Data Breach Watch logoDBW
    Government
    Low
    investigation open
    Updated about 1 month ago

    IntelBrokerly Breached Washington DC DMV and IAAI Data Breach

    Key takeaways

    • Reports suggest a potential breach involving IntelBrokerly Breached Washington DC DMV and IAAI.
    • Discovered on February 1, 2026.
    • Possible data exposed: Full Name, Driver's License Number, Date of Birth, Address, Vehicle Registration Details, License Plate Numbers, VINs, Auction/Claim Details, Phone Numbers, Emails, Hardcoded Credentials, Source Code.
    • Affects individuals in: District of Columbia, California, Texas, Florida.
    • Confirmation level: Based on reports.

    Detailed summary

    In early 2026, the cybercriminal actor IntelBroker claimed responsibility for breaching the Washington DC Department of Motor Vehicles (DC DMV) and Insurance Auto Auctions Inc. (IAAI). IntelBroker posted samples of the stolen data on BreachForums in February 2026. The threat actor announced that the breach included data ranging from 2018 to 2024, including complete source code and various sensitive modules.

    For the DC DMV, approximately 500,000 individuals were affected, with data types including full names, driver's license numbers, dates of birth, addresses, vehicle registration details, and license plate numbers. No SSNs, medical, or direct financial data were reported for DC DMV. For IAAI, up to 3 million records were claimed stolen, potentially affecting vehicle owners nationwide. Data types for IAAI included names, addresses, VINs, auction/claim details, phone numbers, and emails. No SSNs, medical, or direct financial data were reported for IAAI. The full scope of affected individuals remains unverified, as IntelBroker claimed to have full databases.

    Details can emerge later as investigations progress, and official notices may continue to be delivered.

    Data possibly involved

    • Full Name
    • Driver's License Number
      Can be used for identity fraud
    • Date of Birth
      Often used in combination with other data for identity theft
    • Address
      Could be combined with other data for identity theft
    • Vehicle Registration Details
    • License Plate Numbers
    • VINs
    • Auction/Claim Details
    • Phone Numbers
      May be used for SIM swapping or targeted scam calls
    • Emails
      Increases risk of phishing attacks and account takeovers
    • Hardcoded Credentials
    • Source Code

    Company Response Timeline

    Response Grade
    B

    Notified consumers within 31–60 days

    Breach Occurred

    Feb 1, 2026

    Company Discovered

    Feb 1, 2026

    Regulator Notified

    Mar 25, 2026

    Consumers Notified

    Mar 15, 2026

    0 days to discover
    42 days to notify consumers

    Breach Verification Status

    Reports Only

    Current

    Initial dark web reports of potential breach

    Company Confirmed

    Company has acknowledged the breach

    Regulator Confirmed

    Confirmed by regulatory authorities

    Note: Breach verification can take time. Information may evolve as more details become available from companies and regulators.

    Case Status:
    Investigation Open

    We're actively investigating this case and seeking affected individuals.

    Were You Affected By This Breach?

    If you are a customer or have received a data breach notification, you may submit your information as part of our ongoing investigation. Submitting your information is free and does not obligate you.

    Were you in the IntelBrokerly Breached Washington DC DMV and IAAI breach? Check your email

    Free scan against known breach datasets. Then remove your info from data-broker sites with Data Shield.

    No signup required. 30-second scan. Your email is only stored if you opt into alerts.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Check Your Risk Level

    Answer a few questions to understand how this breach might affect you

    What should I do?

    Change your passwords

    Update passwords for the affected service and any accounts using the same password

    Enable two-factor authentication

    Add an extra layer of security to your accounts

    Monitor your accounts

    Watch for suspicious activity on your financial and online accounts

    Watch for phishing attempts

    Be cautious of emails or messages claiming to be from the affected company

    Consider a credit freeze

    Prevent unauthorized access to your credit report

    Scan your email for other exposures

    Check whether this address shows up in other known breaches. Free, no account.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Got a notice about this breach?

    Paste it into BreachBrief to see exactly what data was exposed, how serious it is, and what to do next.

    Protect yourself

    Share This Breach Alert

    Help friends and family who might be affected by sharing this breach information

    Are you a law firm investigating this breach?

    Get qualified claimant leads delivered directly to your CRM.

    Related breaches

    Stay informed about breaches like this one

    We'll notify you when new data breaches are reported. Free, no spam. Unsubscribe anytime.

    Free, no spam. Unsubscribe anytime.