FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider
- ID
- 20691
- Status
- summarized
- Published
- 02 Sep 2026, 9:14 PM
- Fetched
- 02 Sep 2026, 10:17 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 4.5
- Created
- 02 Sep 2026, 10:19 PM
- Tags
- Audience
- developerssaas_founders
What happened
The FBI is investigating a leak of 153 million US and Canadian driver's licenses posted on a Russian cybercrime forum, including the license of US Secretary of Defense Pete Hegseth. The data is suspected to have originated from an ID-authentication service provider, though the specific vendor has not been named.
Why it matters
If you integrate third-party KYC or ID-verification APIs into your product, this is a concrete reminder that your users' most sensitive PII can be exposed at the vendor layer, not your own. Builders should scrutinize what data they pass to ID-auth providers, whether they can minimize or avoid storing ID images, and what contractual breach-notification terms they have in place.
Discussion angle
What data minimization looks like when you're forced to hand government IDs to a third-party verification service — and whether Malaysian builders using similar KYC vendors (e.g. for fintech onboarding) have any leverage to demand better breach disclosure terms.