The Office of the Privacy Commissioner of Canada (OPC) has opened contact with the company at the centre of a confirmed identity-document breach that put digital scans of driver's licences from across North America up for sale on the dark web. In a statement to Global News, the OPC said it is "aware of this matter and is engaged with the company to obtain more information, ensure that it is aware of its obligations under the Personal Information Protection and Electronic Documents Act (PIPEDA)... and determine next steps." The vendor, Louisiana-based identity verification firm IDScan.net, confirmed on or around September 10 that attackers stole driver's licence data from its cloud environment. The dark web service marketing the data, called Nexus, advertised more than 153 million driver's licences covering the United States and Canada. The FBI's New Orleans field office opened a formal inquiry on September 1; the RCMP told Global News in mid-September it is "monitoring" the situation and remains engaged with domestic and international law enforcement.
What Happened
The timeline assembled across sources is unusually tight. On Monday, August 31, a source alerted Brian Krebs to a new seller on the Russian-language cybercrime forum Exploit advertising digital scans of identity documents on what the listing claimed were more than 170 million people in North America. The seller used Krebs's own Virginia driver's licence as a free sample in the initial sales thread, which is what brought the operation to public attention.
The service itself, Nexus, claimed a somewhat smaller and more specific inventory: more than 153 million driver's licences from the US and Canada. Krebs stress-tested the claim by running a blank search against the Nexus index, which returned roughly 11.5 million pages at approximately 15 results per page, consistent with the advertised figure. Krebs published on September 1. The same day, the FBI's New Orleans field office opened its inquiry, and IDScan.net says it "received information" about a hack claim.
IDScan.net did not immediately confirm an intrusion. The Canadian Cyber Security Journal noted on September 2 that the company had not confirmed a breach at time of publication, and TechCrunch reported the firm initially said only that it was investigating an incident. Confirmation came roughly a week later, on September 10, via a notice on the company's own website, which TechCrunch described as the firm's first acknowledgement that it had been hacked. TechCrunch also referenced an earlier report characterising the intrusion as a year-long compromise; IDScan.net's own notice states the investigation remains ongoing and does not, in the material available here, put a public dwell time on the incident.
Canadian regulatory engagement followed the confirmation. The RCMP statement landed around September 15, and the OPC's confirmation that it is engaged with the company was reported September 18.
What Was Taken
Figures vary by source and by category, and they should be read as a range rather than a settled count.
On driver's licences, the sources are broadly consistent: Nexus advertised more than 153 million US and Canadian driver's licences (Krebs, Tom's Hardware, Canadian Cyber Security Journal, GetLegalBrief), while the initial Exploit sales thread made a looser claim of identity documents on more than 170 million people in North America (Krebs). TechCrunch's headline figure is "more than 150 million."
The non-licence categories diverge more. Krebs reported more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards. Tom's Hardware itemises the same archive differently: 10 million ID cards, 1.9 million travel documents plus 1.3 million international driver's licences, 579,000 medical cards, 429,000 common access cards, 91,000 residence cards, 77,000 employment authorization records, and 5 million other documents. The two accounts are reconcilable if Krebs's "three million travel documents and/or international IDs" is Tom's Hardware's 1.9M and 1.3M combined, but no source states that explicitly.
On the Canadian slice, there is a real tension worth naming. Coverage has repeatedly framed this as affecting "millions of Canadians," and a Global News broadcast segment describes the incident as "possibly affecting more than 150 million people in Canada and the U.S." Krebs's own querying of Nexus, however, found the bulk of records were on Americans: a search restricted to Canadian driver's licences returned approximately 1.1 million results, with the largest single concentration being 473,673 records from Ontario. GetLegalBrief repeats both the 473,673 Ontario figure and the roughly 1.1 million Canadian total, and adds that the Ontario records contained ultraviolet and infrared scans. The OPC spokesperson told Global News it is still not clear how many Canadians had personal information exposed, and the Canadian Cyber Security Journal reported the exact Canadian count remains undisclosed. Accounts differ: the ~1.1 million figure is a snapshot of one researcher's search against a since-removed service, not a vendor-confirmed number, and no primary-tier source has ratified a Canadian total.
As to the content of each record, IDScan.net's notice states the stolen information includes full names and driver's licence numbers, along with identity numbers from other government-issued documents such as passports. Krebs and TechCrunch report the archive also exposed licence photos, and per the Canadian Cyber Security Journal a single licence scan carries full name, date of birth, address, licence number and photograph in one image. Tom's Hardware confirms a record for US Secretary of Defense Pete Hegseth was previewable in the database; the Pentagon told TechCrunch it was aware of the suspected breach.
Why It Matters
This is a data class that does not rotate. A password is revocable in seconds; a high-resolution scan of a government identity document, complete with the UV and IR security-feature layers that GetLegalBrief reports were captured in the Ontario records, is durable for the life of the document and in some respects for the life of the person. The same imagery that lets a dispensary or rental counter validate a licence as genuine is the imagery an adversary needs to defeat a remote onboarding check or manufacture a convincing physical forgery.
The exposure profile that follows, as the Canadian Cyber Security Journal frames it, is account takeover, synthetic identity fraud, and physical impersonation, categories that map directly onto PIPEDA's definition of "significant harm," which the statute illustrates with financial loss, identity theft, and negative effects on the credit record. That statutory hook is why the OPC's engagement matters beyond publicity: PIPEDA requires an organisation to report to the Commissioner any breach of safeguards involving personal information under its control where it is reasonable to believe the breach creates a real risk of significant harm.
There is a second-order lesson for defenders. The breach did not occur at a bank, a government registry, or a hospital. It occurred at a fourth-party imaging vendor that sits quietly behind thousands of ordinary transactions, a vendor most affected individuals have never heard of and never knowingly transacted with. That is the structural point: identity data aggregates upward into verification intermediaries, and the blast radius of a single intermediary can exceed that of any one of its customers. GetLegalBrief reports at least four class actions are pending and frames the central legal questions as data minimisation, PIPEDA breach-notification duties, and liability for retaining high-sensitivity document imagery. That last one is the sharpest: the harm here is downstream of a retention decision, not just an access-control failure.
The Attack Technique
The intrusion mechanics have not been publicly detailed by the victim, and no source available here names an initial access vector, a threat actor, or a malware family. What is established:
- Exfiltration target. IDScan.net's own notice says the driver's licences were stolen from the company's cloud, not from endpoint scanning hardware at customer sites.
- Duration. TechCrunch references a prior report describing a year-long hack preceding the confirmation. This has not been independently confirmed in the sources reviewed and the company's investigation is ongoing.
- Attribution of the data, not the actor. Krebs traced the source by examining the artefacts of the images themselves. Per the Canadian Cyber Security Journal, timestamp and device metadata embedded in sample licence images pointed to the infrared and ultraviolet scanning equipment used at rental car counters and cannabis dispensaries, which is IDScan.net's core market.
- Victim-side correlation. Krebs validated the data by checking his own record and, with consent, those of friends and family. Tom's Hardware reports a common thread among the people he located: they had rented a vehicle from Hertz. That pattern is not universal. Security and privacy researcher Zach Edwards found their own data in Nexus despite not having rented a car recently, having presented ID elsewhere.
- Monetisation. Nexus was a searchable retail service rather than a bulk dump, advertised on Exploit with tiered access. IDScan.net's statement notes that "full access to the information required payment," apparently an argument that exposure was gated. The service was offline by the time Tom's Hardware published on September 2, which limits but does not undo distribution, as buyers during the window retain what they purchased.
Treat any claim about how the attackers got in as open. The honest state of knowledge is: cloud-side theft, confirmed by the victim; everything upstream of that, unknown.
What Organizations Should Do
- Inventory your identity-verification supply chain, including fourth parties. If you operate retail, rental, hospitality, or cannabis locations in North America, determine whether IDScan.net hardware or software sits anywhere in your onboarding or age-verification flow, including at franchised or co-branded locations. The Canadian Cyber Security Journal advises affected operators to contact the vendor directly to confirm whether their location's scan data is inside the leaked archive.
- Resolve your notification posture now, before scope is final. Under PIPEDA, the obligation attaches to personal information under your control. If your locations fed scans into the vendor's cloud, do not assume the vendor's notification discharges your duty. Document the reasoning and the real-risk-of-significant-harm assessment while the facts are being established, and be ready to report to the OPC. Canadian organisations should expect the OPC's engagement with the vendor to generate follow-on questions for customers.
- Kill the retention, not just the breach. The core failure mode here is that full document imagery, including UV and IR layers, persisted long after the verification decision it supported. Audit every system that captures identity documents and set hard deletion timers against the raw image, retaining at most a verification result and a minimal hashed reference. If a system cannot delete the image, that is the finding.
- Assume document-image-based verification is now weaker for a large population. Any workflow that treats a submitted licence photo as sufficient proof of identity should be reassessed. Add liveness checks, out-of-band confirmation, or issuer-side validation for high-value actions such as account recovery, credit origination, and payee changes. Static image matching against a compromised corpus is no longer meaningful assurance.
- Build detections for synthetic and impersonation fraud, not just credential abuse. Watch for new-account applications and account-recovery attempts that present clean, internally consistent identity documents paired with mismatched behavioural signals: new device, new geography, no transaction history, unusual velocity across related identities.
- Federally regulated Canadian institutions should run this as a third-party risk exercise. The Canadian Cyber Security Journal frames the incident as a live test of the controls OSFI B-13 expects for technology and cyber risk in vendor chains. Verify that identity-verification vendors appear in your concentration and criticality mapping, that contracts carry enforceable breach-notification windows, and that you have a right to audit retention practices, not just security attestations.
- For individuals in scope, monitor credit rather than watching for password alerts. A driver's licence number cannot be rotated. Credit monitoring, credit freezes where available, and heightened scepticism toward any inbound contact that "confirms" identity details are the realistic controls.
Expect the Canadian record count to move. The OPC has not confirmed a figure, the vendor's investigation is open, and the only Canadian numbers in circulation, ~1.1 million records and 473,673 from Ontario, derive from a single researcher's queries against a service that is now offline.
Sources: Canada’s privacy czar seeking information in massive driver’s licen... | FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security | ID verification giant IDScan confirms data breach with more than 15... | FBI probes report of data breach exposing millions ... | FBI investigating 153 million US and Canadian driver’s licenses lea... | RCMP ‘monitoring’ reports of massive North American drivers’ licens... | IDScan Breach: 473,673 Ontario Licences, 4 Class Actions GetLegalB... | Dark Web Service Sells 153 Million Driver's Licenses — Canadian Rec...