In early 2026, the cybercriminal actor IntelBroker claimed responsibility for breaching the Washington DC Department of Motor Vehicles (DC DMV) and Insurance Auto Auctions Inc. (IAAI). IntelBroker posted samples of the stolen data on BreachForums in February 2026. The threat actor announced that the breach included data ranging from 2018 to 2024, including complete source code and various sensitive modules.
For the DC DMV, approximately 500,000 individuals were affected, with data types including full names, driver's license numbers, dates of birth, addresses, vehicle registration details, and license plate numbers. No SSNs, medical, or direct financial data were reported for DC DMV. For IAAI, up to 3 million records were claimed stolen, potentially affecting vehicle owners nationwide. Data types for IAAI included names, addresses, VINs, auction/claim details, phone numbers, and emails. No SSNs, medical, or direct financial data were reported for IAAI. The full scope of affected individuals remains unverified, as IntelBroker claimed to have full databases.
Details can emerge later as investigations progress, and official notices may continue to be delivered.