FBI Investigates Massive Breach of 153 Million IDs, Including Pete Hegseth’s Driver’s Licence

Dark web service claims to have sensitive data from IDScan.net breach

Hegseth License Leak Data Breach
Federal investigators are probing a devastating dark web data breach after an illicit marketplace listed 153 million North American driver's licences for sale at just $100 apiece Pete Hegseth X account

The FBI has opened an inquiry into an alleged data breach involving a dark-web service that claimed to have more than 153 million driver's licence records from people in the United States and Canada.

Investigative reporting has linked the dataset to IDScan.net, a New Orleans-based identity verification company that processes ID scans for businesses ranging from cannabis dispensaries to age-restricted retailers across the country.

The breach drew immediate national attention after hackers claimed that among the exposed documents was the driver's licence of US Defense Secretary Pete Hegseth, whose personal data appearing on a criminal marketplace raises distinct national security concerns.

What Is IDScan.net and What Data Did It Hold?

IDScan.net sells software that businesses use to scan and check government-issued IDs at the point of entry, whether at a dispensary counter, a bar, or a hotel check-in desk. Its client base includes marijuana dispensaries across the United States, along with other businesses that require ID verification as a condition of sale or access.

That business model means IDScan.net's systems can process large volumes of personal data, including names, dates of birth, ID numbers and images of government-issued documents. If confirmed, the reported scale would make it one of the largest known exposures of government-issued identity documents in North America.

The stolen records reportedly appeared for sale through a dark web service called Nexus. The data on offer reportedly included not only driver's licences and state ID cards but also travel documents and medical cards. The advertised dataset also included records labelled 'CAC,' which may refer to Common Access Cards, the credentials used by Department of Defense personnel for physical and network access.

The FBI confirmed it was investigating but offered no further detail. The bureau's involvement was confirmed by multiple outlets, including Time. IDScan.net has said it is investigating whether unauthorised access occurred and what information, if any, was exposed.

Hegseth's Licence May Have Been Leaked, Too

The presence of Hegseth's driver's licence in the alleged dataset transformed gives the development a different dimension. Hegseth, who leads the Department of Defense (DoD), is among the most sensitive figures in the US government in terms of personal data exposure risk.

The breach arrives at a moment when Hegseth is already facing significant institutional pressure. Several Republican senators have publicly expressed diminished confidence in his leadership.

One unnamed senator quoted by The Independent said, 'I don't have any confidence in him anymore. I think he's all over the place—he's accelerating the retirement or forcing out some of the most distinguished leaders in the Department of Defense that we have.'

Separately, Hegseth defended US military operations by pushing back on characterisations of the ongoing Iran conflict, stating, 'Your characterisation of this incredible effort as a failure is reckless and it's irresponsible and I think it smears the sacrifice of the troops who are out there to ensure Iran never gets a nuclear weapon.'

Security professionals have long warned about exactly this kind of exposure for high-ranking officials. Common access cards, which reportedly appear in the same dataset, are issued by the DoD and carry embedded chips used for physical and logical access to classified networks and secure buildings.

The reported presence of records labelled 'CAC' raises additional questions about how government personnel credentials may be captured and handled by commercial identity-verification systems. However, it has not been established that the reported CAC records came from IDScan.net or that any DoD credential was compromised through the company.

Senator Ron Wyden of Oregon and Representative Pat Harrigan of North Carolina have previously called on the DoD to investigate its policies for protecting service members from being tracked through commercial data pipelines.

In a formal letter to the department, the lawmakers argued that the aggregation of government personnel data by commercial vendors creates exploitable intelligence for foreign adversaries. Their concerns underscore the broader national-security risks that can arise when sensitive information about military personnel is collected and handled by commercial companies.

The US military has separately taken steps to reduce its exposure to commercial tracking, including disabling mobile advertising IDs on government-issued devices. Lawmakers have warned that commercially available location data can expose US service members to foreign adversaries.

'The sale of location data, particularly that of US government personnel, poses a serious threat to national security,' Sen. Ron Wyden (D-Ore.) wrote in a letter to DoD officials to review department security guidelines.

Eva Galperin, director of Cybersecurity for the Electronic Frontier Foundation, told Task & Purpose: 'Minimising the attack surface is always good, even if you don't get the entire attack surface.'

The Scale of the Alleged Breach and Its Implications

For the tens of millions of civilians whose data may be in the exposed dataset, the consequences are more immediate and personal. Driver's licence data is a widely used identity-verification credential. Financial institutions, employers, landlords and background-check providers can use government-issued identification as part of identity checks.

If the claimed volume is accurate, the dataset would represent an extraordinary concentration of identity information, potentially exposing records belonging to a substantial number of people across the US and Canada.

PCMag reported that a hacker was offering access to the dataset on a criminal forum, meaning the information was allegedly being actively monetised. The 153 million figure originated with the Nexus marketplace and has been repeated by multiple outlets, but the FBI has not confirmed the figure, and it should not be treated as a verified count of affected individuals.

The United States does not have a single comprehensive federal privacy law governing how private companies secure all personal identification data. Instead, companies can face a patchwork of federal, state and sector-specific requirements. State-level protections vary widely. A company scanning licences in Louisiana operates under different rules than one doing the same work in California, and neither framework was built with a breach of this size in mind.

No charges had been filed, and no suspects had been publicly identified as of publication.