The FBI has opened an investigation into a dark web identity theft marketplace offering digital scans of more than 153 million drivers licenses belonging to US and Canadian residents. The leaked credentials appear to originate from a Louisiana-based identity verification company whose systems became the source of the breach.

KrebsOnSecurity first reported the scheme this week after discovering individuals whose licenses were listed for sale on the service. Through interviews with affected persons, journalists traced the leaked images to a single identity verification vendor operating from New Orleans. The company's name has not been publicly disclosed, but the FBI's New Orleans field office confirmed it launched an official inquiry into the matter.

The scale of this breach places it among the largest credential theft operations targeting North American citizens. At 153 million exposed drivers licenses, the leaked dataset represents a substantial portion of the combined US and Canadian population. Each compromised license contains government-issued photo identification, address information, date of birth, and license number, all of which enable high-confidence identity fraud and account takeover attacks.

Identity verification companies occupy a critical position in the trust chain for financial services, employment screening, and government interactions. These vendors onboard customers by requiring photo ID uploads, which they then use to confirm identity during account creation. The compromise of a single verification vendor therefore exposes millions of end users across dozens of industries simultaneously.

The business model for this particular dark web service remains unclear. Operators might sell individual licenses to fraudsters at per-unit rates, or bundle datasets for bulk purchase. Historical pricing for compromised drivers license data ranges from USD 1 to 15 per record depending on the data richness and verification status. At 153 million records, a bulk sale at conservative rates could generate millions in criminal revenue.

For affected individuals, the exposure creates immediate fraud risk. Threat actors armed with government-issued photo IDs can establish fraudulent accounts, secure loans, file tax returns, or claim benefits in victims' names. US and Canadian authorities typically require photo ID verification for financial transactions, making drivers licenses particularly valuable to criminals.

The incident reflects a broader pattern of weakness in identity verification infrastructure. Multiple vendors in this space have suffered breaches in recent years. In 2023, Onfido disclosed a data breach affecting millions. In 2022, Socure confirmed customer data exposure. These companies collect sensitive data at scale but sometimes deploy insufficient access controls, encryption, or monitoring to protect it.

The FBI investigation will focus on determining how the identity verification company's systems were compromised. Possibilities include credential theft targeting employee accounts, unpatched vulnerabilities in customer-facing systems, compromised API access, or insider theft. The investigation will also attempt to identify the dark web service operator and prevent continued sales of the stolen data.

Affected individuals should monitor credit reports and place fraud alerts with the three major US credit bureaus (Equifax, Experian, TransUnion). Canadian residents can contact Equifax Canada. Credit freezes provide stronger protection than fraud alerts by blocking new account creation entirely. Financial institutions should implement additional verification steps for any account linked to the compromised records. State and provincial motor vehicle departments may issue replacement licenses to affected persons.