Canada's Office of the Privacy Commissioner (OPC) announced late Monday that Privacy Commissioner Philippe Dufresne has opened a formal investigation into IDScan.net, the Louisiana-based identity verification provider at the centre of what may be the largest exposure of government-issued identity documents in North American history. The probe will examine both the security safeguards IDScan.net had in place at the time of the breach and the adequacy of its notifications to affected individuals, under the Personal Information Protection and Electronic Documents Act (PIPEDA). Claimed scope varies enormously by source: the dark web service advertising the data claims more than 153 million driver's licences (KrebsOnSecurity), the seller's original forum post referenced identity documents on more than 170 million people (KrebsOnSecurity), the FBI and Reuters have described it only as "tens of millions," and IDScan.net's own public notice quantifies nothing at all.
What Happened
The timeline starts on Aug. 31, 2026, when a source alerted independent journalist Brian Krebs to a new vendor on the Russian-language cybercrime forum Exploit advertising access to digital scans of identity documents on more than 170 million people in North America. The seller used Krebs's own Virginia driver's licence as a free sample in the sales thread. The resulting service, branded Nexus, went live that week.
Krebs published on Sept. 1, reporting that interviews with individuals whose licences appeared in the service indicated the images were siphoned from a widely used identity verification company based in Louisiana, and that the FBI's New Orleans field office had opened an official inquiry into the source of the images that same day. Reuters confirmed on Sept. 2 that the bureau was investigating, quoting the FBI as saying it was "looking into the incident" but declining further comment due to the ongoing investigation.
IDScan.net disclosed on Sept. 4 that it had learned around Sept. 1 that data may have been accessed without authorization, publishing a notice stating that "an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud." The company said it was notifying potentially affected individuals and offering free credit monitoring and identity protection services.
On Sept. 15, the RCMP told Global News it was "aware of reports regarding the alleged exposure of driver's license data," was monitoring the situation and remained engaged with domestic and international law enforcement partners, while noting its standard practice of not confirming or denying investigations before charges are laid. On Sept. 18, the OPC told Global News it was "aware of this matter and is engaged with the company." Four days later, that engagement escalated into a formal investigation.
What Was Taken
This is where the accounts diverge sharply, and defenders should treat the gap as unresolved rather than split the difference.
The Nexus listing (as reported by KrebsOnSecurity): more than 153 million driver's licences from people in the United States and Canada, more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards. Krebs performed a rough sanity check on the 153 million figure: a blank search returned roughly 11.5 million pages at about 15 results per page. A Canadian-only driver's licence search returned approximately 1.1 million results, with the largest single concentration from Ontario at 473,673 records. The bulk of the corpus is American. Krebs reported that the data includes the driver's licence of U.S. Defense Secretary Pete Hegseth and several other high-ranking U.S. government officials.
IDScan.net's own notice: full names and driver's licence or other government-issued ID numbers held in customer cloud accounts, per the company's disclosure as summarised by The Deep Dive. No total is given.
The FBI and Reuters: "tens of millions" of driver's licences belonging to people in the U.S. and Canada.
Two things are worth flagging. First, the volume claim originates with a criminal seller, and while Krebs's page-count check is corroborating evidence, it is not independent verification. Second, there is a substantive difference in kind, not just scale: Krebs and Nexus describe digital scans, that is, images of the documents themselves, while IDScan.net's public language describes names and ID numbers. The Deep Dive notes plainly that "the publicly confirmed breach scope remains substantially smaller than figures circulating around the incident." Whether that gap reflects a still-incomplete forensic picture or a genuine overstatement by the seller is exactly the kind of question the OPC investigation exists to answer.
Zach Edwards, a threat researcher at Infoblox, told Reuters the incident was unprecedented in sweep: "There's never been a breach of driver's licences at this scale." Edwards said he found his own licence in the data.
Why It Matters
IDScan.net is infrastructure. The company states its technology performs more than 21 million verifications per month across more than 20,000 locations worldwide, serving hospitality, nightlife, retail, banking, cannabis and transportation. Every bar door scanner, car rental counter and dispensary checkout that routed an ID through that platform became a collection point feeding a single aggregated store.
That is the structural lesson. The businesses whose customers are exposed here did not suffer an intrusion. They outsourced a regulated compliance function, and in doing so transferred custody of their customers' most sensitive identity artefacts to a fourth party most of those customers never knew existed. The blast radius of a vendor compromise is not the vendor's headcount, it is the aggregate footprint of every downstream customer.
Driver's licence images are also uniquely bad data to lose. Unlike a password or a card number, a licence cannot be rotated. The scan is the substrate for synthetic identity fraud, account recovery abuse, KYC bypass at financial institutions, and increasingly for defeating the very document-liveness checks that identity verification vendors sell. A stolen corpus of authentic government ID images is a direct attack on the trust model of remote identity proofing itself. Edwards told Reuters the ongoing nature of the breach "means that this attack created legitimate natio[nal]" security concerns, per the1news, and the presence of a sitting U.S. cabinet secretary's licence in the dataset illustrates why.
The regulatory dimension is now two-pronged. PIPEDA requires organisations to report any breach of security safeguards involving personal information under their control where there is a real risk of significant harm, with significant harm explicitly including financial loss, identity theft and damage to credit records. Dufresne's office is assessing not only whether IDScan.net's controls were adequate, but whether its notifications were. The Deep Dive characterises this as adding a second issue beyond how the data was stolen: how quickly and adequately the company told people. Aviatrix reports that multiple class-action lawsuits have been filed against IDScan.net in the U.S.; that claim appears in only one lower-tier source and should be treated as unconfirmed here.
The Attack Technique
No primary source has described an initial access vector. IDScan.net's own notice says only that an unauthorized third party may have accessed or copied customer information stored within accounts on its cloud. Neither the FBI, the RCMP nor the OPC has published technical detail, and the OPC investigation is explicitly framed around examining safeguards rather than announcing findings about them.
The vendor writeup from Aviatrix offers a reconstruction, attackers compromising the verification infrastructure "likely through application vulnerabilities or credential compromise," escalating privileges within the cloud environment, moving laterally across multi-cloud infrastructure and establishing persistent C2 for extraction. That narrative is hedged speculation from a single OTHER-tier source, not confirmed incident response findings, and no source corroborates any stage of it. Treat it as a hypothesis, not a kill chain.
What the sources do support is narrower and more useful: the exposure sits at the customer cloud account layer, IDScan.net learned of it on or about Sept. 1, the same day the data surfaced publicly, and Edwards's characterisation of the breach as "ongoing" suggests the company was not able to immediately establish that access had been fully cut off.
What Organizations Should Do
-
Inventory your identity verification dependencies now. Determine whether your organisation, or any venue, franchise or partner operating under your brand, routes ID scans through IDScan.net or a comparable platform. Ask specifically whether the vendor retains document images after verification completes, and for how long. Retention is the variable that turns a verification service into a breach target.
-
Demand written answers from the vendor. If you are an IDScan.net customer, request confirmation of whether your tenant's cloud account was among those accessed, what fields and artefacts were held, and what notification the vendor has already sent to your customers in your name. Under PIPEDA the controller obligation may rest with you, not only with the processor.
-
Contractually cap identity document retention. Renegotiate for verify-and-discard by default, with image retention permitted only where a specific statute demands it. Where retention is unavoidable, require customer-managed encryption keys so that a vendor-side compromise does not automatically yield readable documents.
-
Harden identity proofing that trusts document images. Any workflow in your environment that accepts a licence photo for account opening, account recovery or step-up authentication should be assumed to be facing authentic stolen documents. Add liveness, device signals and out-of-band verification rather than relying on document authenticity alone.
-
Audit cloud tenant access and egress on your own verification stack. Enforce MFA on all administrative and API access to verification platforms, scope service credentials to single tenants, alert on bulk read operations against document stores, and set volumetric egress thresholds that would catch mass extraction well before 11 million pages of it leave.
-
Prepare the notification pathway before you need it. The OPC probe targets notification adequacy as much as safeguards. Pre-draft your breach assessment criteria against the PIPEDA real-risk-of-significant-harm standard, identify who signs off, and confirm you can actually reach affected individuals, particularly where the personal data came to you through a vendor relationship rather than a direct one.
Sources: Canada’s privacy czar launches investigation of major driver’s lice... | FBI Probes Service Selling 153M+ Drivers Licenses | FBI probes report of data breach exposing millions of drivers ... | Canada Opens IDScan.net Probe Over Stolen Government ID Data the d... | Canada’s privacy czar seeking information in massive driver’s licen... | Canadian investigation launched into data breach that exposed milli... | RCMP ‘monitoring’ reports of massive North American drivers’ licens... | IDScan Data Breach 2026: 153 Million Driver's Licenses Exposed