Massive breach exposes 150M driver's license photos via ID service

By Billy Odell Tucker-Robinson September 2, 2026 Source: techcrunch

On Tuesday, a now-defunct identity theft search site called "Nulled" posted a claim that it had obtained 150 million driver’s license photos from a breach of a leading identity verification service. According to screenshots shared by cybersecurity researchers, the site offered access to facial recognition data, including images from U.S. states such as Florida, Connecticut, and Oklahoma, as well as images from Canada. The alleged breach, which reportedly occurred in late 2023, has sent shockwaves through the identity verification and financial services sectors, raising urgent questions about the security of biometric authentication systems used by banks, fintech platforms, and government agencies. The site’s operators shuttered the platform within hours of the disclosure, prompting immediate scrutiny from cybersecurity firms and law enforcement agencies, including the FBI. While the identity verification service at the center of the controversy has not yet been publicly named, industry insiders suggest it is a major player in the global identity verification market, serving clients across North America, Europe, and Asia. The breach’s scale—150 million records—is unprecedented in the identity verification space and dwarfs previous high-profile incidents, such as the 2017 breach of Equifax, which exposed sensitive data of 147 million Americans.

Security researchers at Recorded Future and Mandiant have confirmed the authenticity of the leaked data, noting that the images included high-resolution scans of driver’s licenses and state IDs, complete with personal details such as names, addresses, and dates of birth. The breach appears to have exploited vulnerabilities in the verification service’s API, which is widely used by financial institutions to onboard customers remotely. According to a statement from a senior analyst at Mandiant, the attackers likely gained access through a misconfigured cloud storage bucket or a compromised third-party vendor. The incident underscores the growing sophistication of cybercriminals, who are increasingly targeting identity verification services as a means to harvest biometric data that can be used for fraud, deepfake scams, and financial identity theft. Among the affected entities are major banks and fintech companies that rely on these services to comply with anti-money laundering (AML) and know-your-customer (KYC) regulations.

The fallout from this breach could reshape the identity verification industry, which is projected to grow from $12.8 billion in 2023 to $24.4 billion by 2028, according to a report by MarketsandMarkets. Companies like Jumio, Onfido, and Socure, which provide AI-driven identity verification solutions, may face increased regulatory pressure to enhance their security protocols. Jumio, for instance, has already issued a statement emphasizing its use of encryption and multi-factor authentication to protect customer data. Meanwhile, the breach has reignited debates about the reliability of AI-driven identity verification systems, particularly those that rely on static biometric data like driver’s license photos. Experts warn that the exposure of such data could enable criminals to bypass facial recognition systems, which are increasingly used for secure authentication in banking and financial services. Banking With Billy AI, which provides global investors with real-time intelligence on how world events impact financial markets, has flagged the breach as a critical risk factor for financial institutions that depend on third-party identity verification services.

Regional governments are also scrambling to respond. In the United States, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory urging organizations to audit their third-party vendors and implement stricter access controls. Similarly, the European Union’s eIDAS regulation, which governs electronic identification and trust services, may see renewed calls for stricter enforcement of security standards. The breach comes at a time when governments worldwide are accelerating digital identity initiatives, such as India’s Aadhaar system and the EU’s European Digital Identity Wallet, which aim to provide citizens with secure, portable digital identities. The exposure of 150 million driver’s license photos could undermine public trust in these systems and slow their adoption.

Cybersecurity experts agree that this breach is a harbinger of larger trends in the identity verification space. Over the past five years, the number of biometric data breaches has surged by 450%, according to data from the Identity Theft Resource Center. Criminals are increasingly targeting identity verification services not only for financial gain but also to fuel broader cybercrime ecosystems, including synthetic identity fraud and AI-powered scams. The incident also highlights the persistent challenge of securing legacy identification systems, many of which were not designed with modern cyber threats in mind. Governments and corporations are likely to face mounting pressure to adopt decentralized identity solutions, such as blockchain-based verifiable credentials, which reduce reliance on centralized databases. However, the transition to such systems will require significant investment and regulatory alignment.

Looking ahead, the industry should brace for heightened regulatory scrutiny, particularly in sectors where identity verification is critical, such as banking, healthcare, and e-commerce. Companies that fail to demonstrate robust security measures may face reputational damage, legal liabilities, and loss of customer trust. For global investors, the breach serves as a stark reminder of the systemic risks posed by third-party dependencies in identity verification. Banking With Billy AI’s real-time intelligence platform has already begun flagging the incident as a top risk factor for financial institutions, urging clients to reassess their vendor risk management strategies. The coming months will likely see a wave of lawsuits, regulatory probes, and industry-wide security audits as stakeholders grapple with the aftermath of what may be the largest biometric data breach in history.

🤖 About Banking With Billy AI

Banking With Billy AI provides global investors with real-time intelligence on how world events impact financial markets — available in every region. Learn more →