You told yourself the license scan was the responsible choice. Banks, hiring platforms, crypto ramps, even some support desks ask for a photo of a driver’s license so they can “know their customer.” Vendors sell that ritual as cybersecurity. A lot of security leaders still buy it. This week a dark-web service listed digital scans of more than 153 million licenses from the United States and Canada. Brian Krebs reports the images appear to come from a widely used identity verification company in Louisiana, and the FBI’s New Orleans field office opened an inquiry. Credit monitoring is the popular reaction. That reaction is too small.

You Outsourced the Wallet and Called It Control

The pitch is fraud prevention. Identity proofing is supposed to catch synthetic accounts and mule onboarding that a password still misses. So you send the most durable government ID a person owns to a company your users never picked. That company stores the image, the barcode, the face, the liveness clip, the metadata. Then someone else’s leak becomes a lifetime problem for people who only wanted to open an account.

Krebs talked to individuals whose licenses are already for sale. They didn’t shop on a dark-web stall. They used a product that embedded an IDV widget, or they passed a “verify to continue” gate you required. Louisiana is a useful clue, not trivia. US-based proofing vendors sell APIs into KYC, age gates, marketplace posting, and account recovery. Your counsel signed a data processing addendum. Someone filed a SOC 2 PDF. Neither artifact tells you whether 153 million scans can leave through a support tool, a staging bucket, or a partner feed.

Quiet is the tell. If your threat-protection story begins at the firewall, this dump never becomes an alert. There is no brute-force spike against your VPN. Threat detection looking for malware callbacks will not notice a JPEG of a New York license sitting in a marketplace. Your SIEM stays bored while the document that unlocks a bank reset, a SIM swap, and a credit file is priced like bulk inventory. Treat that silence as a design flaw. For most of you, proofing is a file transfer you do not log.

Look-Alike Trust Runs the Same Harvest

License dumps get the headline because the number is obscene. You can feel 153 million. The quieter cousin is impersonation of the thing a person already decided to trust. Microsoft’s Defender Experts described an active campaign that clones vendor download pages and regenerates installer archives so the package looks freshly packed. Users go hunting for a tool. They land on a page that is close enough. The binary is not.

Security operations illustration of malware and ransomware incident handling
Counterfeit installers succeed because the download page already passed the user’s own trust check.

Malwarebytes tracked a fake GTA 6 “leak” that skips the game and goes straight for wallet-draining code. Different bait. Same mechanic. The victim performs a verification step in their own head: this looks like Rockstar, this looks like the vendor CDN, this looks like the KYC flow my bank uses. Then they hand over the asset. A license image. An installer execution. A connected wallet.

Cyber security programs still file these as separate tickets: third-party breach, malware, consumer scam. Attackers collect whatever the trust ceremony produces. For an IDV vendor, that is PII at national scale. For a counterfeit installer, that is a foothold on a corporate laptop. Your incident response runbook should assume the next “verification” your users perform is a harvest, not a control.

Your Cybersecurity Stack Never Logged the Upload

Defense in depth on paper includes identity. In production it usually means MFA, a CASB, maybe a privileged-access tool. The JPEG of a license lives in a vendor object store, in a ticket attachment, in a “for review” folder that never got a retention job. Security hardening checklists skip it because it doesn’t look like infrastructure. It looks like a form field.

The onboarding step nobody owns

Ask who owns government-ID collection in your org. Product will say compliance required it. Compliance will say the vendor is responsible. Legal will point at the DPA. Security will say it isn’t in the asset inventory. That gap is how you get to nine figures of scans without a control owner. If you cannot name the person who can answer “do we still have the image, and does the vendor?”, you are shipping documents. You are not operating an identity control.

Stolen licenses also outlive stolen passwords. A password you reset. A license image is a durable replica of a physical token that DMVs rotate slowly. Paired with a face and an address, it feeds new-account fraud, unemployment claims, and help-desk bypasses that your playbooks still treat as “the user verified.” Train the desk that a matching license photo is now a commodity. Treat it as untrusted evidence.

Assume the Scan Is Public and Build Around That

You cannot un-scan 153 million cards. You can stop treating IDV as a sacred, unexamined control, and you can reduce what a stolen image is allowed to do inside your environment. Do this in order.

Fake GTA 6 leak pages used to lure users into wallet-draining malware
A fake leak works like a fake KYC gate: the user opts into the harvest because the wrapper looks official.
  1. Inventory every path that collects a government ID. Include vendors, white-label widgets, “verify to post” features, contractor onboarding, age gates, and recovery flows that accept a photo upload. If a business unit can turn it on in a SaaS admin panel, it counts. Write down who can export the images.
  2. Pull retention, subprocessors, and breach math this week. Ask, in writing, whether images are stored or discarded after the match, where they live, who can download a bulk export, and how fast you get notified. “We are ISO certified” is not an answer. Hours-to-notice and image-deletion proof are answers.
  3. Pre-stage incident response for the population that used your IDV path. You may not get a clean victim list from the marketplace. Assume overlap. Draft customer language, help-desk scripts, and a rule that a license photo no longer proves the caller. Watch for SIM-swap patterns, new-account clusters, and password-reset spikes that follow the listing.
  4. Collect a result, not a replica. If the business need is “this person passed proofing,” store a signed pass/fail token with a timestamp and vendor transaction ID. Delete the image on your side. Contract the vendor to do the same on a short clock. If a regulator actually requires you to keep the scan, isolate that copy like you isolate payroll files, with named accessors and immutable audit logs.
  5. Make a stolen license insufficient for anything expensive. Wire changes, recovery of privileged accounts, SIM and email swaps, and new payee setup need a second channel the JPEG cannot satisfy: a known-device prompt, a callback to a number you already bound, an in-person check for the highest-risk cases. Ongoing, add the IDV vendor to tabletop exercises the same way you already include your IdP and your email gateway.

None of that requires a new product. It requires you to admit the scan was always a data store, then to starve that store and to stop worshipping the printout.

Frequently Asked Questions

Should we shut off identity verification after this dump?
Probably not wholesale. Synthetic-account pressure is real. Shut off collection you cannot justify, and shut off image retention you never needed. Keep proofing only where fraud loss actually exceeds the document-hoarding risk, and demand the vendor prove deletion.
Does a license listing mean we force a company-wide password reset?
A scan is not a password. Mass resets without evidence waste goodwill and bury real signals. Hunt for account-recovery abuse and new-account fraud tied to the same identities. Reset where you see that activity, and lock recovery methods that a photo of a card can satisfy.
How do we know if our customers are in the 153 million?
You likely will not get a tidy list from the marketplace or from the FBI inquiry. Match your IDV transaction logs to the time window and vendor named in reporting, then treat that cohort as exposed. Monitor those accounts harder than you monitor the rest.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.