Skip to content

Thursday, September 3, 2026

Gigantum.net
Software & security

FBI investigating report of millions of driver’s licenses being leaked on dark web

A report earlier this week said millions of driver’s licenses, including that of Defense Secretary Pete Hegseth, may have been leaked on the dark web.

· 710 words· updated September 3, 2026 at 02:23 PM
(Getty Images)
(Getty Images)

(NEXSTAR) – The FBI’s New Orleans field office says it is investigating after a report surfaced that millions of driver’s licenses belonging to U.S. and Canadian residents may have appeared on the dark web.

Earlier this week, Brian Krebs, an independent journalist, reported that he had found a dark web site selling the digital scans of more than 153 million driver’s licenses. He described finding the records of multiple friends and family members, noting that several of those he spoke with reported renting a car around the same time as the timestamps included with the digital scans.

Krebs alleged that some of the businesses these individuals reported sharing their driver’s license with work with IDScan.net , a company that verifies IDs. A representative for the company reportedly told Krebs the matter was under investigation. Nexstar contacted IDScan.net for comment but did not receive a response.

In his report, Krebs explained that the FBI confirmed it was investigating an apparent breach involving IDScan.net .

When reached for comment, the agency’s New Orleans field office told Nexstar, “The FBI can confirm that it is looking into the incident. Due to the ongoing nature of the investigation, we decline to comment further.”

Nexstar has not been able to confirm the validity of the dark web posting cited by Krebs. In an update to his Wednesday posting, Krebs said the website in which the digital scans were posted had been removed.

Nexstar has also not been able to confirm Krebs’ reporting that Defense Secretary Pete Hegseth’s driver’s license was included in the alleged leak. An official confirmed with Nexstar that the War Department is “aware of these reports and is evaluating them.”

Zach Edwards, a threat researcher at the cybersecurity company Infoblox, told Reuters that this breach, if it is as wide-ranging as alleged, may be the largest on record.

Information associated with a driver’s license is “enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable,” Seemant Sehgal, founder and CEO of BreachLock, explained to Infosecurity Magazine .

What if your information was leaked in a breach?

Unfortunately, it probably wouldn’t be the first time. There have been several data breaches in recent years, including two 2024 incidents exposing billions in personal information records and the sensitive information (like Social Security numbers) of more than 70 million people.

Simple measures, like freezing your credit, can reduce your exposure for these types of crimes of opportunity. That can prevent bad actors from using your Social Security number to take out loans or open new credit cards, for example.

Freezing your credit prevents any new credit, like loans or new credit cards, from being approved, whether it’s legitimate or not. You are able to freeze (and “thaw,” or lift the freeze on) your credit report for free with the three major credit reporting agencies : Equifax, Experian, and TransUnion.

If someone has used your driver’s license, the Federal Trade Commission recommends reporting it immediately to your nearest Department of Motor Vehicles agency. Your state may be able to flag your license number in the event that another attempt is made to use it. The FTC also suggests checking, freezing, and monitoring your credit, as mentioned above.

While it is widely believed our personal information, like Social Security numbers, is already out there , experts note not everyone who has been victimized in a data breach will end up victimized by identity theft.

“If you’re a high-value individual that maybe has a high net worth or works at a company that they can extort you, you might actually be a real target,” Kyle Hanslovan, CEO of cybersecurity firm Huntress, previously told Nexstar. “For the masses though, the everyday common person, you’re more of a target of opportunity.”

Most people shouldn’t spend too much time worrying about what may happen if their information ends up in the wrong hands, Hanslovan says. Instead, he recommends keeping an eye on your important accounts and making sure you’re prepared to act in case something does go wrong.

“It stinks for privacy, but it kind of normalizes just what’s happening,” Hanslovan said. “It doesn’t make it right, and it definitely doesn’t wave, you know, a company’s true fiduciary responsibilities to protect your data.”

Gathered from external sources. Rights to this text belong to whoever originally published it.