Privacy
FBI Probes 150M Driver's Licenses Sold on Dark Web
Massive breach of US driver's license data linked to IDScan.net; FBI opens investigation. Also: TikTok's $400M COPPA settlement and more.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
FBI Investigates Sale of 150M+ Driver’s Licenses on Dark Web
The FBI has opened an investigation after more than 150 million driver’s license scans from people across the US were sold on the dark web. The identity theft service Nexus advertised on the Russian cybercrime forum Exploit claimed to have more than 153 million driver’s licenses and over 13 million other identification documents, belonging to more than 170 million people across North America. Investigative journalist Brian Krebs first reported the breach on Tuesday, Sept. 1, and shortly after publication, the Nexus website disappeared from the dark web with a message saying the service is no longer available.
Evidence uncovered during Krebs’ investigation pointed to New Orleans-based IDScan.net, whose technology is used by major businesses like Caesars Entertainment, FedEx, Hertz, and Target. Several people whose licenses appeared on Nexus said timestamps matched dates when they traveled or rented vehicles, and Krebs said six images of his own license had timestamps matching a June 2025 car rental. The database also reportedly includes records of top government officials, including Defense Secretary Pete Hegseth, whose data was listed for $100. IDScan.net said it is investigating but has not confirmed a breach. Cybersecurity researchers warn the data could create serious identity theft and privacy risks, especially for people hoping to keep their locations private.
150M+ Driver’s Licenses Exposed On Dark Web, FBI Launches Probe: Report →
Florida Bans Flock License Plate Readers on State Highways
Florida has banned Flock automated license plate readers on state highways, citing privacy concerns. The decision applies specifically to the use of the surveillance cameras on state-maintained roads.
The move marks a significant restriction on a technology that has been widely adopted by law enforcement agencies across the country. Flock cameras capture and analyze license plates, creating a searchable database of vehicle movements. Privacy advocates have long argued that such systems enable mass surveillance without proper oversight, and this ban could influence other states considering similar restrictions.
Florida bans Flock cameras on state highways over privacy concerns →
Irish Watchdog Fines HSE $750K Over Rotting Psychiatric Records
Ireland’s Data Protection Commissioner (DPC) has announced total fines of $750,000 (645,000 euros) tied to two personal data breaches involving rotting paper mental health records recovered from abandoned psychiatric hospitals. Both sites are owned by Ireland’s Health Service Executive (HSE), the national public health service. The breaches were reported after intruders gained access in October and November 2023 to former psychiatric hospitals in County Westmeath and County Donegal, where videos posted to social media highlighted medical records stored in asbestos-contaminated and mold-infested facilities.
The DPC found multiple violations of the General Data Protection Regulation, including failing to safeguard medical records and failing to retain them only as long as necessary. Deputy Commissioner Graham Doyle said site inspections revealed documents damaged by mold, contaminated by animal droppings, and rotting due to storage conditions, found in disused bathrooms, shipping containers, and rooms without lighting or heating. The DPC also reprimanded the HSE for failing to report the breaches within the GDPR-mandated 72-hour window and cited similar previous infringements as an aggravating factor. The HSE has been ordered to audit all storage facilities, expunge unnecessary paper files, and implement robust tracking systems.
Irish Privacy Watchdog Details Psychiatric Data Breaches →
Pentagon Employee DataRepublican Launches DSA Tracker Database
Jennica Pounds, a Utah software engineer and right-wing influencer known as DataRepublican, has launched a database called DSA Explorer that tracks people with ties to the Democratic Socialists of America (DSA). Pounds, who was recently hired by the Pentagon in July, created the website as a personal project that she says does not involve government money or input. Critics say the database is an inappropriate use of sensitive political information by a federal employee and could amount to government spying on US citizens.
Pounds gained fame as DataRepublican by developing AI tools that helped guide Elon Musk’s funding cuts and layoffs under DOGE. Her employment was not publicly known until it surfaced after an August dispute in which she wrongly accused a State Department undersecretary of trying to leak legally compromising documents. The site includes a disclaimer warning it may contain errors. Former Rep. Adam Kinzinger posted on X questioning how many other pro-Trump influencers are on the federal payroll. Neither Pounds nor the Department of Defense responded to requests for comment.
Utah’s “DataRepublican” launches socialist tracker →
TikTok Agrees to $400M Settlement in Children’s Data Privacy Lawsuit
TikTok has agreed to pay $400 million to resolve a US Department of Justice lawsuit alleging the platform illegally collected personal information from children under 13. The settlement is among the largest recoveries obtained under the federal Children’s Online Privacy Protection Act (COPPA). Under the deal, TikTok will pay $300 million, plus an additional $100 million if a court vacates the 2019 Federal Trade Commission consent decree involving its predecessor, Musical.ly.
The August 2024 lawsuit targeted TikTok, ByteDance Ltd., and related affiliates, alleging that TikTok allowed children under 13 to create regular accounts, collected their personal information while using inadequate systems to detect and remove those accounts, and made it difficult for parents to have accounts deleted. The government also alleged that millions of users under 13 were able to join the app and interact with adults. The case followed a 2019 FTC consent decree with Musical.ly that required $5.7 million in payments and corrective measures. TikTok is also facing a separate class action lawsuit over alleged unsolicited text messages.
TikTok agrees to pay $400 million to settle DOJ suit over data from children under 13 →