Canada’s privacy commissioner investigating massive driver’s licence data breach
· Toronto Sun

See more Toronto Sun on Google — save as a Preferred Source
Visit librea.one for more information.
Canada’s federal privacy commissioner has launched an investigation into a data breach that potentially exposed data from driver’s licences of millions in Canada and the United States.
IDScan.net provides identification verification software to several categories of businesses, notably hospitality and nightlife establishments, among others, to verify customers’ government-issued identification, according to the commissioner’s office.
“The investigation will examine the security safeguards that IDScan.net had in place at the time of the breach, as well as the adequacy of its notifications to affected individuals, to determine its compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private-sector privacy law,” the OPC said in a news release .
The PIPEDA notes: “An organization shall report to the Commissioner any breach of security safeguards involving personal information under its control if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual.”
Examples of “significant harm” under that legislation include “financial loss, identity theft, negative effects on the credit record.”
The CPO said it has been “actively engaging” with IDScan.net to “ensure that the organization is taking the necessary steps to address the incident and mitigate any risks to Canadians.”
The company is investigating
IDScan.net confirmed the unauthorized access to customer information stored in its cloud environment “on or around September 1, 2026,” in a press release earlier this month.
“The types of information contained within the affected data may include full names and driver’s license or other government-issued identification numbers,” the company said of the troubling incident.
IDScan.net, which touts its technology as “the best-in-class ID fraud prevention platform,” said it was notifying individuals who had potentially been affected and offered free credit monitoring services and identity protection services.
Data sold on the dark web?
Two days before the company issued its alert, the FBI confirmed it was investigating a report from independent journalist Brian Krebs that tens of millions of drivers’ licences from people in the U.S. and Canada were being sold on the dark web.
Krebs said that the site appeared to be updating its database of stolen data in real time, indicating that it was being fed by a live breach, Reuters reported.
However, the site selling the driver’s licence data disappeared after Krebs’ report was published, the journalist said.
‘Never been a breach… at this scale’
No further details were provided due to the ongoing investigation, but if the breach is confirmed, it could be one of the largest-ever exposures of government-issued identity documents in North America.
Zach Edwards, a threat researcher at the cybersecurity company Infoblox, told Reuters the incident was unprecedented in terms of its scope.
“There’s never been a breach of driver’s licences at this scale,” Edwards told the outlet, noting that he discovered his own ID was available for sale on the site.
He added that the ongoing nature of the breach “means that this attack created legitimate national security risks for high-profile individuals.”