September 3, 2026

A massive cache of stolen American driver’s licenses has appeared for sale on a relatively new dark-web marketplace, exposing the personal details of more than 153 million people. According to reporting from Ars Technica, the data set includes high-resolution scans of physical licenses along with associated personal information such as names, addresses, dates of birth, and in many cases Social Security numbers. The sheer volume suggests the records were compiled from multiple breaches that occurred over several years, then consolidated into a single, marketable package.

The marketplace offering the collection, which surfaced in early September 2026, operates under a name that translates roughly to “Identity Bazaar.” It uses a familiar dark-web template: an onion address accessible only through the Tor browser, cryptocurrency payments in Bitcoin or Monero, and escrow services to reassure buyers that the seller will not disappear with their funds. What sets this listing apart is the scale and the quality of the images. Unlike many previous dumps that contained only text records scraped from corporate databases, this one features actual photographs of the plastic cards, complete with holograms, magnetic stripes, and barcodes. Such detail makes the material far more useful for criminals seeking to create convincing forgeries or to pass identity checks that require visual confirmation.

Security researchers who examined samples provided by the seller say the data appears genuine. Several individuals whose licenses were included confirmed that the scanned images match their official documents and that the associated addresses and birth dates are accurate. One researcher, working under the handle “vx-underground,” downloaded a small test batch and cross-referenced it against known breach corpora. The overlap with earlier incidents, including the 2021 breach of a major background-check company and the 2023 compromise of several state motor-vehicle databases, is substantial. It seems the operator behind Identity Bazaar spent months aggregating records from underground forums and private Telegram channels before assembling them into this massive bundle.

The pricing structure reflects the perceived value. Buyers can purchase the entire archive for 15 bitcoin, roughly $1.1 million at current exchange rates, or opt for smaller regional subsets. A package covering licenses from California, New York, and Texas costs about 2.5 bitcoin. Individual records are also available at prices ranging from $15 to $45 depending on the amount of supplementary data attached. The seller advertises that more than 40 percent of the records include linked Social Security numbers, a detail that dramatically increases their worth for tax-fraud schemes and account takeovers.

Law enforcement agencies have taken notice. The FBI issued a statement acknowledging awareness of the marketplace and said it is working with affected state departments of motor vehicles to assess exposure. Several states have already begun notifying residents whose data appears in the collection. California’s DMV sent automated alerts to roughly 18 million license holders, advising them to monitor credit reports and consider placing fraud alerts with the major credit bureaus. Similar messages went out from New York, Florida, and Illinois. Privacy advocates argue that such notifications, while necessary, arrive far too late. Many of the underlying breaches happened years ago, yet the compromised data remained circulating in private circles until the public listing made its existence impossible to ignore.

The appearance of this collection highlights ongoing weaknesses in how states manage driver’s license data. Most motor-vehicle agencies still rely on legacy systems originally designed decades before widespread internet connectivity. These platforms were never built to withstand sophisticated cyberattacks or to protect the high-resolution images now routinely stored in digital form. When a contractor or vendor with broad access is compromised, the fallout can be enormous. In several documented cases, attackers gained entry through third-party software used for appointment scheduling or online renewal portals. Once inside the network, they exfiltrated entire document repositories without triggering meaningful alarms.

Compounding the problem is the fact that driver’s licenses have become de facto national identification documents. They are used to open bank accounts, board airplanes, purchase restricted items, and verify age for social-media platforms. A single high-quality scan can therefore serve as a master key for multiple types of fraud. Criminal groups have already demonstrated creativity in exploiting such material. In one scheme uncovered last year, fraudsters used stolen license images to create deepfake videos for bypassing video identification checks at online casinos. In another, counterfeit physical cards produced from dark-web scans were used to collect unemployment benefits across multiple states.

Identity theft experts recommend several immediate steps for anyone concerned about their exposure. First, obtain a copy of your credit report from each of the three major bureaus and look for unfamiliar accounts. Second, place a freeze on your credit file so new accounts cannot be opened without your explicit permission. Third, enable two-factor authentication on every financial and government website, preferably using an authenticator app rather than SMS. Fourth, consider signing up for an identity-monitoring service that scans dark-web markets for your personal information. While none of these measures can retroactively secure data already stolen, they can limit the damage that criminals are able to inflict.

The seller of the 153-million-record set claims to have additional caches waiting in the wings, including passport scans and digitized birth certificates. Whether those claims prove accurate remains to be seen, but the threat trajectory is clear. As more government and commercial entities digitize sensitive documents, the incentive for attackers to target those repositories grows. The dark-web economy has matured into a sophisticated marketplace where data brokers aggregate stolen material, repackage it, and sell it to the highest bidder. Buyers range from lone scammers to organized cybercrime syndicates that use the information to fuel larger campaigns such as business email compromise or large-scale tax fraud.

Some lawmakers have responded by introducing bills that would require states to adopt stricter data-protection standards, including regular third-party audits and mandatory encryption for stored images. Others advocate moving away from static plastic cards altogether and toward digital wallets that use cryptographic proofs to verify identity without revealing the underlying document. Pilot programs for such mobile driver’s licenses are already underway in several states, but widespread adoption faces both technical and political hurdles. In the meantime, the paper-and-plastic versions continue to serve as primary identification for most Americans, and their digital counterparts remain tempting targets.

The emergence of this latest data trove serves as a stark reminder that personal information, once digitized, is difficult to reclaim. Even if law enforcement manages to shut down Identity Bazaar and arrest its operator, copies of the database will almost certainly proliferate across other forums. The information itself cannot be deleted from the internet. For the 153 million affected individuals, the realistic goal is not prevention but damage control and heightened vigilance. Financial institutions, government agencies, and technology companies all share responsibility for making identity verification more resistant to stolen credentials, yet progress has been frustratingly slow.

Researchers tracking the marketplace expect the listing to remain active for weeks or months, gradually lowering in price as initial demand is satisfied. By then, the data will have changed hands multiple times, seeding new waves of fraud that may not become visible for months. The cycle has become depressingly familiar: breach, aggregation, sale, exploitation, notification, and eventual resignation. Breaking that pattern will require more than takedowns of individual dark-web sites. It demands systemic improvements in data stewardship at every level of government and commerce.

Until those changes arrive, Americans must assume that their driver’s licenses and the sensitive details they contain are potentially available to anyone willing to pay. The 153 million records now on offer represent a significant fraction of the adult population. For many, the question is no longer whether their information has been stolen, but when they will discover how it has been used against them. Proactive monitoring, credit freezes, and skepticism toward unsolicited requests for personal information remain the most practical defenses in an environment where prevention at scale has proven elusive. The dark-web marketplace may fade, but the data it sells will persist, shaping the risk landscape for years to come.

Massive Cache of 153 Million Stolen US Driver’s Licenses for Sale on Dark Web first appeared on Web and IT News.

Leave a Reply

Your email address will not be published. Required fields are marked *