150 Million Driver's Licence Photos May Have Been Stolen From an ID Verification Service
Key takeaways
- More than 150 million driver's licence photos are reportedly available for purchase on a dark web marketplace following a breach of an identity verification service
- 150 million records would represent approximately 45 percent of the entire US adult population
- A journalist found their own driver's licence for sale within hours of a routine car rental
- Driver's licences contain photos, dates of birth, home addresses, and government-issued identifiers, making them comprehensive identity theft packages
If you have ever verified your identity online using your driver's licence, this story will make you uncomfortable. A major identity verification service appears to have been breached, with an identity theft search site now claiming to have more than 150 million driver's licence photos available for purchase on a dark web marketplace. Separately, a journalist at Ars Technica rented a car, and within hours found their own licence on sale.
Those two data points together are significant. The scale, 150 million records, puts this in the category of the largest data breaches ever recorded. And the timeline, hours between handing over ID and finding it for sale, suggests either a very recent breach or an ongoing operation that has been running long enough to process new data quickly.
Which service was breached?
The name of the verification service has not been officially confirmed, but identity verification as a sector has grown enormously over the past five years. Regulations around age verification, financial services compliance, and platform access have pushed a huge volume of identity checks to a small number of specialist providers. The economics of the sector mean that a handful of companies have ended up holding truly enormous databases of sensitive identity documents.
Driver's licences are particularly valuable because they contain high-quality photographs, date of birth, home address, and a unique government-issued identifier. They are used not just as proof of age but as primary identity documents for opening bank accounts, accessing government services, and passing Know Your Customer checks. A stolen licence photo combined with the other data on the document is a comprehensive identity theft package.
The scale of the problem
For context, 150 million records would represent roughly 45 percent of the entire US adult population. Even if that figure is an exaggeration by whoever is selling the data, the actual number is likely still extraordinary. These kinds of claims on dark web marketplaces are sometimes inflated to drive up sale prices, but researchers who have reviewed samples in previous comparable breaches have generally found the data to be genuine.
This story is also adjacent to another one making rounds this week. Ars Technica's journalist discovered their licence for sale after a routine car rental, which raises a separate and concerning possibility: that data is not just coming from one large breach of a single provider, but from multiple points in the ecosystem where identity documents are collected, scanned, and stored. Car rental companies, hotels, government agencies, and financial institutions all collect this kind of data routinely, and their security practices vary enormously.
What you can actually do
The honest answer is not much, at least not immediately. You cannot change your driver's licence number the way you can change a password. You cannot easily get a new date of birth. What you can do is place fraud alerts or credit freezes with the major credit bureaus, which makes it harder for someone to open new accounts in your name even if they have your details.
In the UK and Europe, the regulatory response to a breach of this size would trigger mandatory notification requirements under data protection law, with significant fines for the company responsible. US breach notification laws vary by state and are generally less prescriptive about timelines, which sometimes means that the dark web marketplace knows about the data before the people whose data it is.
The bigger picture
This story fits into a pattern that has been building for several years. The push to verify identity online, driven by regulation, fraud prevention, and platform compliance requirements, has created centralised honeypots of sensitive data. Centralisation is efficient and economically attractive for the companies building these services. It is also, from a security perspective, catastrophic when it goes wrong. One breach of one provider potentially exposes everyone who has ever verified their identity through that provider's network.
The identity verification industry needs a serious rethink about how it stores and protects this data. Techniques like hashing, minimal data retention, and decentralised verification exist. They are just not always the cheapest option, and in a competitive market, the cheapest option tends to win until something goes very wrong.