A new report counting global data breaches since September says roughly 320 million people have been exposed. The most striking incident in the tally: digital scans of 153 million US driver's licences were reportedly leaked, with the records allegedly offered for sale on a Russian cybercrime forum on the dark web. For anyone who holds a licence, driver's license data breach protection is now a practical necessity, not a theoretical one.

The details below come from the report as summarized by Business Standard. The licence records are described as reportedly leaked and allegedly for sale, so the claims have not been independently confirmed here. Still, the steps to protect yourself are the same whether or not every detail holds up.

What the 320 Million Record Exposure Includes

The report tallies people affected by data breaches worldwide since September, arriving at about 320 million. The single largest item it highlights is the alleged leak of 153 million US driver's licence scans. If accurate, that one incident would account for nearly half of the total.

The summary available to us does not list every incident behind the 320 million figure, so it would be wrong to guess at the rest. What matters is the type of data in the headline case. A licence scan is not a password. It is an image of a government-issued identity document, typically showing a name, address, date of birth, photo and licence number.

How Stolen Driver's License Data Fuels Identity Fraud

Passwords can be changed in minutes. A date of birth and a licence number cannot. That is why leaked identity documents are a lasting fraud risk: the information stays useful to criminals for years.

A scan of a licence can help someone attempt to:

  • Open accounts or apply for credit in your name
  • Pass weak identity checks with a bank, telecom provider or online service
  • Craft convincing phishing or phone scams, since the caller already knows your address and birth date
  • Take over accounts by impersonating you to customer support

The fact that records are reportedly being sold on a cybercrime forum suggests they may be bought by different buyers with different goals. That is one reason to act even if you never see an immediate sign of trouble. Large breaches also tend to be part of a wider pattern; our coverage of 4,699 ransomware attacks in the first half of 2026 shows how steady the supply of stolen data has become.

Steps to Take Now: Credit Freezes, Breach Checks and 2FA

You cannot un-leak a licence, but you can make it much harder to misuse.

1. Freeze your credit. A credit freeze restricts access to your credit file, so lenders generally cannot open new accounts without your approval. It is typically free to place and lift, and it directly blunts the most common use of stolen ID data.

2. Check whether you are exposed. Use a reputable breach-notification service to search your email address and phone number. Also watch for letters or emails from companies you have used, since affected organizations may be required to notify you.

3. Turn on two-factor authentication (2FA). Prioritize email, banking, mobile carrier and cloud storage accounts. An authenticator app or hardware key is stronger than SMS codes, because criminals who know your personal details can attempt SIM swaps.

4. Use unique passwords. A password manager makes this realistic. Breached data is often tested against other sites.

5. Monitor statements and credit reports. Review them regularly, and set up alerts for new inquiries or large transactions.

6. Be skeptical of contact out of the blue. Anyone who quotes your licence number or address to seem legitimate may be working from leaked data. Hang up and call the organization using a number you find yourself.

What a VPN Can and Can't Do After Your Data Leaks

A VPN encrypts your traffic between your device and the VPN server and hides your IP address from the sites you visit. That is useful on public Wi-Fi and for limiting some tracking. It does not reach into a database that has already been stolen.

Once a company or verification service has lost your licence scan, nothing you do with your connection changes who holds it. A VPN also cannot stop a criminal from using that data to apply for credit or phish you. Treat a VPN as one layer of everyday privacy, not as a response to a breach. Much of the risk sits with organizations holding your data, and some of them are targeted directly, as in the case of midmarket distributors facing a ransomware surge.

What This Means For You

If you hold a US driver's licence, assume your details could be in circulation and act accordingly. You do not need to panic, but you should not wait for a notification letter either. Notification timing varies widely, and the breach laws by country explainer shows why some people learn about exposure months after the fact.

Also share only what is necessary. When a service asks you to upload a licence scan, consider whether you are comfortable with how long they keep it. Every copy stored somewhere is a copy that can be lost.

Key Takeaways and Next Steps

The report's headline numbers, 320 million people exposed and 153 million alleged licence scans offered for sale, are a reminder that strong driver's license data breach protection starts with what you control: your credit file, your accounts and your habits.

  • Place a credit freeze with each credit bureau today
  • Check whether your email and phone number appear in known breaches
  • Enable 2FA on email, banking and phone accounts
  • Use a password manager and unique passwords
  • Review the breach laws explainer to understand how quickly companies must notify you

Spend twenty minutes on these steps today. They will do more for your identity security than any tool that only protects your connection.