FBI Probes Service Selling 153M+ Drivers Licenses

Curated from Krebs on Security

For SREs and security engineers, this breach underscores a critical, often overlooked dependency risk: third-party identity verification vendors. When your authentication stack relies on external services to process biometric data or government-issued IDs, you are inheriting their entire supply chain risk profile. The scale of this leak suggests a systemic failure in data handling or access controls at the vendor level, exposing millions of users to immediate identity theft. This is not just a privacy issue; it is a direct threat to the trust integrity of any service relying on those credentials for onboarding or compliance. Concrete takeaway: Audit your third-party identity providers immediately. Verify their data retention policies, encryption standards at rest, and incident response SLAs. Ensure your architecture supports rapid credential revocation if such a vendor is compromised, rather than relying on the vendor to notify you before the damage is done.

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

— Krebs on Security

Read the full article on Krebs on Security →