Jessica Entwistle
September 4 2026
Krebs on Security reports that a new identity theft service launched on the dark web is selling digital scans of more than 153 million drivers licences from people in the United States and Canada. Based on interviews with individuals whose licences are available for purchase, the data appears to have been siphoned from a widely-used identity verification company based in Louisiana. The FBI's New Orleans field office is now investigating the breach. The service offers high-resolution scans of government-issued identity documents, creating significant risk for identity fraud, account takeover, synthetic identity creation, and other forms of impersonation. The scale of the breach and the quality of the data make it a particularly valuable resource for criminals.
Whilst this breach affects a US-based verification service, the operational implications extend to UK organisations that rely on third-party identity verification providers, particularly those operating internationally or using shared platforms. The incident demonstrates how identity verification services, which hold sensitive biometric and document data at scale, represent high-value targets for attackers. For organisations that use such services for customer onboarding, employee verification, right-to-work checks, or compliance processes, this is a reminder that the security of your identity verification supply chain directly affects your own risk exposure. If a provider you rely on is breached, your customers, employees, or business partners may be affected, and your organisation may face regulatory, reputational, or operational consequences. The availability of high-quality identity documents on criminal marketplaces also increases the sophistication of social engineering and account takeover attempts targeting your organisation, as attackers can now present convincing identity credentials that may pass initial verification checks.
UK businesses using third-party identity verification services should review who they rely on, how those providers protect the data they collect on your behalf, and what contractual assurances you have regarding breach notification, liability, and data handling. Consider whether your onboarding and account recovery processes have sufficient controls to detect fraudulent identity documents, particularly if attackers are using high-quality scans from breached databases. Review whether your incident response plans account for compromise of identity data held by suppliers, and whether you have clear processes for notifying affected individuals and regulators if a supplier breach affects your customers or employees. This is also a useful moment to assess whether your organisation has visibility into the security practices of the identity verification providers you use, and whether you conduct regular due diligence or audit their controls. If you operate in regulated sectors such as financial services, legal, or healthcare, consider whether your compliance obligations extend to the security of identity data held by third parties on your behalf.
Source: Krebs on Security