Canada's Office of the Privacy Commissioner announced late Monday, September 21, that Commissioner Philippe Dufresne has opened a formal investigation into a data breach at IDScan.net, the Louisiana-based identity verification vendor whose systems are the suspected source of a dark web archive advertising digital scans of more than 153 million driver's licences from people in the United States and Canada. The OPC says it will examine both the security safeguards IDScan.net had in place at the time of the breach and the adequacy of its notifications to affected individuals, to determine compliance with PIPEDA, Canada's federal private-sector privacy law. One framing correction is worth making up front: despite widespread characterisation of this as a "government driver's licence database" breach, the compromised holder of the data is a private vendor processing government-issued documents on behalf of commercial customers. The documents are governmental; the breached environment is not.
What Happened
The timeline assembled from the available reporting is tight. On August 31, 2026, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian-language cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The service, dubbed Nexus, used Krebs's own Virginia driver's licence as a free sample in its initial sales thread. Krebs published on September 1, reporting that the FBI's New Orleans field office had opened an official inquiry into the source of the images that same day. On September 2, Reuters reported the FBI confirming it was investigating a report that tens of millions of drivers' licences belonging to people in the US and Canada were being sold on the dark web, with the bureau declining further comment "due to the ongoing nature of the investigation."
IDScan.net disclosed on September 4 that it had learned around September 1 that data may have been accessed without authorisation, later determining that an unauthorized third party may have accessed or copied information held in customer cloud accounts. On September 18, the OPC told Global News it was "aware" of the matter and "engaged with the company." Four days later, that engagement became a formal investigation.
Note the divergence between the criminal marketplace's claims and the vendor's own confirmations. Nexus advertises 153 million-plus licence records; Reuters characterises it as "tens of millions"; the initial Exploit listing claimed 170 million people. IDScan.net's public notice describes potential unauthorized access to information stored within customer accounts on its cloud, a scope that The Deep Dive correctly notes "remains substantially smaller than figures circulating around the incident." No primary source has yet confirmed that the Nexus archive and the IDScan.net incident are the same dataset. The attribution rests on Krebs's metadata analysis and on interviews with individuals whose licences appear in the service, not on a vendor or law enforcement confirmation.
What Was Taken
Per the Nexus listing as reported by Krebs, the archive comprises more than 153 million driver's licences from the US and Canada, more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. The Canadian Cyber Security Journal reports the travel-document count as 1.9 million rather than three million; on this figure the sources conflict and neither is independently verified.
Krebs's own sampling supports the order of magnitude: a blank search in Nexus returns roughly 11.5 million pages at approximately 15 results per page. The bulk are Americans. A search restricted to Canadian driver's licences returns approximately 1.1 million results, with the largest single concentration from Ontario at 473,673 records. The Deep Dive rounds the Ontario figure to roughly 473,000.
IDScan.net's own disclosure confirms a narrower and less alarming set: full names and driver's licence or other government-issued ID numbers held in customer cloud accounts. The gap between "names and licence numbers" and "high-resolution scans of the physical document" is the single most consequential unresolved question in this incident. A licence scan carries full name, date of birth, address, licence number and photograph in one image, which is materially more dangerous than the field data alone.
The exposure is not evenly distributed and is not confined to consumers. Krebs reported finding the driver's licence of US Defense Secretary Pete Hegseth among the records available for purchase, one of several high-ranking US government officials whose licences appear in the service.
Why It Matters
Zach Edwards, a threat researcher at Infoblox, told Reuters the incident is unprecedented in sweep, saying "there's never been a breach of driver's licences at this scale." Edwards found his own licence in the set.
For Canadian defenders the structural lesson is the more durable one. IDScan.net states its technology performs more than 21 million verifications per month across more than 20,000 locations worldwide, serving hospitality, nightlife, retail, banking, cannabis and transportation. That is a single identity-verification chokepoint aggregating the most sensitive class of civil identity document across tens of thousands of physical premises. The concentration risk is the vulnerability, independent of whatever specific technical flaw was exploited.
Two second-order consequences follow. First, a stolen licence image is not a rotatable credential. Passwords get changed; a date of birth and a licence number do not, and provincial licence reissuance is slow, manual and expensive at scale. The fraud window is measured in years. Second, Canadian businesses running IDScan.net hardware carry their own PIPEDA notification obligations once scope confirms their customers' records are inside the archive. Being a downstream customer of the breached vendor does not transfer the duty.
The OPC investigation itself is significant beyond this incident. By explicitly scoping the inquiry to include notification adequacy, not just safeguards, Dufresne's office is signalling that the speed and completeness of breach communication is itself enforceable under PIPEDA. Under the Act, an organization must report any breach of security safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm, with harm expressly including financial loss, identity theft and negative effects on credit record. Licence data clears that bar without argument.
The Attack Technique
Initial access remains unconfirmed and no primary source has described the intrusion method.
What is evidenced is provenance rather than technique. The Canadian Cyber Security Journal reports that Krebs traced timestamp and device metadata in sample licence images to infrared and ultraviolet scanning equipment of the type used at rental car counters and cannabis dispensaries, which is what pointed investigators at IDScan.net as the likely source. That is forensic linkage of the images to a class of hardware, not a description of how an attacker got in.
IDScan.net's own language points at its cloud tenancy rather than at endpoint hardware, describing unauthorized access to or copying of customer information stored within accounts on the IDScan.net cloud. That is consistent with compromise of a cloud storage layer or of credentials granting access across customer accounts, but the company has not said which.
One vendor writeup, Aviatrix, describes a full chain of application vulnerability or credential compromise, privilege escalation in the cloud environment, lateral movement across multi-cloud infrastructure and established C2 for data extraction. Aviatrix presents this as analysis rather than confirmed finding, and it is not corroborated by IDScan.net, the FBI, the OPC or any of the outlet reporting. Treat it as a plausible hypothesis, not as incident fact. Aviatrix also reports that multiple class-action lawsuits have been filed against the company.
What Organizations Should Do
-
Inventory identity-verification vendors in your onboarding and age-gating chains. If you operate retail, rental, hospitality, cannabis or gaming locations in Canada or the US, determine now whether IDScan.net hardware or software sits at any counter, and contact the vendor directly to confirm whether your location's scan data is inside the affected set. Federally regulated institutions should treat this as a live test of the third-party risk controls OSFI B-13 expects them to maintain.
-
Establish your own PIPEDA position before the vendor establishes it for you. If Canadian records from your locations are implicated, your organization has an independent reporting obligation to the OPC and to affected individuals where there is a real risk of significant harm. Draft the assessment now rather than waiting for IDScan.net's scope determination.
-
Stop treating a licence scan as a proof of identity. Any workflow that accepts an uploaded or presented licence image as sufficient authentication for account recovery, credit application, high-value transaction or in-person verification should be assumed compromised for a substantial share of the North American adult population. Add liveness checks, out-of-band confirmation or knowledge factors not present on the document face.
-
Audit scan retention at the edge. The core failure mode here is that verification data persisted long after the verification decision was made. Where a licence is scanned to answer a yes/no question such as age or validity, retain the answer and discard the image. Where retention is contractually or legally required, enforce a hard expiry and encrypt at rest with keys the vendor's cloud tenancy does not hold.
-
Tighten fraud monitoring for synthetic identity and account takeover, not just credential stuffing. The data classes in this archive support document-backed impersonation, which defeats controls tuned for password reuse. Watch for new-account applications whose document data is internally consistent but whose behavioural and device signals are novel.
-
Communicate to affected staff and customers with specifics, not reassurance. IDScan.net is offering credit monitoring and identity-protection services to potentially affected people. Credit monitoring is detection, not prevention, and it does nothing against physical impersonation. Where your workforce is implicated, point people at provincial licence reissuance and credit-file fraud alerts as well.
Defenders should expect the confirmed scope to move. The OPC investigation, the FBI New Orleans inquiry and the RCMP's stated monitoring of developments are all active, and the current 153 million figure originates with the criminals selling the data. Plan for the upper bound; report only what is confirmed.
Sources: Canada’s privacy czar launches investigation of major driver’s lice... | FBI Probes Service Selling 153M+ Drivers Licenses | FBI probes report of data breach exposing millions of drivers ... | Canada Opens IDScan.net Probe Over Stolen Government ID Data the d... | Canada’s privacy czar seeking information in massive driver’s licen... | Canadian investigation launched into data breach that exposed milli... | Dark Web Service Sells 153 Million Driver's Licenses — Canadian Rec... | IDScan Data Breach 2026: 153 Million Driver's Licenses Exposed