GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

153 Million Driver's Licenses Reportedly Leaked in Massive Breach

A new dark web marketplace is selling driver's license data tied to car rental transactions, and the FBI is reportedly investigating.

A newly discovered dark web site is offering what it claims is data from 153 million driver's licenses, apparently sourced from car rental companies or a shared vendor in that industry. One reporter found their own license for sale just hours after renting a vehicle, suggesting the breach is active and data is flowing to the marketplace in near real time rather than from a single stale dump.

The FBI is said to be investigating, though it's unclear yet which company or companies were compromised, how the attackers got in, or how long the exposure has been ongoing. The scale, if confirmed, would make this one of the larger identity-document leaks in recent memory.

Driver's license scans are especially valuable to fraudsters because they combine a photo, address, license number, and birth date, enough to pass many identity checks used for account takeovers, fraudulent loans, or fake IDs.

Why it matters: Driver's license data is harder to reset than a password, so a leak like this creates long-tail fraud risk for victims for years. It also raises fresh questions about how much personal data rental and travel companies retain and whether their vendor security practices are keeping pace with the value of that data on dark web markets.

Sources: Ars Technica