153 Million Driver’s Licences Are for Sale. Now We Know Whose.

Identity verification firm IDScan confirmed on 10 September 2026 that attackers took data from its cloud systems. The IDScan data breach involves scans of more than 150 million driver’s licences, alongside millions of other government-issued documents. Reports put the figure at 153 million US and Canadian licences.

The stolen records include full names, driver’s licence numbers and identity numbers taken from documents such as passports. The company is notifying affected people and offering free credit monitoring and identity protection.

The FBI’s New Orleans field office opened an investigation. IDScan operates from Louisiana.

How the IDScan data breach came to light

The public trail started before the company confirmed anything. A dark web platform appeared advertising a searchable database of identity documents for sale.

That listing claimed more than 153 million driver’s licence records, over 10 million ID cards, and millions of further documents including medical cards and travel documents. The FBI began probing the reported breach in early September.

Laptop screen representing exposed records in the IDScan data breach

IDScan said it received information around 1 September indicating that data may have been accessed without authorisation. Its confirmation followed on 10 September.

The breach operators say they pulled data continuously over a year into their private database. That claim comes from the people selling the records, and no independent source confirms it.

The gap between the first public listing and the company’s confirmation ran roughly ten days. Victims therefore learned of the sale before they learned whose systems it came from.

Why an ID verification vendor holds this much

IDScan’s corporate customers range from entertainment venues to cannabis dispensaries. Those businesses check identity documents at the door or at the point of sale.

Verification services sit in the middle of that check. They receive the document image, confirm it, and return a result. Retaining the scan afterwards turns a transaction into a stored record.

That accumulation is what makes vendor breaches different from breaches at any single venue. One compromised supplier exposes every customer that supplier served.

We saw the same structural problem in our coverage of the American Tower data breach and in our report on the TruStage outage lawsuits.

What a stolen licence scan can actually do

A driver’s licence image is more dangerous than a stolen password. Anyone can change a password in seconds. Licence numbers do not work that way.

Document images are the raw material for account takeover at services that verify identity by photo. They also support synthetic identity fraud, where real details from several people are combined into a new profile.

Credit monitoring helps with the visible part. It flags new accounts opened in a person’s name. It does nothing about a document image circulating indefinitely.

Replacing a licence is possible in most jurisdictions but rarely quick. The number often stays the same.

Why this lands differently in each country

The records span both the United States and Canada. Remedies differ across that border and across individual states and provinces.

Most US states let residents freeze credit files with each of the three national bureaus at no cost. Canada operates a smaller bureau market, and the equivalent alert process varies by province.

Replacing a licence also differs. Some jurisdictions issue a fresh number after documented fraud. Others reissue the same number on a new card.

Anyone outside North America is not automatically clear either. The advertised database included travel documents, and passport details travel across borders in a way licence numbers do not.

A researcher from Hanoi who once showed a passport at a venue using this vendor sits in a different position from a local resident. The document she presented carries weight anywhere, and no single agency can reissue confidence in it.

Steps worth taking now

Place a credit freeze rather than relying on monitoring alone. A freeze blocks new accounts instead of reporting them after the fact.

Accept the identity protection if the company notified you. It costs nothing and creates a paper trail if disputes follow.

Treat unexpected identity-verification prompts with suspicion. An attacker holding a document image may attempt verification in your name.

Check statements more often for the next few months. Fraud from bulk data sales often surfaces well after the sale.

Keep the notification letter if one arrives. Banks and insurers frequently ask for proof of the underlying breach before they write off a disputed charge, and a dated letter settles that question faster than a news article does.

Points readers keep raising about the leak

  • How many records were taken? Reports describe scans of more than 153 million US and Canadian driver’s licences, plus over 10 million ID cards and further documents.
  • What data was in them? Full names, driver’s licence numbers and identity numbers from other government-issued documents such as passports.
  • When did IDScan find out? The company said it received information around 1 September and confirmed the breach on 10 September 2026.
  • Is law enforcement involved? Yes. The FBI’s New Orleans field office opened an investigation.
  • What is IDScan offering? Notification of affected individuals plus free credit monitoring and identity protection.
  • How long was data being taken? The breach operators claim exfiltration ran continuously over a year. That claim is theirs and is unverified.

More security reporting on Tamara News

Read our coverage of the American Tower data breach, the Berlin ransomware attack and the TruStage outage lawsuits.

Sources

  • TechCrunch — ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen. techcrunch.com
  • Krebs on Security — FBI Probes Service Selling 153M+ Drivers Licenses. krebsonsecurity.com
  • TIME — FBI Probes Report of Breach Exposing 153 Million Driver’s License Scans. time.com

Nvidia Just Spent $13 Billion on a Company Most Shoppers Have Never Heard Of

Nvidia agreed on September 3, 2026 to buy Hugging Face, the open-source AI development platform. The deal is valued at roughly $12.93 billion. The Nvidia Hugging Face deal is Nvidia’s second-largest acquisition on record. It gives the chipmaker a direct line to the more than 18 million developers who use Hugging Face to build and share AI models.

Data center server racks tied to the Nvidia Hugging Face deal expansion into AI software

Inside the Nvidia Hugging Face Deal

The agreement is structured as approximately $11.9 billion in cash plus up to $1 billion in equity retention for Hugging Face employees. That comes from Bloomberg’s reporting on the transaction and Nvidia’s own securities filing. Hugging Face runs a platform and community for developing, sharing and deploying open-source models, datasets and applications. It is the software layer Nvidia has spent years trying to get closer to as it defends its position in AI hardware.

Why Nvidia Is Buying Its Way Into Open Source

Nvidia’s business has historically centered on chips, not the open developer communities that build on top of them. Acquiring Hugging Face changes that. It connects Nvidia’s hardware, software and cloud computing services directly to a platform where millions of developers already publish and download models daily. CNBC reported that Hugging Face’s own leadership approached Nvidia CEO Jensen Huang weeks ahead of the announcement. That suggests the platform saw the tie-up as beneficial for its own growth, not just Nvidia’s.

Nvidia’s Growing Acquisition Trail

The Hugging Face purchase ranks as Nvidia’s second-biggest acquisition. It trails only the roughly $20 billion purchase of assets from chipmaker Groq, completed in December 2025. That earlier deal is now drawing separate scrutiny. The US Justice Department is investigating whether Nvidia structured its licensing arrangement with Groq specifically to avoid antitrust review. The question could color how closely regulators examine the Hugging Face acquisition as it moves toward closing. Nvidia has made dozens of smaller acquisitions in recent years as it builds out its software and networking capabilities, according to deal-tracking firm Tracxn. The Hugging Face purchase breaks that pattern in scale, ranking it alongside only the Groq transaction as a deal large enough to draw sustained regulatory attention.

Server hardware representing the computing infrastructure behind the Nvidia Hugging Face deal

What Happens Before the Deal Closes

Nvidia’s securities filing points to a close in the first half of next year, pending regulatory approval. Until then, Hugging Face is expected to keep operating its platform independently. Developers and rival chipmakers will be watching closely. They want signs of how tightly Nvidia intends to integrate the platform with its own hardware and cloud offerings once the deal completes.

How Rivals and Investors Are Reacting

The deal size is large in absolute terms, but it remains a fraction of Nvidia’s overall market value, which analysts say helps explain why it has not dominated investor attention the way the Groq deal once did. The purchase can be read as a defensive move as much as an offensive one, aimed at keeping rivals from building closer ties to the open-source community Hugging Face anchors. Google and Meta both maintain their own open-model efforts. Developers on Hugging Face’s platform currently publish models built for a wide range of competing chip architectures, not just Nvidia’s. Whether that openness survives the acquisition is one of the biggest questions developers are asking. The deal is expected to close in the first half of next year. An open question is what happens to community-contributed models once a single hardware maker owns the platform hosting them. Neither company has detailed what governance changes, if any, will follow once the acquisition closes.

Frequently Asked Questions

What did Nvidia agree to buy?

Nvidia agreed on September 3, 2026 to acquire Hugging Face, the open-source AI platform used by developers to share and deploy models. The price is approximately $12.93 billion.

How is the Nvidia Hugging Face deal structured?

The transaction is roughly $11.9 billion in cash plus up to $1 billion in equity retention for Hugging Face staff, according to Nvidia’s securities filing.

Why does Nvidia want Hugging Face?

Hugging Face’s platform connects Nvidia with more than 18 million developers who build, share and deploy open-source models. It deepens the tie between Nvidia’s chips and the software ecosystem built on top of them.

Is this Nvidia’s biggest acquisition?

It is Nvidia’s second-largest acquisition on record. Only the roughly $20 billion purchase of assets from chipmaker Groq, completed in December 2025, was bigger.

When will the deal close?

Nvidia’s securities filing points to a close in the first half of next year, subject to regulatory approval.

Does this deal face antitrust scrutiny?

Nvidia already faces a separate US Justice Department inquiry into its licensing arrangement with AI-chip startup Groq. That backdrop could shape how regulators approach the Hugging Face deal.

Taken together, the Hugging Face deal and the ongoing Groq antitrust inquiry show a company simultaneously expanding its reach and defending its past dealmaking. That balancing act will likely define how regulators and rivals view Nvidia’s next moves. For more on Nvidia’s expanding footprint in AI infrastructure, see our coverage of the chip export loophole Washington is trying to close and the memory chip shortage squeezing Apple, Nvidia and Samsung. Our report on OpenAI’s GPT-6 Astra release covers the model Nvidia’s hardware increasingly competes to run.

Sources

A University Foundation Says Anthropic Built Claude on Its Patents

The University of Tennessee Research Foundation has sued Anthropic in federal court in Delaware. The foundation alleges the AI company’s systems infringe two patents covering neuroscience-inspired machine learning technology developed by university researchers. The complaint, filed in July 2026, marks the first patent-infringement case brought against Anthropic.

The foundation says the patents cover work in artificial intelligence, neural networks and neuromorphic computing invented by University of Tennessee professors. It is seeking unspecified damages along with an order blocking further alleged infringement.

Neuromorphic computing refers to hardware and software designed to mimic how biological brains process information, an approach that has influenced parts of modern machine learning research. University research foundations like the one at Tennessee typically manage patent portfolios generated by faculty and pursue licensing deals or litigation when they believe commercial use has occurred without proper authorization.

Research foundations attached to major universities often generate meaningful revenue through technology licensing, and litigation is generally treated as a last resort after licensing discussions fail to produce an agreement. Public court filings do not indicate whether the foundation attempted to negotiate a license with Anthropic before filing suit in July.

Delaware’s federal court handles a large share of US patent litigation involving technology companies, partly because many corporations are legally incorporated there. That makes the district a common venue choice for plaintiffs regardless of where the underlying dispute actually originated.

The foundation’s legal team has not publicly commented beyond the filed complaint itself. Cases at this early stage typically have no scheduling order for hearings yet, since courts usually wait for the defendant’s initial response before setting a timeline.

What the Tennessee sues Anthropic patent case actually claims

According to the foundation’s complaint, Anthropic’s AI systems rely on techniques covered by patents the university’s professors developed through their neuroscience-inspired machine learning research. The foundation manages intellectual property generated by University of Tennessee faculty. It argues that Anthropic’s commercial AI products incorporate this patented approach without a license.

Courthouse building representing the Tennessee sues Anthropic patent lawsuit

Patent infringement suits against AI companies have become more common. Universities, competitors and rights holders increasingly argue that the underlying research techniques powering large language models draw on their prior work without authorization or compensation.

Why this is a notable first for Anthropic

Anthropic has faced copyright disputes tied to training data in the past. This case is distinct because it targets the architecture and methods behind the technology itself, rather than the data used to train it. A successful patent claim could, in theory, affect how the underlying systems are built, not just how training material was sourced.

Anthropic has not yet filed a public response to the complaint. The company has not commented publicly on the specific allegations as of early September 2026.

What this means for the broader AI industry

Universities and research institutions increasingly hold patents covering foundational machine learning techniques developed decades before today’s commercial AI boom. The University of Tennessee Research Foundation’s suit could encourage similar claims from other institutions watching how this case unfolds. AI companies have generally licensed data and compute at scale but have paid less public attention to whether underlying architectural techniques carry patent obligations.

Legal analysts tracking AI litigation note that patent cases typically move more slowly than copyright disputes. They often take years to reach resolution through discovery, expert testimony and potential appeals.

What other universities are watching

Technology transfer offices at several major research universities have flagged AI patent litigation as an area to monitor closely, according to industry newsletters covering the space. Many universities hold older patents tied to neural network research from the 1990s and 2000s, long before commercial large language models existed. Whether those patents can be enforced against modern AI systems remains legally untested outside a small number of cases. A ruling in the Tennessee case, whichever way it goes, is likely to influence how other institutions weigh similar claims.

No other university has yet filed a comparable suit against Anthropic specifically. Legal observers say that could change depending on how this case develops over the coming months.

What happens next in the case

The case will proceed through the federal court system in Delaware, where Anthropic is expected to file a formal response addressing the infringement allegations. Discovery follows next, in which both sides exchange technical evidence about how the disputed methods were developed and used. That process can take many months in patent litigation of this complexity.

Neither party has indicated interest in an early settlement. Cases of this type frequently proceed toward trial unless a licensing agreement is reached beforehand.

Questions about the lawsuit

  • Who filed the lawsuit? The University of Tennessee Research Foundation.
  • When was it filed? July 2026, in federal court in Delaware.
  • What does the foundation allege? That Anthropic’s AI systems infringe patents covering neuroscience-inspired machine learning technology.
  • Is this the first patent suit against Anthropic? Yes, according to reporting on the case.
  • Has Anthropic responded? The company had not issued a public response to the specific allegations as of early September 2026.
  • What is the foundation seeking? Unspecified damages and an order blocking further alleged infringement.

Related coverage on Tamara News

See our coverage of the GPT-6 Astra release, the Nvidia chip export loophole story, and the Apple UK antitrust lawsuit.

Sources

  • WBIR — University of Tennessee Research Foundation sues Anthropic. wbir.com
  • U.S. News & World Report — Anthropic Sued for Infringing Neural Network Technology Patents. money.usnews.com

Google Just Patched Its Seventh Emergency Chrome Bug This Year — Update Now

Google has shipped an emergency fix for a Chrome vulnerability that attackers were already exploiting before the patch went out. It marks the seventh actively-exploited zero-day the company has addressed in the browser so far in 2026. The update reached the stable channel on September 9, 2026. Google is urging users to update immediately rather than wait for automatic installation.

Zero-day vulnerabilities are flaws that attackers exploit before a vendor has released a fix, which makes them more dangerous than bugs discovered through routine testing. Google’s security team disclosed limited technical detail about the flaw. That is standard practice, meant to slow attackers from reverse-engineering the exploit before most users have patched.

Chrome ships updates through a staged rollout system, meaning not every user receives a new version at the exact same moment. Google typically pushes critical security fixes to the front of that queue, which is why officials describe emergency patches like this one as reaching most users within a day or two of release, faster than a routine feature update.

Enterprise IT teams often manage Chrome updates separately from consumer devices, using centralized policy tools to push patches across an organization’s fleet on a controlled schedule. Security teams generally treat a zero-day advisory as a trigger to override that normal schedule and push the fix immediately instead.

What the Chrome zero-day patch 2026 actually fixes

Google’s advisory confirmed attackers were exploiting the vulnerability in the wild. The company withheld specifics about which threat actors were behind the activity or how many users may have been targeted. Chrome’s security team typically restricts technical bug details until most of the browser’s user base has installed the update. For a browser with Chrome’s scale, that rollout can take days to weeks.

Encrypted network data visualization representing the Chrome zero-day patch 2026 fix

The seventh exploited zero-day of the year keeps Chrome roughly on pace with recent years. The browser has regularly logged a handful of actively-exploited flaws annually. That reflects both its scale as the world’s most-used browser and the resources attackers dedicate to finding weaknesses in it.

Why this keeps happening to the world’s most-used browser

Chrome’s dominant market share makes it a high-value target. A working exploit can potentially reach a huge number of devices before defenders catch up. Google runs a bug bounty program and an internal red team specifically to find these flaws before attackers do. Still, the sheer size of Chrome’s codebase, combined with its exposure to nearly every kind of web content, means new vulnerabilities surface regularly.

Security researchers say browsers remain one of the most attractive targets for both criminal groups and state-linked actors. A single successful exploit chain can bypass many other layers of a device’s security.

What users should actually do

Chrome typically updates itself automatically. Users can force an immediate check by opening the browser’s menu, selecting Help, then About Google Chrome, which triggers a check and installs any pending update. Chrome needs a relaunch to complete the patch. Leaving old browser tabs open without restarting does not apply the fix.

Users on Chromium-based browsers such as Microsoft Edge and Brave should also watch for their own vendor updates. Those browsers often need to incorporate the same underlying Chromium security fix separately.

How this compares with Chrome’s earlier 2026 patches

Chrome’s six previous zero-day patches this year followed a similar pattern: limited public detail at release, followed by fuller technical writeups once most users had updated. Security researchers who track browser vulnerabilities say the frequency is not unusual for a codebase Chrome’s size, though it can look alarming when tallied across a single year. Enterprise security teams have adjusted by treating every Chrome security bulletin as a same-day patching priority rather than folding it into routine update cycles. That shift has become common across large organizations managing thousands of endpoints.

Google’s Project Zero and its internal Chrome security team continue to publish periodic summaries of the year’s vulnerability trends, typically after each individual flaw has been fully patched across the user base.

What happens if you don’t update

Once a zero-day’s technical details become public, whether through Google’s own eventual disclosure or independent researcher analysis, the window for opportunistic attackers to build their own exploits widens considerably. Enterprises running managed Chrome deployments typically have a shorter runway to push the update across their fleets before that broader risk period begins.

Google has not indicated any plans to change its update cadence. Further security bulletins are expected to follow its standard monthly and out-of-band patching pattern for the rest of 2026.

Questions about the Chrome update

  • When was the patch released? September 9, 2026, on Chrome’s stable channel.
  • Is this the first zero-day Chrome has faced this year? No, it is the seventh actively-exploited zero-day Google has patched in Chrome in 2026.
  • How do I update Chrome manually? Open the browser menu, go to Help, then About Google Chrome, and restart when prompted.
  • Does this affect Chromium-based browsers like Edge? Those browsers typically need their own separate update to incorporate the same fix.
  • Has Google said who is behind the exploit? No, Google withheld details about the threat actors involved.
  • Is restarting the browser necessary? Yes, the update does not take effect until Chrome is relaunched.

Related coverage on Tamara News

See our coverage of the GPT-6 Astra release, the American Tower data breach, and the Sony PlayStation Store lawsuit.

Sources

Fabletics Shared Your Shopping Data With Meta and TikTok, Suit Claims

A new Fabletics class action lawsuit was filed on September 9, 2026, in federal court in San Francisco. The suit alleges the activewear retailer unlawfully intercepted and shared customers’ online communications and purchase information with major advertising platforms, despite giving customers privacy assurances to the contrary.

What the Fabletics class action lawsuit alleges

According to the complaint, reviewed by Courthouse News Service, Fabletics embedded tracking technologies from Meta, Google, TikTok, Snapchat, LinkedIn and Microsoft directly onto its website. Those technologies allegedly collected customers’ personally identifiable information and shopping activity before shoppers had any opportunity to opt out.

Fabletics class action lawsuit
Fabletics Shared Your Shopping Data With Meta and TikTok, Su

The named plaintiff says she purchased leggings and jackets through the Fabletics website in March 2026, and that her identity and purchase details were disclosed to third-party advertising platforms without her knowledge or consent, according to case filings tracked by ClassAction.org.

Part of a wider pattern of complaints

This is not the only active class action facing the retailer. Fabletics also faces a separate suit alleging it passed the cost of 2025 tariffs onto customers while promising refunds it did not deliver. A third pending case alleges the company failed to clearly disclose that its VIP membership program automatically renews on a month-to-month basis.

Taken together, the three cases paint a picture of a company facing scrutiny on multiple fronts at once, from data practices to billing transparency, in the same court system over the same several-month period.

Why tracking-technology suits are becoming more common

Lawsuits alleging unauthorized data sharing through embedded ad-platform trackers have become increasingly common against e-commerce retailers. Plaintiffs’ firms are applying older wiretapping and privacy statutes to modern website tracking pixels. Courts have reached mixed conclusions on whether these tools count as unlawful interception under laws written before web tracking existed.

The outcome of the Fabletics case could hinge on a few narrow facts. When were customers actually notified about tracking? Did any real opt-out mechanism exist before data moved to third parties? Those details tend to decide cases like this one.

What happens as the case moves forward

Fabletics has not yet filed a public response to the complaint. Companies facing similar suits typically have roughly 30 days to respond once served. Timelines still vary by jurisdiction and case specifics.

If the case proceeds to class certification, more customers could join. Any consumer who made a purchase through the Fabletics website during the relevant period could eventually be eligible. That process typically takes months to resolve, even in cases nobody actively contests on the merits.

Privacy attorneys not involved in the case say the outcome could influence how other apparel retailers configure their own tracking tools going forward, regardless of how this specific dispute resolves. Several firms have already begun reviewing their own consent flows in anticipation of similar scrutiny, according to lawyers who track this niche of consumer litigation closely.

How this compares with past tracking-pixel cases

Retailers across the industry have faced similar suits in recent years. Plaintiffs’ firms have targeted companies for embedding ad-platform pixels that capture browsing behavior and send it to Meta, Google or TikTok before a shopper consents. Some cases have settled quietly. Others have gone to trial with mixed results.

Courts remain split on a core legal question: does a tracking pixel count as “interception” under wiretapping statutes written decades before web tracking existed? Some judges have said yes, treating the pixel as a third party listening in on a private communication. Others have ruled the retailer itself is a party to the communication, which exempts it from wiretapping liability under many state laws.

That legal uncertainty is part of why these cases keep being filed. Plaintiffs’ firms see an unsettled area of law with potential for large class recoveries, given how many customers a single retailer’s website can touch in a short period.

Retailers, meanwhile, have started auditing their own tracking setups more closely. Some have added clearer cookie consent banners specifically to blunt this type of claim before it is filed, though consent banners alone do not always resolve the underlying legal question.

Whether the Fabletics case follows the settlement pattern or proceeds toward a contested ruling will likely depend on how strong the plaintiff’s specific evidence turns out to be once discovery begins.

Common questions about the Fabletics lawsuit

What does the Fabletics class action lawsuit claim?
It alleges Fabletics shared customers’ purchase and browsing data with advertising platforms including Meta, Google and TikTok without proper consent.

Where was the lawsuit filed?
The suit was filed in federal court in San Francisco on September 9, 2026.

Are there other lawsuits against Fabletics right now?
Yes. Separate class actions allege the company improperly passed tariff costs to customers and failed to disclose automatic VIP membership renewal terms.

Has Fabletics responded to the allegations?
No public response had been filed as of this writing.

Who could be affected if the case is certified as a class action?
Customers who made purchases through the Fabletics website during the period covered by the complaint could potentially be included, pending court certification.

For more on recent consumer litigation, see our coverage of the Sony PlayStation Store lawsuit and the Apple UK antitrust case.

Sources