts closely, place fraud alerts or credit freezes with major credit bureaus, and remain vigilant for signs of identity misuse.
**Q: Has the identity theft service been taken down?**
A: The service’s dark web presence was reportedly taken offline shortly after the breach became public, though the operators behind it have not been publicly identified or apprehended as of the latest reporting.
—
## Conclusion
The emergence of this identity theft service marks a alarming escalation in the scale and sophistication of personal data breaches. With over 150 million drivers licenses and countless additional identity documents exposed, the incident highlights the profound risks that arise when sensitive verification data is concentrated in the hands of a limited number of third-party providers. The federal investigation currently underway is expected to shed light on how the breach occurred and who is responsible, but for the millions of individuals whose data is now in the wild, the damage may already be done. Moving forward, stronger regulations, greater transparency, and more rigorous security standards for identity verification companies will be essential to preventing a breach of this magnitude from happening again.
Thank you for reading



