FBI Investigating Massive Leak of 153 Million US Driver's Licenses on Dark Web
How stolen identity documents fuel the phone scams hitting your number
Your phone rings. "This is Rachel from Chase Fraud Prevention. We've detected unusual activity on your account—two wire transfers totaling $8,000 to an overseas account. Before we freeze your card, can you confirm you're still at 742 Evergreen Terrace, Springfield?"
You haven't moved in five years. The address is correct. Your middle name is correct. Even your license expiration date matches when she asks. How does she know?
She knows because 153 million US driver's licenses were exposed in a data breach under FBI investigation. Your full legal name, home address, date of birth, and license number are circulating in dark web marketplaces. This isn't abstract identity theft. It's the infrastructure powering the scam calls hitting your phone every single day.
The 153 Million License Leak: What We Know
The breach surfaced in 2026 when security researcher Brian Krebs documented a dark web listing offering 153 million US driver's license records in bulk. The dataset includes full legal names, residential addresses, dates of birth, and license numbers. The FBI confirmed an active investigation but has not yet attributed the breach to a specific source or disclosed which state DMV databases were compromised.
Driver's license data is a verified identity document. Unlike a leaked email address or password, a license record links directly to credit bureaus, banking institutions, telecom carriers, and government services. It's the skeleton key to your financial life.
Attribution remains unclear. No ransomware gang has claimed credit, no state DMV has issued a public disclosure, and the FBI has not named suspects. What we know for certain: the data is real, it's being sold, and scammers are weaponizing it right now.
How Stolen License Data Turns Into the Scam Call You Got This Morning
The 153 million record leak doesn't just enable old-school identity theft. It supercharges the phone scams Traceback users report daily through three attack vectors.
Caller ID spoofing gets personal. Scammers use your area code, street name, and full legal name to spoof local numbers that look safe on your caller ID. When "Springfield Hospital" calls from a 217 number and knows your middle initial, you answer. Traditional spam filters flag robocalls by volume, not by content. Traceback's conditional call forwarding technology captures the real number behind the spoof in 1.3 seconds, surfacing the actual caller before you engage.
Social engineering becomes surgical. Say a caller claims to be from Verizon and asks you to verify your address as a security measure. You give the street name. They say, "Great, and that's apartment 3B, correct?" You confirm. They've passed "security" without you realizing they fed you the answer. With your license details in hand, scammers navigate bank security questions, carrier verification prompts, and password reset flows designed to protect you.
SIM swap attacks go mainstream. A scammer calls T-Mobile posing as you. They provide your full name, date of birth, home address, and license number, all from the breach. The carrier rep, following protocol, ports your number to a SIM card the scammer controls. Within minutes, they intercept your 2FA codes, reset your bank passwords, and drain accounts while you're locked out of your own phone. The FBI has documented a significant increase in SIM swap complaints in recent years, and leaked driver's license data is the fuel.
Why Scam Calls Are Getting More Convincing
Scammers blend stolen identity records with cheap VoIP services to operate at industrial scale across Verizon, AT&T, T-Mobile, and smaller carriers like Mint Mobile, Cricket, and Boost. They spoof caller IDs to match your area code, route calls through anonymized gateways, and hang up the moment you question a detail because they can dial 10,000 more numbers in the next hour. Volume plus personalization equals profit.
Traceback doesn't stop the breach. That damage is done. When a scammer spoofs a local hospital or bank and you tap "Reveal," Traceback surfaces the real number behind the facade, often a VoIP gateway in another state or country. Knowing who's actually calling changes the power dynamic. You stop answering calls that sound convincing but feel wrong.
The underlying problem is the data ecosystem. Breaches feed marketplaces, marketplaces feed scammers, and scammers feed on the fact that most people still trust caller ID. Traceback works because it doesn't trust caller ID. It captures the actual originating number using conditional call forwarding, a technique that redirects hidden or declined calls through Traceback's infrastructure to unmask the source in 1.3 seconds. Works on iOS and Android, with no carrier cooperation required beyond basic call forwarding support, which every major US carrier offers.
For more on how Traceback compares to traditional spam filters, see how Traceback reveals hidden and No Caller ID calls.
What to Do Right Now
- Assume your license data is out there. If you've had a US driver's license in the past decade, treat this breach as affecting you.
- Freeze your credit with all three bureaus (Equifax, Experian, TransUnion) using annualcreditreport.com. This prevents new account fraud even if scammers have your full identity details.
- Set up account PINs with your wireless carrier. Call Verizon, T-Mobile, or AT&T and add a separate numeric PIN required for any account changes. This blocks SIM swap attacks.
- Use Traceback to identify suspicious callers when a No Caller ID or local-spoofed number calls. Visit us.trytraceback.com/pricing for subscription details and to start your free trial.
- If a caller knows your license details and asks you to verify them, hang up and call the institution directly using the number on your card or statement, never the number the caller provides.
- File reports with the FTC and FBI IC3 if you're targeted by a scam call that references personal details from this breach.
- Monitor your bank and credit card statements weekly for unauthorized charges. Scammers test small transactions first.
FAQ
Can I find out if my driver's license was in the 153 million record leak?
Not yet. No public search tool exists, and the FBI has not disclosed which state DMV databases were compromised. Assume your data is exposed if you've held a US driver's license in the past ten years. Take protective steps now rather than waiting for confirmation.
What's a SIM swap attack and how does stolen license data enable it?
A SIM swap attack occurs when a scammer convinces your wireless carrier to port your phone number to a SIM card they control. They use your full name, date of birth, address, and license number, all from the breach, to pass carrier security verification. Once they own your number, they intercept 2FA codes, reset passwords, and drain financial accounts while you're locked out.
Why can't my carrier just block spoofed calls?
The caller ID system wasn't designed for security. It transmits whatever data the originating carrier sends, and scammers use VoIP services to inject fake caller IDs. STIR/SHAKEN authentication helps, but it only verifies the call path, not the identity. Traceback uses conditional call forwarding to capture the actual originating number before the call reaches your phone, bypassing the caller ID system entirely.
Is my data still at risk if I've since moved or renewed my license?
Yes. Old addresses and dates of birth remain useful for social engineering. Scammers don't need current data to pass security questions. They might say, "We're updating our records, you used to live at 742 Evergreen, correct?" You confirm, they build trust, and the attack proceeds.
How does Traceback work?
Traceback uses conditional call forwarding. When a hidden or No Caller ID call arrives, it's redirected through Traceback's infrastructure, which captures the actual originating number in 1.3 seconds. The number is surfaced in the app with carrier name and location data when available. Learn more at us.trytraceback.com.
Should I change my phone number after this breach?
Usually no. Changing your number disrupts 2FA, banking alerts, and legitimate contacts. Focus instead on securing the number you have with carrier-level PINs, monitoring for unauthorized account changes, and using Traceback to identify suspicious calls before answering.
What's the difference between a data breach and a dark web leak?
A data breach is the initial theft or unauthorized access to a database. A dark web leak is the subsequent public distribution or sale of that stolen data on underground marketplaces. This driver's license dataset was breached at some point in the past, and the leak occurred when it appeared for sale on dark web forums in 2026.
How should I document a scam call for my own records?
Use Traceback to log the call with the revealed number, timestamp, and any details you remember about the interaction. Keep notes separate from any official reports you file. For official documentation, report directly to the FTC, FBI IC3, and your local law enforcement. If you need legal guidance, consult a qualified attorney about your specific situation.
For context on how scammers are using similar tactics in other schemes, read about AI voice cloning scams targeting families and task-based job scams that start with a phone call.
Your License Is Out There. Your Phone Doesn't Have to Be.
You can't undo the breach. The 153 million records are circulating, bundled, sold, and resold across marketplaces you'll never see. What you can control is who gets through to you. When a scammer spoofs your local bank and knows your middle name, they're counting on you to answer, trust, and comply.
Start your free Traceback trial. See who's really calling. Stop answering calls from people pretending to be someone they're not. Visit us.trytraceback.com/pricing to get started.
⚠️ Disclaimer: This article is general information only and does not constitute legal advice. For any specific legal situation, consult a qualified attorney. Traceback is not responsible for legal outcomes.