Blog

6.99 Million Driver's Licenses Exposed. Here's What Protects Your Business and Your Customers.

Insurance provider AssuranceAmerica just confirmed a breach affecting 6.99 million people — names, contact information, and driver's license numbers, along with policy and claims details. It's now the largest known exposure of Americans' driver's license information this year, and it's not an isolated event. In June, Texas' parks and wildlife division disclosed that hackers had stolen at least 3 million driver's license and passport numbers. That's two major driver's license breaches in as many months.

A Trend I Flagged Two Years Ago Hasn't Slowed Down

Back in 2024, I sat down with PYMNTS' Karen Webster to talk about what happens after a breach like this. We talked about the National Public Data breach — 2.9 billion records from a background-check company, meaning not just Social Security numbers but employment history, past addresses, and aliases. My take at the time was that a breach like that doesn't really hand criminals new information so much as it lowers the price of buying a convincing identity. Supply goes up, and cost comes down.

That trend hasn't slowed. It's accelerated. According to TransUnion's most recent fraud trends report, driver's license and state ID data now shows up in more than a third of all reported data breaches, up from just 15% in 2020 — a 140% increase in six years. Demand for this particular credential is climbing faster than for almost anything else criminals go after, because a driver's license is still the default way most businesses confirm someone is who they say they are.

Stolen Numbers Are Just the Starting Point

A driver's license number, on its own, isn't a driver's license. But paired with the flood of other personal data already circulating — addresses, birthdates, employment history — it's everything a criminal needs to assemble a convincing fake identity, then use that identity to create a counterfeit or synthetic license to match it. AI can make that counterfeit look authentic, right down to the hologram.

What can't be faked is the hidden, authoritative security format state DMVs embed inside every license's barcode — proprietary elements like digital signatures, subdirectories, and checksum formulas that only the issuing state and Intellicheck have access to. Criminals can buy someone's name, address, license number, even their medical history. What they can't buy is that hidden format, and counterfeiters can't replicate it.

Why the First Check Matters Most

Identity verification is supposed to be the first fraud check a business runs, before an account opens, a claim gets paid, or money moves. The trouble is that a lot of identity verification still relies on templates and OCR — reading what's printed on an ID and checking that it looks right. A fake built from real, stolen driver's license data is built to pass exactly that kind of check. The name matches. The address matches. Increasingly, thanks to AI, even the visual details match.

Once a fake ID gets past that first gate, the business is relying entirely on its other fraud defenses — transaction monitoring, behavioral analytics, manual review — to catch what identity verification missed. Those tools are built to flag activity that looks unusual: a new address, an odd purchase pattern, information that doesn't quite match. A fake ID built from real, stolen driver's license data doesn't trip those flags, because most of what's on it is genuine and correctly matched. That's often enough for a fraudster to take over an account, open a new one, move money out quickly, or finance a high-value purchase before anything looks wrong.

What This Means for Your Business

What can you do to neutralize a stolen driver's license number? Verify each license against the one thing a breach can't hand a fraudster: the hidden barcode format itself. A business that checks for that stops a stolen number from being useful. A business that only checks whether an ID looks right does not.

This kind of breach isn't going away. If anything, the data says it's becoming more common. Protecting your own systems will always matter, but it can't be the only line of defense, because your customers' data is also sitting in every other company that's ever collected it. The businesses that come out ahead will be the ones that plan for that reality and verify identity at the transaction level — catching the IDs made from stolen numbers before they become fraudulent accounts, claims, or withdrawals.

Download the PDF

Access this Resource

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Related Resources

The Newsroom

Stay up to date on Intellicheck with press releases, news, and company updates.

See all News