Canada's Privacy Watchdog Launches Probe into Massive Driver's Licence Data Breach—Millions Exposed
In what is shaping up to be one of the largest identity document breaches in North American history, Canada's federal privacy commissioner has officially stepped in to investigate a hack that may have exposed the driver's licence data of millions of citizens. The breach, linked to identity verification provider IDScan.net, has triggered a cross-border cybersecurity response involving the RCMP and the FBI, leaving experts to warn of elevated risks of identity theft and financial fraud. With the dust still settling, the incident serves as a stark reminder of the vulnerabilities inherent in storing sensitive personal data in the cloud.
The Office of the Privacy Commissioner of Canada (OPC) confirmed it is "aware of this matter and is engaged with the company to obtain more information." In a statement to Global News, the OPC emphasized that it is ensuring the affected company understands its obligations under the Personal Information Protection and Electronic Documents Act (PIPEDA), the nation's federal private-sector privacy law. Under PIPEDA, organizations are legally mandated to report any breach of security safeguards involving personal information if it is reasonable to believe the breach creates a "real risk of significant harm" to an individual, such as financial loss or identity theft.
This unprecedented hacking incident came to light after independent cybersecurity journalist Brian Krebs discovered a dark web marketplace selling digital scans of millions of driver's licences. While the RCMP has not officially named the victim company, multiple reports have pointed to New Orleans-based IDScan.net. Krebs, whose findings were corroborated with nine affected individuals, estimated that a staggering 153 million identity documents were stolen, including approximately 1.1 million belonging to Canadian citizens. These figures have not been independently verified by Global News, and neither the RCMP nor the Canadian Centre for Cyber Security has confirmed the exact scope of the data breach.
The Attack and the Fallout: A Timeline of the IDScan.net Breach
The timeline of the hack suggests a rapid escalation. IDScan.net released a statement on Sept. 4 acknowledging that on or around Sept. 1, it became aware that "an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud." This revelation aligns with Krebs' discovery of the dark web listing, suggesting that the threat actor moved quickly to monetize the stolen data. The source of the identity documents has yet to be confirmed by federal officials, but the FBI has confirmed it is "looking into the incident," though it remained tight-lipped due to the ongoing nature of the investigation.
For Canadians, the implications of this hack are particularly severe. Driver's licences are the de facto standard for identity verification in the country, often used to open bank accounts, apply for credit cards, and verify age. Gururaj Saileshwar, a professor of cybersecurity and computer science at the University of Toronto, warned that the exposure of actual driver's licences is "very, very risky." He explained that with a physical scan of a licence, malicious actors could impersonate victims, leading to "real harm, financial harm, identity theft," on a scale that is difficult to mitigate once the data is in the wild.
Government and Law Enforcement Response to the Cybersecurity Threat
The breach has sent ripples through the political and law enforcement landscape. The RCMP confirmed it is "monitoring" the situation and remains engaged with domestic and international partners, though it has not confirmed whether a formal criminal investigation is underway in Canada. The federal privacy commissioner’s office is seeking information to "determine next steps," specifically regarding compliance with PIPEDA. In the political sphere, the Prime Minister’s Office deferred inquiries to Public Safety Minister Gary Anandasangaree, whose spokesperson declined to on an ongoing investigation, citing the FBI's work.
Political parties have also been drawn into the fray. The Green Party of Canada stated that while neither Elizabeth May nor party members were affected, they are "deeply concerned about the exposure of North Americans’ personal data." Meanwhile, the Conservative Party, NDP, and Bloc Quebecois did not respond to requests for . This silence underscores the uncertainty surrounding the breach, as provincial authorities responsible for issuing licences also stated they could not confirm the number of residents impacted in their regions. This lack of concrete data from official channels has created a vacuum of information, leaving millions in the dark about their exposure.
Expert Analysis: Why This Hack is a Cybersecurity Nightmare
The sheer volume of data involved makes this a unique cybersecurity threat. Unlike credit card numbers which can be cancelled, a driver's licence number and photo are immutable identifiers. Saileshwar emphasized that the risk is "very real," and given the volume of data, a "large volume of people are affected." He suggests that Canadians should not wait for a notification from IDScan.net before taking action. "If you see an account that’s being opened for you... it’s important to take action and keep monitoring your credit scores," he advises.
As a proactive defense measure, Saileshwar recommends that individuals who are not actively applying for loans or credit cards should "freeze your credit." This prevents unauthorized accounts from being opened by malicious actors who have obtained the stolen identification data. The hack underscores a broader failure in corporate data handling and security. Saileshwar argues that businesses need to adopt better security measures, such as limiting data retention to only what is necessary and ensuring robust access control. "There really needs to be better security measures adopted, best practices adopted," he said, urging regulators to implement and enforce laws that compel companies to perform due diligence both proactively and reactively.
Mitigation and Moving Forward: Protecting Your Identity
In response to the breach, IDScan.net has stated that affected individuals will be contacted directly and provided with access to free credit monitoring and identity protection services. However, experts argue that credit monitoring alone may not be sufficient when physical ID scans are involved. The dark web is now awash with authentic-looking IDs that could be used to bypass Know Your Customer (KYC) protocols at financial institutions. This malware-like dissemination of personal data requires a more aggressive approach to personal security.
For those concerned about their vulnerability, cybersecurity professionals recommend immediately changing passwords associated with any accounts that may use IDScan.net verification, enabling multi-factor authentication on all financial accounts, and reporting any suspicious activity to local law enforcement and the Canadian Anti-Fraud Centre. As IDScan.net and authorities continue to work through the aftermath, the onus is on the individual to remain vigilant. "This isn’t going to be the last data breach," Saileshwar warned. "We’re only going to see more and more of these and we should make sure that we are learning from this and improving."
The investigation into this hacking incident is still in its infancy, but the initial findings paint a grim picture of the cybersecurity landscape. With the OPC stepping in and the FBI actively investigating, there is hope that the threat actor will be identified. Yet, the data has already been sold, and the risk of identity fraud looms large over millions of North Americans. This hack serves as a critical reminder that in the digital age, our physical identities are only as secure as the cloud servers that store them.