
Developing story: The FBI investigation described below is active. Attribution, breach scope, and affected vendors may change. Verify current facts before publishing or acting on vendor-specific details.
A dark-web service is reportedly advertising scans of more than 153 million U.S. and Canadian driver's licenses, apparently obtained through a breach of an identity verification company. KrebsOnSecurity broke the story and reports that the FBI has opened an investigation into the operation.
The practical implication for small and midsize businesses is not abstract. If your company has ever used a third-party service to verify employee identities, screen contractors, or satisfy a compliance requirement, documents you submitted on behalf of your people may already be in the hands of whoever is running this service. And the uncomfortable truth is that most businesses have no clear picture of which identity-verification vendors they currently use, what those vendors retain, or how long they keep sensitive documents on file.
Below are three concrete steps you can take right now, before this investigation concludes and before the next breach of this kind surfaces.
Step 1: Audit Your Identity-Verification and Background-Check Vendors
Think through every point in your business where identity documents change hands. Common examples include:
Employee onboarding (I-9 verification, background screening)
Contractor and vendor credentialing
Customer identity verification required by your industry (financial services, healthcare, real estate)
Compliance-driven KYC (Know Your Customer) or AML (Anti-Money Laundering) checks
For each vendor you identify, find answers to these questions:
Does the vendor have a published data retention and deletion policy? Where does it appear in your contract or their terms of service?
How long does the vendor keep scans or copies of identity documents after the verification transaction is complete?
Does the vendor offer a process for requesting deletion of records associated with your employees or clients?
What security certifications or audit reports does the vendor publish (SOC 2 Type II is a reasonable minimum to ask for)?
If a vendor cannot answer these questions clearly, that is a signal worth taking seriously. Identity documents are not just personally sensitive. In the wrong hands they enable account takeover, synthetic identity fraud, and social-engineering attacks against the people your business is responsible for protecting.
While you are auditing, look for vendors you are no longer actively using. Former background-check providers, identity services tied to software you replaced, onboarding platforms from a prior HR system. If you stopped using them, confirm that your data was deleted and document that confirmation.
Step 2: Check Whether Your Employees or Clients Are Flagged in Dark-Web Monitoring
A breach of this size raises the probability that credentials tied to your employees or clients are already circulating in criminal marketplaces. Dark-web monitoring watches those marketplaces continuously and alerts you when email addresses, usernames, or credentials associated with your domain appear in known data sets.
This matters for two reasons. First, a compromised credential is often the first step in a larger attack. An attacker who buys a username and password from a dark-web service can use it to attempt account takeover across business email, payroll systems, benefits portals, and cloud applications. Second, if an employee's personal identity documents were exposed through a verification vendor, that same employee is more likely to become a social-engineering target, because an attacker who holds a scan of someone's driver's license can construct convincing impersonation scenarios.
Onsite Technical Services includes dark-web credential monitoring as part of its managed security program. If you want to check whether your business domain is showing up in dark-web data sets, reach out to us directly and we can run a check.
Step 3: Review Your Own Data Minimization Practices
The third step is internal, and it is the one most businesses skip: stop collecting and storing identity documents you do not actually need.
Data you never collected cannot be stolen from you. Every scan of a driver's license your business retains beyond its necessary purpose is a liability. Consider:
Do you retain copies of identity documents after verification is complete? In many cases the verification event itself is what matters legally, not a stored copy of the document. Check with your legal counsel on what your specific compliance obligations actually require you to retain.
Where are those documents stored? Email inboxes and shared drives are common holding places for identity scans that were submitted for onboarding and never formally disposed of. These are high-risk storage locations.
Who has access to those records? Apply a least-privilege approach: only the roles that have a documented operational reason to view identity documents should be able to access them.
Do you have a documented retention schedule and a deletion process? A policy that says "we delete identity documents after 90 days" is useful only if someone is responsible for executing and verifying that deletion on a regular basis.
Data minimization is not just a privacy best practice. It is a meaningful reduction in your breach exposure. A company that does not retain identity document scans cannot lose them in an incident.
The Bigger Picture: Vendor Supply-Chain Risk Is a Business Risk
This breach, if the reported scope is confirmed, would represent one of the largest known exposures of government-issued identity documents from a single source. But the mechanism behind it, a trusted verification intermediary collecting sensitive documents and becoming a high-value target, is not unusual. It is a predictable consequence of how identity verification works at scale.
Small and midsize businesses are frequently at the end of a vendor chain they did not design and cannot fully see. Your direct security investments protect your own environment. They do not automatically extend to every third party that handles data on your behalf. That is why vendor risk reviews are part of a sound security program, not an optional exercise for larger enterprises.
The three steps above are not a complete vendor risk management program. They are the immediate triage actions worth taking this week, before the investigation concludes and before the next story of this kind surfaces.
If you want a structured conversation about how your vendor relationships fit into your overall security posture, Onsite Technical Services works with Phoenix-area businesses to map those exposures and make them manageable. Start that conversation here.
This article covers a developing story. The FBI investigation is ongoing and key details, including the identity of the breached vendor and the confirmed scope of exposed records, may change. Check current news sources for the latest confirmed information before making vendor-specific decisions.

