153 million driver’s licenses were offered for sale on the dark web. None of the owners had been hacked. None of them clicked a suspicious link, opened a malicious attachment, or used a weak password. They simply rented a car, entered a venue that required age verification, or used a service that scanned their ID to confirm their identity. One service, somewhere in a chain they never saw and never chose, stored that data – and someone managed to pull it out and sell it. This is the story recently reported by Krebs on Security, and the FBI is now investigating it. But beyond the striking headline number, this story touches on something every manager at a mid-sized company already knows deep down, even if they’ve never put it into words: we don’t actually know who our vendors’ vendors are.
What actually happened, in three lines
A commercial service, whose job was to provide identity verification or similar data to other businesses, accumulated an enormous volume of scanned driver’s licenses. Someone gained unauthorized access to that database, or the database itself was offered for sale by a party that held it legitimately but misused it. The result: a massive collection of official identity documents, meant to serve one clear purpose, became available to hostile actors. None of the license holders were direct customers of that service. They were customers of someone who was a customer of someone else – a chain three or four links long, and at the far end of it, a person’s most sensitive personal information leaked out without them ever knowing that link even existed.
Why another security tool wouldn’t have prevented this
The natural temptation, reading a story like this, is to ask what technical defenses could have stopped it. Another firewall, another monitoring tool, another layer of encryption. But that question misses the point. The problem here wasn’t technological in the narrow sense. It was structural: one organization trusted an external service to handle sensitive data, and that service, in turn, presumably relied on additional parties in the process – hosting providers, subcontractors, third-party systems. At every link, someone made a decision – sometimes consciously, sometimes not – about what level of security they were willing to provide. No one at the far end of the chain reviewed those decisions, because they didn’t even know they were being made.
This is worth pausing on, because it speaks directly to how most organizations are structured today. A mid-sized company works, on average, with dozens of software and service vendors – a CRM system, a payments platform, an email marketing tool, an HR platform, a cloud provider, a lead management system. Each of them, in turn, works with additional vendors of their own. A chain that looks transparent from the outside but is nearly impossible to map from the inside, unless someone in the organization does it deliberately. And that’s exactly what most organizations don’t do, because they lack the time, the tools, or the sense of urgency – until something like this story happens.
It’s worth being clear: as far as is currently known, this doesn’t appear to be a case of blatant negligence or a deliberate disregard for security rules – and that may be exactly what makes the story so unsettling. This looks, on the surface, like a legitimate process – an identity-verification service collecting documents in order to provide a real service to its customers. The problem sits in a layer no one sees: who actually retains this data, for how long, under what access permissions, and who checks any of that in the first place. It sounds like a question that belongs to the security and cyber domain, but in practice it’s a fully business question, because the consequences – reputational damage, legal exposure, loss of customer trust – land squarely on the CEO’s desk.
Three questions any manager can ask a vendor tomorrow
You don’t need a full security team to start addressing this problem. There are three simple questions any manager can send tomorrow morning to any key vendor the company works with, no deep technical expertise required.
First, what data of ours do you actually retain, and for how long. Not a general statement from a policy document, but a concrete answer – which data fields, where they’re stored, and when they get deleted.
Second, do you share that data with any third party, and if so – with whom, and for what purpose. This is precisely the question that would have exposed the problem in the driver’s license case. The point isn’t necessarily to get a “no” – it’s that asking the question forces the vendor to actually think about it, and forces you to understand your real risk map.
Third, what happens if you experience a security incident – who gets notified, how quickly, and what is your contractual commitment to us. Many companies sign service agreements without a clause requiring immediate notification of a security incident, and only find out about a breach once it’s already making headlines.
These questions don’t guarantee a breach won’t happen. No tool, no question, and no policy guarantees that with certainty. But they shift the burden to the right place – from a one-time technical check to an ongoing understanding of where your data actually lives and how it’s handled.
Where’s the line between caution and paranoia
This raises the opposite question, and it’s a legitimate one too: if you have to investigate every vendor, check every chain, demand answers about every subcontractor – where does it end. You can’t run a business if every partnership turns into a legal investigation. And that’s a real objection, not just an excuse to avoid the work.
The answer lies in distinguishing between two types of vendors. Some vendors handle sensitive data – customer records, financial information, identifying details – and some provide a service that has no contact with data like that at all. The demand for transparency shouldn’t be uniform. A vendor managing your employees’ payroll system should go through far more scrutiny than a vendor supplying office equipment. That’s not paranoia – it’s risk mapping by severity, exactly like every other area of management operates.
On a broader scale, there’s a clear logic here: concentrating responsibility with a single provider, instead of scattering it across dozens of point vendors with no overarching view, reduces the risk of blind links forming in the chain. When one provider is responsible for network and communications infrastructure, backup and business continuity, cloud management, and end-user support and operations, there’s a single point of contact that sees the full picture – rather than a chain of vendors each of whom sees only their own piece. This doesn’t fully solve the problem of vendors’ vendors, but it significantly reduces the number of unknown links in the chain, and shifts responsibility to someone whose job is to keep asking the right questions, all the time – not just after reading a story like the one from Krebs.
Ultimately, the story of the 153 million licenses isn’t a reminder to fear something abstract – it’s a concrete question every CEO can ask themselves this week: if a key vendor I work with were breached tomorrow, would I find out fast enough to protect my customers? And if the answer isn’t clear, that’s already a sign it’s time to start checking.
If this is an open question for your organization, we’d be glad to hear how you’re handling it. Feel free to reach out to us.
Source: FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security) — https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/


