FBI Investigates Breach at ID Verification Firm Holding Millions of Driver's License Scans
If confirmed, the breach would represent a significant exposure of government-issued identification data for millions of Americans, raising questions about federal oversight of private identity...
The Federal Bureau of Investigation is examining a potential data breach at an unidentified ID verification company that may have exposed scanned copies of millions of Americans' driver's licenses, according to a bureau spokesperson who confirmed the investigation to Bloomberg News on September 3, 2026.
The FBI spokesperson did not name the company under investigation, did not specify the number of individuals potentially affected, and did not disclose when the breach may have occurred. Those details remain unknown pending the bureau's ongoing inquiry.
ID verification companies occupy a significant role in the U.S. Digital economy. Businesses in sectors including banking, insurance, healthcare, and government services contract with these firms to confirm the identities of customers and applicants. The process typically involves users submitting photographs of government-issued identification documents, including driver's licenses, along with facial images. The aggregation of that data into centralized databases creates concentrated targets for unauthorized access.
Driver's licenses contain a range of sensitive personal information. Depending on state, a standard license includes the holder's full legal name, residential address, date of birth, physical descriptors, and a unique identification number. When combined with a scanned image, this data can be used in identity fraud, account takeover schemes, and synthetic identity creation, according to the Federal Trade Commission's consumer guidance on identity theft.
The FTC has previously noted in its annual Consumer Sentinel Network reports that identity theft complaints consistently rank among the most common fraud categories reported by Americans. In its 2024 report, the FTC recorded more than 1 million identity theft complaints that year alone, a figure that has held at or above that level since 2020.
Federal oversight of private ID verification companies is distributed across multiple regulators. The FTC holds broad authority to act against unfair or deceptive data security practices under Section 5 of the FTC Act. The Consumer Financial Protection Bureau has authority over firms that function as consumer reporting agencies. Sector-specific regulators, including the Office of the Comptroller of the Currency for banks and the Centers for Medicare and Medicaid Services for healthcare, impose additional data protection requirements on their respective industries. No single federal agency holds comprehensive jurisdiction over all private identity verification providers.
At least one major ID verification company, ID.me, has previously drawn congressional scrutiny. In 2022, the Internal Revenue Service temporarily suspended a requirement that taxpayers verify their identities through ID.me's facial recognition system after privacy advocates and lawmakers raised concerns. The IRS later expanded its in-person verification alternatives, according to IRS press releases from that period. ID.me has not been identified by the FBI or Bloomberg as the company currently under investigation.
The breach, if confirmed, would not be the first large-scale exposure of government-issued identification data in the United States. In 2015, the Office of Personnel Management disclosed that hackers had accessed personnel files and security clearance background investigation records for approximately 21.5 million federal employees and contractors, according to OPM's official breach notification. That incident included sensitive personal data and, in some cases, fingerprint records.
What would clarify the current situation includes: a named company or companies involved, the precise number of individuals whose records were exposed, the date range during which the breach occurred or was active, the method of access used by the unauthorized party, and whether any data has been used in downstream fraud. The FBI has not provided a timeline for the completion of its investigation.
As of September 3, 2026, no federal agency had issued a public consumer advisory directing affected individuals to take specific protective steps, and no company had publicly confirmed being the subject of the FBI inquiry. The Congressional Times will update this report as confirmed information becomes available.