6.9 million driver's licence numbers were exposed in a recent breach, giving scammers a ready stockpile of government-issued identifiers they can use to pass verification checks and impersonate customers. AssuranceAmerica confirmed attackers accessed an employee account and exposed names, contact details and licence numbers, McAfee wrote in an analysis this week. Around the same time, former Fresno television anchor Alex Delgado replied to a text claiming to be from Robinhood and later moved more than $70,000 at the scammers' direction. McAfee and Fresno Police urged people to monitor accounts, consider a fraud alert or credit freeze, and verify support numbers through official apps or company websites.
6.9 million isn't just a statistic. It's a stockpile of identity material that makes social engineering far easier to pull off. McAfee flagged the AssuranceAmerica incident as one of the largest recent exposures of government issued identity documents and explained why licence numbers, when paired with names and contact details, let attackers pass verification checks or write messages that include accurate personal data.
How attackers turn data into money
Scammers target dormant or empty brokerage accounts because the email address attached to an account is a control point. Email receives account alerts and password reset links and is commonly used as a recovery channel. If an attacker succeeds in changing that email, they can intercept future communications, use the account as proof of identity in other scams, or escalate to a full takeover if the account later receives funds.
The Fresno case shows the other half of the puzzle: social pressure. Alex Delgado told local reporters she responded to a text that claimed to be from Robinhood and then called the number supplied in the message. The caller, posing as Robinhood support, said Delgado's account was under attack and persuaded her to move funds to a different account while an investigation supposedly ran. When Delgado later contacted support through the Robinhood app, it was too late to recover the transfers, she said.
Fresno Police Detective Timothy Johnson warned that increasingly sophisticated spoofing and AI driven content make fraudulent texts and emails look official. He advised people to verify messages independently rather than use the contact details supplied in unsolicited messages. That advice mirrors McAfee's guidance that breached individuals monitor financial accounts closely and be sceptical of unexpected calls or messages that reference recently leaked personal data.
Driver's licence numbers are durable pieces of identity. Unlike a password, you can't change a licence number.
McAfee noted that attackers prize those numbers because they can be combined with names, dates of birth and contact details to clear identity checks, open accounts, or personalise phishing messages so targets are more likely to comply.
Empty brokerage accounts have value beyond immediate cash. An account an attacker controls becomes a credential they can show to other services, a landing place to route funds, or a stepping stone for more elaborate fraud. Low cost social engineering and readily available breached data lower the friction for these schemes, turning accounts that seem inert into usable assets for criminals.
The mechanics are straightforward. First, attackers collect leaked personal data. Second, they craft a convincing alert or call that references the leaked details. Third, they pressure the target to follow instructions, often involving moving money or revealing authentication codes. Delgado's loss illustrates how effective that sequence can be even when victims try to verify claims later through official channels.
Related Articles
Consider placing a fraud alert or a credit freeze with the credit bureaus, and contact financial services only through verified app or website phone numbers rather than links or numbers in unsolicited messages. Originally reported by mcafee.com.
This article was created with AI assistance.