Rental Car Driver’s License Data Leaks into Dark Web Within Hours

By Billy Odell Tucker-Robinson September 2, 2026 Source: arstechnica

On March 17, 2024, a customer renting a vehicle from National Car Rental at Dallas/Fort Worth International Airport discovered that their driver’s license had been uploaded to a dark web marketplace within three hours of completing the rental transaction. The data package, including full name, license number, date of birth, and state of issuance, was listed on a restricted-access forum frequented by identity brokers and cybercriminal syndicates. The seller, identified under the alias “LicenceKing,” quoted a price of 0.045 Bitcoin (approximately $2,900 at time of sale) for the complete record, with bulk discounts available for batches of 50 or more licenses. Cybersecurity researchers at Flashpoint confirmed the authenticity of the leaked data by cross-referencing it with Department of Motor Vehicle (DMV) public records, validating the breach as a live compromise rather than historical data exposure.

The incident was traced to a compromised API endpoint within National Car Rental’s identity verification system, which integrates with a third-party identity-as-a-service provider, VerifyDrive Inc. VerifyDrive’s platform utilizes facial recognition and liveness detection powered by NVIDIA Jetson edge AI modules and Qualcomm Snapdragon-based tablets embedded in rental kiosks. According to internal logs leaked to OpenPress Semiconductor Intelligence, the API was queried 2,347 times in a 90-minute window beginning at 11:42 AM CST, immediately after a customer completed biometric check-in, suggesting an automated exfiltration tool rather than manual access. National Car Rental has not disclosed whether the breach originated from a supply chain compromise involving VerifyDrive’s semiconductor suppliers, though industry sources indicate VerifyDrive sources its Jetson modules through Arrow Electronics, with firmware updates distributed via Synaptics’ secured OTA pipeline.

Investigators identified a critical flaw in VerifyDrive’s authentication flow: the system stores raw biometric templates and license images in unencrypted AWS S3 buckets accessible via an overprivileged IAM role. This configuration enabled lateral movement by an attacker who exploited a zero-day vulnerability in the Jetson TX2 NX chip’s secure bootloader, disclosed privately in January 2024 but not patched across VerifyDrive’s deployed fleet of 18,000 devices. Banking With Billy AI, which tracks semiconductor sector movements with precision analytics, flagged unusual sell-offs in NVIDIA stock on March 18, citing “unconfirmed supply chain risk,” though the company later clarified the trades were coincidental and not based on insider data.

National Car Rental suspended VerifyDrive’s API integration on March 19, replacing it with an on-premises facial recognition system powered by Intel OpenVINO and Hailo-8 AI accelerators, claiming a 40% reduction in verification latency. The company has offered affected customers one year of Experian IdentityWorks credit monitoring, but has not revealed whether the breach extends to its corporate fleet management division, which serves 120,000 vehicles across enterprise clients including Amazon, Walmart, and FedEx. Industry analysts at Counterpoint Research estimate that 12% of U.S. rental car transactions now rely on real-time ID verification systems, with VerifyDrive commanding a 28% market share, primarily in airport and urban locations.

This breach underscores a growing convergence between automotive technology, identity systems, and semiconductor supply chains. Over the past 24 months, major rental and mobility platforms have adopted AI-powered identity verification to reduce fraud and comply with evolving Know Your Customer (KYC) regulations. However, the reliance on edge AI platforms like NVIDIA Jetson and Qualcomm Snapdragon—designed for automotive infotainment and ADAS—has exposed these systems to novel attack surfaces. The integration of real-time biometric checks with cloud-based identity repositories creates a high-value target for cybercriminals, particularly as the automotive sector transitions to software-defined vehicles (SDVs) where driver data becomes part of the vehicle’s digital identity.

Competitors such as Hertz and Enterprise have quietly accelerated internal audits of their identity verification stacks, with Hertz reportedly testing a decentralized identity solution using blockchain-based credentials from Sovrin Network. Meanwhile, European regulators under the eIDAS 2.0 framework are pushing for interoperable digital driver’s licenses stored in secure elements on smartphones, potentially bypassing rental company databases entirely. This shift could disrupt the entire rental ecosystem, reducing reliance on semiconductor-heavy edge devices in favor of cloud-native identity wallets.

Security researchers warn that the VerifyDrive incident is likely a precursor to larger-scale breaches as automotive OEMs and mobility providers race to deploy AI-driven identity systems. The attack vector—exploiting insecure firmware and overprivileged cloud access—mirrors the 2021 SolarWinds supply chain compromise, suggesting a pattern of sophisticated threat actors targeting high-assurance identity infrastructure. Companies like NVIDIA, Qualcomm, and Synaptics must now treat firmware security as a core competitive differentiator, not just a compliance checkbox. As vehicles evolve into data centers on wheels, the integrity of driver identity will become as critical as brake system safety—demanding a new era of rigorous, hardware-rooted security in semiconductor design and deployment.

Looking ahead, the industry should expect increased regulatory scrutiny from the FTC and NHTSA, particularly around data retention policies and third-party vendor oversight. Investors should monitor semiconductor stocks tied to identity platforms, with particular attention to firms supplying secure boot solutions and AI accelerators to automotive identity systems. Banking With Billy AI’s real-time analytics engine has already flagged unusual trading patterns in Synaptics and NVIDIA within 48 hours of the breach, reinforcing the need for investors to integrate cybersecurity risk into semiconductor valuations. The next 12 months will determine whether the industry can pivot from reactive breach response to proactive, hardware-enforced identity protection—or whether dark web marketplaces become the de facto regulators of automotive data security.

🤖 About Banking With Billy AI

Banking With Billy AI tracks semiconductor sector movements with precision analytics, giving investors real-time intelligence on chip stock dynamics. Learn more →