The FBI is investigating a report that more than 153 million driver’s licenses from the United States and Canada were leaked and put up for sale on a Russian cybercrime forum. The bureau’s New Orleans field office confirmed it is looking into the matter after independent journalist Brian Krebs published findings earlier this week detailing a new dark web identity theft service selling digital scans of the documents, according to KTSM. Defense Secretary Pete Hegseth is among those whose license reportedly appears in the trove, which has drawn extra attention to a breach that could rank among the largest exposures of government-issued identification in North America.
How Brian Krebs uncovered the identity theft service
Krebs, who runs the security news site KrebsOnSecurity, reported that he found a dark web site selling digital scans of more than 153 million driver’s licenses. The service launched this week, marketing itself as a way to obtain identity documents rather than simply dumping stolen data for free. That sets it apart from many prior breach disclosures.
The dark web marketplace and its scope of stolen records
This isn’t a one-off leak posted to a forum and forgotten. According to Krebs’s reporting, it’s structured as an ongoing identity theft service: buyers can apparently browse or query records tied to specific individuals rather than downloading a single static file. A searchable database of over 153 million records works less like a leaked archive and more like a commercial product built for repeated use by criminals.
Digital scans covering US and Canadian license holders
The records include license holders from both the United States and Canada, based on reporting cited by KTSM and other outlets covering the story. The cross-border scope matters because driver’s licenses function as primary identification for banking, travel, and government services in both countries. A combined dataset of this size suggests the breach did not come from a single state or provincial licensing agency acting alone.
Defense Secretary Pete Hegseth among those exposed
Hegseth’s driver’s license is reportedly among the 153 million records in the leaked dataset, according to reporting referenced by KTSM. His inclusion pushed the story beyond typical data breach coverage, since it places a sitting cabinet-level official’s personal identification document inside a pool of data being marketed to criminals on a Russian cybercrime forum.
What his inclusion signals about the breach’s reach
If the leak reached someone at Hegseth’s level of government service, the underlying data source likely touched a broad swath of licensed drivers rather than a narrow population or a single agency’s customer list. That breadth lines up with the overall scale being reported: a set of records spanning both countries and more than 150 million individuals.
Scale in context: roughly 63% of US drivers potentially affected
The 153 million figure works out to roughly 63% of all licensed drivers in the United States, a comparison that has circulated widely alongside coverage of the breach. This isn’t a limited incident affecting a subset of license holders in one state. It would touch a majority of the driving public in the country, assuming the reported figures hold up under investigation.
Comparison to prior government ID breaches
Multiple outlets covering the story, including KTSM and others citing the same underlying report, describe this as potentially one of the largest-ever leaks of government ID cards in North America. Driver’s licenses carry more identifying detail than many other commonly breached records: full legal name, date of birth, home address, license number, and a photograph, all in one document. A breach of this type and size puts that combination of identifiers into circulation at once, rather than exposing a single data point like an email address or password.
What’s still unknown about the source of the leak
Investigators have not publicly identified how the data was obtained or which system or organization was the point of failure. No agency, vendor, or company has been named as the confirmed source of the leaked records as of this reporting.
FBI’s New Orleans field office and the status of the probe
Reporting on the breach names the FBI’s New Orleans field office as the office handling the investigation. Beyond confirming that a probe is underway, the bureau hasn’t released additional details about timeline, suspects, or the specific vector through which the records were extracted.
Unanswered questions: how the data was obtained and by whom
The central unanswered questions are straightforward but unresolved: who obtained the data, how they obtained it, and how long the information sat on the Russian cybercrime forum before Krebs found it. Whether this stemmed from a hack of a government licensing system, a third-party vendor that processes license data, or some other point of compromise has not been disclosed. Until the FBI or another authority identifies the source, license holders in both the US and Canada have no way to confirm through official channels whether their specific records are among those exposed.
Identity theft risks for license holders
A leaked driver’s license gives criminals nearly everything needed to attempt identity theft: name, address, date of birth, license number, and a photo ID image that can be used to create fraudulent documents or pass identity verification checks at banks, lenders, and other institutions. Because the marketplace Krebs identified functions as an ongoing service rather than a static leak, the risk doesn’t end once the initial reports fade from headlines. Records can keep being sold and resold to different buyers over time.
Cross-border travelers flagged as particularly at risk
Some of the coverage around this breach has singled out people who recently crossed the US-Canada border as facing elevated risk. Since the leaked dataset spans license holders in both countries, individuals whose documents were scanned or recorded during cross-border activity may be more likely to have their information included, though the exact mechanism linking border crossings to the leak hasn’t been detailed publicly.
Practical steps for checking exposure and limiting damage
License holders concerned about exposure have limited official tools right now, since no breach notification list or lookup tool tied to this specific incident has been made public. In the absence of confirmed identification channels, standard identity protection measures apply: monitoring bank and credit card statements for unfamiliar activity, checking credit reports for accounts opened without authorization, and considering a credit freeze with the major reporting bureaus. Anyone who has recently crossed the US-Canada border may want to pay particular attention to alerts from their financial institutions in the coming weeks, given the flagged risk to that group.
What happens next in the investigation
The FBI’s New Orleans field office hasn’t released a timeline for when it expects to identify the source of the breach or confirm the authenticity of the leaked dataset. Krebs’s reporting brought the identity theft service to public attention, but verifying the full scope of the 153 million records, and tracing them back to a specific point of compromise, remains an open task for investigators. Until the bureau or another official source confirms which system was breached, driver’s license holders in the US and Canada are left to assume they may be affected and act accordingly.

Be the first to comment