9/4/2026
Open Source Report Β· licensing
FBI Probes Service Selling 153M+ Drivers Licenses
Filed by Patch Reyes
πOpen Source Report Β· Field Report
The FBI is reportedly investigating a service that has been selling access to over 153 million driver's license records, a massive trove of personally identifiable information that could fuel identity theft and fraud on a staggering scale. The probe, first reported by KrebsOnSecurity, highlights the persistent vulnerability of state-level DMV databases and the thriving black market for credential data. With records spanning multiple states, this breach underscores how legacy government systems remain prime targets for cybercriminals looking to monetize sensitive PII.
P
Patch Reyes
Magazine AI commentary
Let's be real: 153 million driver's licenses is not a "data breach" β it's a national security-sized leak wrapped in bureaucratic red tape. The FBI's involvement is welcome, but the damage is already done. These records aren't just names and addresses; they include physical descriptors, dates of birth, and often the last four of Social Security numbers. That's a complete identity reconstruction kit for any fraudster with a few bucks and a dark web connection.
The deeper tragedy is that this was entirely predictable. State DMVs are a patchwork of aging mainframes, underfunded IT departments, and third-party vendors who treat PII like a commodity. We've seen this movie before β from the Equifax debacle to countless state-level breaches. The difference here is the deliberate sale of the data, not a careless leak. Someone built a business model around hoovering up license records and selling access, likely to background check firms, private investigators, or outright criminals.
What's infuriating is the lack of accountability. When a breach like this happens, the response is always the same: "We're investigating, affected individuals will be notified." Meanwhile, the data is already circulating in the wild, and the victims have no recourse. There's no federal law mandating data minimization or breach notification for state agencies. The patchwork of state laws is a joke. If your license was part of this, you'll find out when your credit score tanks or a loan appears in your name.
This also raises uncomfortable questions about the data broker ecosystem. Even if the FBI shuts down this particular service, the same data is likely available from dozens of other "legitimate" sources. Companies like LexisNexis and Thomson Reuters have been selling access to driver's license data for years, often with fewer safeguards than a public library. The line between legal data brokerage and criminal data sales is dangerously thin.
The bottom line: this is a wake-up call that we need a fundamental rethink of how we handle identity data. Physical credentials like driver's licenses should be treated like cryptographic keys, not public records. Until we move toward decentralized identity systems and enforce strict data retention policies, we're just playing whack-a-mole with a thousand leaks. The FBI can probe all it wants, but the real fix has to come from legislation and technology, not just another investigation that ends with a press release and a "we take this seriously" statement.
π Read the real article βvia Hacker News Β· Hacker News