The FBI's New Orleans field office has confirmed it is investigating a possible massive data breach after an independent journalist reported that the digital scans of more than 153 million driver's licenses from U.S. and Canadian residents were being sold on the dark web.
Brian Krebs, a well-known cybersecurity reporter, said he discovered a dark web marketplace offering the records. He noted that several friends and family members whose licenses appeared in the trove recalled renting cars around the time stamps embedded in the scans. Krebs alleged that some of the rental companies involved work with IDScan.net, a firm that specializes in identity verification. A representative for IDScan.net reportedly told Krebs the matter was under investigation. Nexstar's requests for comment from IDScan.net were not returned.
In his report, Krebs said the FBI had confirmed it was looking into a suspected breach involving IDScan.net. The FBI's New Orleans office, which is handling the case, told Nexstar: "The FBI can confirm that it is looking into the incident. Due to the ongoing nature of the investigation, we decline to comment further."
The validity of the dark web posting has not been independently confirmed by Nexstar. In an update to his Wednesday report, Krebs said the site hosting the scans had been taken down. Additionally, Nexstar could not verify Krebs' claim that Defense Secretary Pete Hegseth's driver's license was among the leaked records. A Defense Department official confirmed to Nexstar that the department is "aware of these reports and is evaluating them."
If the breach is as extensive as alleged, it could be one of the largest on record, according to Zach Edwards, a threat researcher at cybersecurity firm Infoblox, who spoke with Reuters. The data contained on a driver's license is sufficient to pass identity checks that many financial institutions and government agencies still consider reliable, noted Seemant Sehgal, CEO of BreachLock, in an interview with Infosecurity Magazine.
What to do if your data was exposed
Given the frequency of data breaches in recent years—including two major 2024 incidents that exposed billions of records and the sensitive data of over 70 million people—experts advise taking proactive steps. A credit freeze, which is free at the three major credit bureaus (Equifax, Experian, and TransUnion), can prevent criminals from opening new accounts in your name. You can temporarily lift the freeze when you need to apply for credit.
If you suspect your driver's license has been compromised, the Federal Trade Commission recommends reporting it to your state's DMV. Some states can flag your license number to prevent fraudulent use. The FTC also suggests checking your credit reports and considering a credit freeze.
While it's likely that much of our personal information is already in the wild, experts caution that not everyone affected by a breach will become a victim of identity theft. "If you're a high-value individual that maybe has a high net worth or works at a company that they can extort you, you might actually be a real target," said Kyle Hanslovan, CEO of cybersecurity firm Huntress. "For the masses though, the everyday common person, you're more of a target of opportunity."
Hanslovan advises most people not to obsess over the risks but to monitor important accounts and be ready to act if something appears wrong. "It stinks for privacy, but it kind of normalizes just what's happening," he said. "It doesn't make it right, and it definitely doesn't wave, you know, a company's true fiduciary responsibilities to protect your data."
The incident also raises questions about the security practices of third-party vendors that handle sensitive identification data, a concern that has been amplified by recent tensions in cross-border data sharing. Meanwhile, the potential involvement of a high-ranking official like Hegseth underscores the national security implications of such breaches.
