Canada's federal privacy commissioner has entered one of the largest identity-document breaches on record. The Office of the Privacy Commissioner of Canada (OPC) told Global News on September 18 that it is "aware of this matter and is engaged with the company to obtain more information, ensure that it is aware of its obligations under the Personal Information Protection and Electronic Documents Act (PIPEDA)... and determine next steps." The company in question is IDScan.net, a Louisiana-based identity verification vendor that confirmed in a website notice that an unauthorized third party accessed customer data on its cloud platform. The stolen material surfaced on a dark web search service called Nexus, which claims more than 153 million driver's licence scans from the United States and Canada. The FBI's New Orleans field office opened an inquiry on September 1, and the RCMP has said it is monitoring the situation and remains engaged with domestic and international law enforcement.
What Happened
The timeline as reported across sources is tight and largely consistent. On Monday, August 31, 2026, a source alerted Brian Krebs of KrebsOnSecurity to a new listing on the Russian-language cybercrime forum Exploit. The seller advertised access to digital scans of identity documents covering, in Krebs' words, "more than 170 million people in North America." The service itself, branded Nexus, claims a somewhat lower figure for driver's licences specifically: more than 153 million from the US and Canada. Those two numbers are not in conflict so much as differently scoped, but they are worth keeping separate. TechCrunch and others have rounded the headline figure to "more than 150 million."
Krebs corroborated the scale rather than taking the seller's word for it: a blank search in Nexus returned roughly 11.5 million pages of results at about 15 results per page. The proprietor had posted Krebs' own Virginia driver's licence as a free sample in the sales thread, which he verified, as did a security researcher quoted in his report.
IDScan.net's own account: "On or around September 1, 2026, IDScan.net received information indicating that certain data may have been accessed without authorization. Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident. This investigation is currently ongoing." Accounts differ slightly on when that notice constituted a confirmation. Help Net Security reports the notice was posted September 4; TechCrunch, writing September 10, characterised the notice as the company's first acknowledgement of an intrusion and noted that a week earlier the firm had said only that it was investigating. The Canadian Cyber Security Journal, publishing September 2, recorded that IDScan.net had not confirmed a breach at that time. The most defensible reading is that the company's language hardened over the first ten days of September.
For Canada, the specific numbers come from Krebs' own searching of the Nexus interface rather than from IDScan.net or any regulator. Searching for Canadian driver's licences returned approximately 1.1 million results, with the largest single concentration from Ontario at 473,673 records. The OPC spokesperson explicitly could not confirm how many Canadians are affected, and the Canadian Cyber Security Journal noted the exact Canadian count remains undisclosed. Treat 1.1 million as a journalist's floor estimate from a seller-controlled search box, not as a confirmed victim count.
What Was Taken
The gap between what IDScan.net has confirmed and what the criminal service is advertising is the most important thing on this page.
IDScan.net's notice says an unauthorized third party "may have accessed and/or copied certain customer information" stored in its accounts on the IDScan cloud platform, and describes the data at risk as names and driver's licence or other government-issued identification numbers. TechCrunch reports the stolen information includes full names and driver's licence numbers along with identity numbers from other government-issued documents such as passports.
Nexus advertises considerably more. Per Krebs, as echoed by Help Net Security and Security Affairs, the inventory includes:
- More than 153 million driver's licences from the US and Canada
- More than 10 million identification cards
- More than three million travel documents and international IDs (the Canadian Cyber Security Journal gives a lower figure of 1.9 million travel documents; the three million figure traces to Krebs and is the better-sourced of the two)
- At least 579,000 medical cards, plus smaller batches of residence cards and employment authorization records
Critically, these are images, not just field data. Security Affairs reports that each record contains six images of a licence: front and back, captured in visible, infrared, and ultraviolet light, with a timestamp. Krebs found his own record's timestamp matched a June 2025 flight and car rental. That is a full forensic capture of a security document, including the covert features that exist specifically to defeat forgery.
Security Affairs also reports the record total was growing by roughly 400,000 per day at time of publication, which the operators attributed to ongoing exfiltration from a live intrusion they claim has run for over a year. That is the seller's claim about their own operation and has not been confirmed by IDScan.net or law enforcement, but it is consistent with the year-long-hack framing in TechCrunch's reporting.
Why It Matters
A leaked password is revocable. A leaked passport number is not, and a UV-and-IR scan of a physical licence is worse still. As the Canadian Cyber Security Journal put it, a single licence scan carries full name, date of birth, address, licence number, and photograph in one image, which supports account takeover, synthetic identity fraud, and physical impersonation well beyond what a stolen credential enables. Multispectral imagery raises the ceiling further: it is the raw material for producing documents that survive the same automated checks IDScan.net's own products perform.
The victim set is not IDScan.net's direct customers alone. This is a third-party data concentration failure. Security Affairs names Hertz, Target, FedEx, Motorola Solutions, Caesars Entertainment, and Jack Henry among IDScan.net's clients; the vendor's equipment is common at car rental counters, retailers, cannabis dispensaries, entertainment venues, and hospitality operators across North America. Most people in this dataset never chose to do business with IDScan.net. They handed a licence to a rental clerk.
The exposure reaches into government. The dataset includes high-ranking US officials, with US Defense Secretary Pete Hegseth's licence among the records available for purchase. TechCrunch reports the Pentagon confirmed it was aware of the suspected breach.
On the regulatory side, PIPEDA requires an organization to report to the Commissioner "any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual," with significant harm including financial loss, identity theft, and damage to credit records. That obligation does not stop at the vendor. Any Canadian business whose customers' scans sit in the archive faces its own notification analysis. GetLegalBrief reports at least four class actions are pending against IDScan.net; that figure comes from a single aggregator and should be treated as reported rather than confirmed.
The Attack Technique
The initial access vector has not been disclosed by IDScan.net, the FBI, or any other source. What is on the record:
- The compromised location was the IDScan cloud platform, specifically customer accounts hosted there, per the company's own notice.
- The intrusion appears to have been long-running. The Nexus operators claim exfiltration has been active for over a year, and TechCrunch's reporting refers to a year-long hack. IDScan.net has not confirmed a dwell time.
- Data was still flowing at the time of Krebs' reporting, with the Nexus catalogue growing by roughly 400,000 records per day, suggesting either live access or a staged upload of a previously captured archive.
- Attribution to IDScan.net was made by artifact analysis before the company confirmed anything. Krebs traced timestamp and device metadata in sample images to the infrared and ultraviolet scanning equipment used at rental car counters and dispensaries. The Canadian Cyber Security Journal describes this as the chain that pointed to IDScan.net as the likely source.
- The seller is monetising through a searchable paid service rather than a bulk dump. IDScan.net's notice acknowledges that "full access to the information required payment," and the company says it is notifying potentially affected people "in an abundance of caution" with free credit monitoring and identity protection.
Anyone claiming to know the initial vector right now is guessing. The investigation is ongoing and the company says it is cooperating with federal law enforcement.
What Organizations Should Do
- Inventory every identity-verification vendor in your onboarding and age-gating chain, including hardware at physical counters. If you operate IDScan.net scanners at any Canadian location, contact the vendor directly to establish whether your location's scan data is in the archive, and get the answer in writing.
- Start your PIPEDA breach-of-security-safeguards assessment now rather than waiting for the vendor's final scope. The real-risk-of-significant-harm test turns on the sensitivity of the data and probability of misuse, and licence imagery scores high on both. Document the assessment even if you conclude notification is not required.
- Kill retention of document imagery you do not need. The core failure here is that scans of security documents were retained at all, at scale, long after the verification decision was made. Verify, extract the minimum attribute you actually need, and delete the image.
- Assume document-image-based identity proofing is degraded for this population. If your fraud controls treat a clean licence scan, including IR and UV features, as strong evidence of presence, that assumption no longer holds for anyone in this dataset. Add liveness checks, out-of-band verification, or step-up controls for high-value account changes.
- Treat this as a live test of third-party risk controls. The Canadian Cyber Security Journal notes that federally regulated institutions with identity-verification vendors in their onboarding chain should measure this incident against the expectations set out in OSFI B-13. Contractual breach-notification timelines, data residency, and deletion guarantees are the clauses to pull first.
- Brief your fraud and customer-service teams on synthetic identity and impersonation attempts referencing genuine licence data, and monitor for account-takeover attempts that clear knowledge-based authentication cleanly. Individuals who used a rental counter or dispensary scanner in the last two years should consider a credit freeze rather than relying on monitoring alone.
Sources: Canada’s privacy czar seeking information in massive driver’s licen... | FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security | IDScan confirms breach after 153 million driver’s licenses leak on... | ID verification giant IDScan confirms data breach with more than 15... | Dark Web Service Nexus Sells 153M+ Driver's Licenses | RCMP ‘monitoring’ reports of massive North American drivers’ licens... | IDScan Breach: 473,673 Ontario Licences, 4 Class Actions GetLegalB... | Dark Web Service Sells 153 Million Driver's Licenses — Canadian Rec...