FBI Probes a 153M Driver’s License Trove, Plus 4 Stories
A dark-web service says it is selling scans of more than 153 million U.S. and Canadian driver’s licenses, and the FBI is investigating where they came from. Today’s Brief also covers a court-software breach, stress on the country’s largest electric grid, New York City pausing student-facing generative AI through eighth grade, and a Google antitrust ruling.
The FBI is investigating a 153-million-license identity trove
This is one of those breach stories where the number is enormous enough that it can outrun what we actually know. So, first, the part that is established: KrebsOnSecurity found a new dark-web service called Nexus claiming to sell more than 153 million driver’s-license scans, plus roughly 10 million other ID cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. The FBI has separately confirmed to Reuters that it is looking into the incident.
Brian Krebs didn’t just take the seller’s word for it. He checked licenses belonging to friends and family with their permission and confirmed nine records were authentic. The timestamps attached to those scans lined up with dates those people had traveled. His own license was being used as a free sample. He also watched the database grow by nearly 400,000 license records in about 24 hours, which is why the possibility of an ongoing breach matters as much as the headline number.
What is not established yet is the source. Krebs’ reporting points toward images collected through an identity-verification company, and IDScan.net told him it was investigating. Reuters could not independently establish that the stolen data came from IDScan.net, and the company had not responded to Reuters’ requests for comment. That distinction matters. “153 million licenses are for sale” and “we know exactly who lost them” are not the same claim.
A driver’s-license image is useful because so many systems treat it as proof that you are you. It can help a fraudster build convincing account-opening documents, pass weaker identity checks, or make a phishing attempt look frighteningly legitimate. Replacing the physical card doesn’t magically erase a copy of the old image from somebody else’s database.
There is no confirmed victim-notification list yet, so I wouldn’t tell 150 million people to replace their licenses this morning. A free credit freeze with Equifax, Experian and TransUnion is a much more useful general defense against somebody opening new credit in your name, and the FTC recommends continuing to monitor existing accounts because a freeze doesn’t protect those. Also be especially suspicious of emails or calls claiming they need another copy of your ID to “verify” whether your ID was stolen. That would be a very efficient sequel to the original problem.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
A court software breach may have exposed personal information
Thomson Reuters disclosed a separate security incident involving C-Track, a case-management platform used by court systems. The company detected unauthorized activity June 30 and later determined that an intruder had obtained files from one cloud environment as early as March.
The affected systems span Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, the U.S. Virgin Islands, and parts of Canada including Ontario. Some affected court records contained names and personal information. Thomson Reuters says C-Track itself remains operational and safe to use, but the company and Ontario’s courts have not yet established publicly exactly what information was taken or how many people are affected.
That uncertainty is worth preserving. Court files can range from things that are intentionally public to records containing sensitive information about people who may never have chosen to put themselves in a database at all. If you’re involved in a proceeding handled by one of the affected court systems, watch for official notices and be cautious about highly specific phishing that references a real case, court, attorney or filing. Attackers don’t need every secret about you if they have enough accurate context to make the fake message believable.
Extreme heat is pushing the largest U.S. power grid into emergency procedures
There is also a much more physical technology problem today: keeping the lights and air conditioners on while a large part of the country is very hot at the same time.
The Department of Energy issued an emergency order September 1 allowing PJM Interconnection to dispatch specified generators and call on backup generation as a last resort if conditions worsen. PJM serves about 67 million people from the Mid-Atlantic into the Midwest. Its own application said hot weather was driving demand toward 152,000 megawatts or more while outages and firm power exports added stress.
PJM has a Maximum Generation Alert and Load Management Alert in effect for September 3. Those alerts are aimed at utilities and generators; PJM explicitly says they do not require action from customers. That is important, because “grid emergency” sounds a lot like “everybody unplug the refrigerator.” We are not there.
Other regions are tight too. Reuters reports that MISO, which coordinates power across 15 states, expected demand around 121 gigawatts, near its 127.1-gigawatt record, and raised reserve requirements. Some local utilities have asked customers to conserve. If your own utility sends one of those requests, follow it. Otherwise the useful takeaway is that the grid is operating with less room for surprises during this heat wave, not that rotating blackouts have already begun.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
New York City is pausing student-facing generative AI through eighth grade
New York City Public Schools announced a one-year moratorium on student-facing generative AI for children from 2-K through eighth grade, affecting nearly 600,000 students. Companion chatbots are prohibited across all grades.
Calling this simply an “AI ban” loses some useful detail. The city is still allowing teachers to use approved AI tools for planning and operational work. High school students will get two AI-critical-thinking modules during the year, and up to 50,000 students can participate in limited, teacher-supervised pilots. There are also exceptions for assistive technology, multilingual learners and some career-readiness programs.
In other words, the policy is less “pretend AI doesn’t exist” and more “don’t make a rapidly changing chatbot part of a child’s normal classroom workflow before we know what it is doing to the learning.” The city is pairing that pause with screen-time recommendations and a Technology in Schools Coalition that is supposed to study the results and make recommendations for future years.
That strikes at the question schools are going to have to answer whether they like AI or not: when does a tool help a student think, and when does it quietly do the thinking instead? New York is choosing to spend a year gathering evidence before answering that for younger students at enormous scale. Given how often education technology has arrived with a sales deck several years ahead of the evidence, a controlled pause is not an absurd idea.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Google keeps its ad-tech business, but a judge ordered changes
A federal judge has ordered Google to change the digital-advertising system that a court previously found to be an illegal monopoly, but she rejected the Justice Department’s request to force Google to sell pieces of the business.
There is an unusual reporting problem here: Judge Leonie Brinkema’s full opinion and the exact remedies will remain sealed for 14 days while the parties review it for redactions. We know she ordered changes and said she agreed with most of the remedies proposed by the two sides. We do not yet know enough to tell a publisher, advertiser or small business exactly what will change inside Google’s ad stack.
That makes some of the early “Google escapes breakup” coverage technically correct but incomplete. The government lost the structural remedy it wanted. Google still has to alter a system a federal court found unlawfully monopolized the publisher ad-server and ad-exchange markets. Google argues a breakup would have damaged tools used by small businesses and publishers; critics argue behavioral rules won’t be strong enough to change the underlying market power.
For businesses using Google Ads or publishers depending on Google’s ad technology, there is nothing to reconfigure today. The useful thing is to wait for the actual order instead of inventing operational consequences from a two-page public decision. Fourteen days is not a terribly long time to postpone pretending we know what a sealed document says.
There is a thread through all five stories: technology keeps creating systems we depend on long before most of us can inspect them. Identity-verification companies hold government IDs. Courts move proceedings into cloud platforms. Power markets coordinate thousands of generators. Schools are deciding how much thinking to hand to software, and advertising runs through machinery few outsiders can explain. The question isn’t whether technology belongs there. It’s whether the safeguards and accountability grew as fast as the dependency did.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- KrebsOnSecurity: FBI Probes Service Selling 153M+ Drivers Licenses
- Reuters: FBI investigates reported driver’s-license data breach
- FTC: Get a credit freeze to stop identity thieves
- Reuters: Thomson Reuters detects C-Track cybersecurity incident
- U.S. Department of Energy: PJM emergency order
- PJM: Current hot-weather operations updates
- Reuters: Heat wave stresses U.S. electric grids
- NYC Mayor’s Office: Generative AI moratorium in schools
- Associated Press: Judge orders changes to Google’s ad-tech business
