Driver License Data Breach: Small Business Next Steps

Researchers found more than 153 million North American driver license scans for sale after an identity-verification vendor was implicated. Here is the practical read for local offices.

A driver license data breach is not a distant federal story. If your office scans IDs at the front desk, at a rental counter, or through a vendor that "just verifies age," those photos and barcodes can leave your building and show up in a criminal catalog.

This week, reporting tied more than 153 million U.S. and Canadian license images to a new dark-web sales service. The FBI opened an inquiry. For a small business in Bradenton or Sarasota, the useful question is not who the vendor is. It is whether you collect licenses you do not need, and whether the company that stores the scans can be trusted with that file.

What happened

Security journalist Brian Krebs described a marketplace, advertised on a cybercrime forum, that claimed tens of millions of driver licenses plus smaller piles of ID cards, travel documents, and medical cards. Listings grew by hundreds of thousands of records in a day, which is the pattern of an active feed rather than a one-time dump.

People whose licenses appeared in sample records matched the timestamps to ordinary errands: a car rental, a hotel check-in, a regulated retail visit. Several scans included extra lighting versions of the same card. That detail matters because it points to professional ID-capture hardware, not a phone photo someone emailed themselves.

The seller claimed the images came from a major identity-verification company whose customers include well-known brands. Krebs connected timestamps and customer lists to IDScan.net, a Louisiana firm that markets ID checks to rental desks, retail, and other in-person businesses. The company said it was investigating. Krebs also reported that the FBI New Orleans field office opened a case the same day his story published. Shortly after publication, the sales site went offline.

That last part is not a happy ending. Once license images circulate, copies persist. Taking a storefront down does not pull files off the machines that already bought them.

How it affects your business

A driver license is still the default proof of identity in Florida offices. Banks, landlords, clinics, auto shops, staffing firms, and hospitality desks ask for it because it is convenient. Criminals like it for the same reason. A clean front-and-back scan can support new credit, fake "know your customer" checks, and phishing that quotes a real address and date of birth.

You do not have to be the breached vendor to feel this. Your customers and staff live in the same population. Work emails used on loyalty forms, rental agreements, and vendor portals become a hook: a fake DMV notice, a "confirm your identity" payroll message, a loan application that already knows the street.

If you scan licenses yourself, you now hold a high-value file. Many small offices keep those images in a shared inbox, a front-desk PC, or a copier's scan-to-folder path. Those locations are rarely inventoried. A departing employee, an old copier hard drive, or a cloud folder shared "temporarily" can leak the same class of data without a national headline.

Vendor risk is the other half. Identity-verification tools sit in the same category as payroll processors and backup appliances: you send them sensitive records because they promise speed. CISA's guidance for small and medium businesses keeps repeating the same unglamorous steps: know what you collect, limit who can export it, and require strong sign-in on every account that can see personal data.

Florida offices that handle health, financial, or children's information have extra notification duties if those IDs sit next to the license scan. Even shops that only keep a photocopy "in case of a bounced check" should assume the copy is personal information, not scrap paper.

What to do

Skip the dark-web scavenger hunt. You will not get a reliable yes-or-no for every employee. Act as if license data is already useful to someone who wants to impersonate your staff or your customers.

1. Stop collecting what you do not need. If a policy, insurer, or regulator does not require a license image, write down the last four digits or visually confirm age and hand the card back. Every extra scan is another file you must protect.

2. Find the copies you already have. Search shared drives, email, the copier, the booking tool, and any "ID verification" app. If a folder has no owner, treat it as unmanaged. Delete what you cannot justify, and keep a short written reason for what remains.

3. Treat vendor ID tools like payroll. Ask who stores the image, for how long, in which country, and who can export a bulk file. If the vendor cannot answer in writing, do not send them another license this week.

4. Lock the accounts that can see IDs. Multi-factor authentication on email, cloud storage, and the verification portal. Remove last year's contractor. Prefer an authenticator app or a hardware key over text messages.

5. Watch for follow-on fraud. Tell staff that a real-looking DMV, IRS, or bank note may quote details from a leaked card. Confirm requests out of band. Freeze personal credit if a home address and license number were in a known dump. The Federal Trade Commission walks consumers through that process at IdentityTheft.gov.

6. Tighten the front desk. Do not leave licenses on the counter. Do not photograph IDs with a personal phone. If you must scan, send the file to a restricted folder, not a group inbox.

Our cybersecurity notes for local shops cover the same theme from the network side. If you want a second pair of eyes on where ID scans actually live, contact us and bring the list from step two. Managed IT in this market is less about a new gadget and more about assigning someone to review access before the next vendor story lands.

The marketplace in this week's reporting may already be gone. The images are not. Treat license collection as a business decision, not a habit.

---

Source: discussed on Hacker News. Original reporting: FBI Probes Service Selling 153M+ Drivers Licenses by Krebs on Security.