Canada investigates IDScan.net after millions of driver’s licenses leak online
Were adequate security measures put in place?

IDScan.net logo is on a phone screen. Image by Thomas Fuller/SOPA Images/LightRocket/Getty.
- Canada’s privacy commissioner is investigating IDScan.net after an unauthorized party copied cloud-stored customer data.
- Dark web sellers listed 153 million driver’s license scans and other identity documents from US and Canadian people.
- Investigators will examine IDScan.net’s security safeguards and whether it properly notified affected victims.
- The inquiry remains active, and Canadian officials have not said when it will finish.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Office of the Privacy Commissioner of Canada has opened an investigation into the recent data breach at IDScan.net.
Earlier this month, IDScan.net, a company that performs over 21 million ID verifications per month globally, confirmed that an unauthorized party accessed and copied customer information that was stored on the IDScan.net cloud.
A marketplace on the dark web dubbed Nexus was selling millions of US and Canadian driver’s licenses. The scans included 153 million driver’s licenses, 10 million ID cards, 3 million international travel cards, and 579,000 medical cards, such as marijuana dispensary cards.
One of the records included the driver’s license of US Secretary of Defense Pete Hegseth, which was listed for $100.
Cybersecurity expert and investigative reporter Brian Krebs, who broke the story, reported that his driver’s license included 6 image files of the front and back, including an infrared and ultraviolet version.
“It is a catastrophic data breach, probably the worst I’ve ever seen. It poses a significant threat to celebrities, politicians, lawyers, wealthy people, law enforcement officers, etc.,” security analysts claimed.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
That’s why Philippe Dufresne, Privacy Commissioner of Canada, has launched an investigation into the data breach.
The Canadian privacy and data protection authority will be looking into the security safeguards that IDScan.net had in place at the time of the breach.
In addition, the Privacy Commissioner will see whether victims were notified adequately of the incident in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private-sector privacy law.
“IDScan.net issued a public advisory about the incident earlier this month. Since that time, the Office of the Privacy Commissioner of Canada (OPC) has been actively engaging with IDScan.net, and will continue to do so, to ensure that the organization is taking the necessary steps to address the incident and mitigate any risks to Canadians,” the data protection authority says in a press release.
Because this is an active investigation, the OPC says it can’t provide further details at this time. When the investigation will be completed remains unclear.