Canadian privacy czar opens investigation into driver’s licence hack

Canadian privacy czar opens investigation into driver’s licence hack
Credit: Getty Images

Canada's privacy commissioner, an independent agency led by Philippe Dufresne, has opened an investigation into reports of a massive cyber breach from earlier in September that has reportedly affected not only Americans but Canadians as well. The cyberattack reportedly targeted more than 100 million individuals' personal information, specifically driver's licenses. The Office of the Privacy Commissioner (OPC) announced the investigation on September 21, just after multiple Canadian news sources confirmed with the OPC that it was “aware” of the incident and had begun to make contact with the company affected, IDScan.net.

Privacy Commissioner of Canada Philippe Dufresne has opened an investigation into a data breach at IDScan.net following reports that an unauthorized third party gained access to the company database and stole personal information, including digital scans of driver's licences and other types of identification (ID),

OPC statement

Unprecedented scope

According to Canadian media outlets, this may be one of, if not the largest data breaches in Canadian history. With the total number of Canadians affected being unknown, there could be tens of millions of Canadian ID's readily available for purchase online. Zach Edwards, a threat researcher at the cybersecurity company Infoblox, told Reuters the incident was unprecedented in terms of its sweep. With the OPC investigating both IDScan, the company that was hacked, as well as the company that is selling the ID, the office hopes to find exactly how many Canadians were affected by the data breach. While investigating, Zach Edwards found that he himself had been a part of the data breach.

There's never been a breach of driver's licences at this scale; this means that this attack created legitimate national security risks for high-profile individuals.

Zach Edwards

What is IDScan?

CANADA – 2026/09/05: In this photo illustration, the IDScan.net (ID Scan) logo is seen displayed on a smartphone screen. (Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images)

IDScan is an online platform used by companies to verify their users' identities. There are dozens of major companies that use IDScan's services, including multiple companies that have major Canadian user bases. FedEx, Target, GameStop, and Hertz all used IDScan's services, resulting in millions of Canadian users being affected by the data breach. Requiring ID verification is a growing trend amongst a number of companies. Dating apps like Hinge and Tinder both require ID verification, as well as a number of social media companies. When ID verification was first introduced in the early 2020s, many users were understandably nervous about submitting their official government ID's to a cloud-based service, and those fears have now come true for more than 150 million North Americans.

How will the OPC investigate?

According to statements from the OPC, it will be closely examining some of the safeguards that IDScan had in place at the time of the breach. The OPC will also be questioning IDScan's transparency and communication with the affected individuals. According to some reports, users were not actually informed about the data breach, instead finding out through independent reports stemming from the US. In order to be compliant with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the company should have alerted Canadians immediately after the breach and explained the potential consequences of the breach.

The investigation will examine the security safeguards that IDScan.net had in place at the time of the breach, as well as the adequacy of its notifications to affected individuals, to determine its compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law.

OPC statement

Future of ID verification?

According to data privacy experts, since 2011, there have been nearly 90 independent incidents of data verification sites being breached in order to scrape driver's licenses and other forms of ID from internet users. While the trend in data breaches has slowed since 2020, the breaches we are seeing now are bigger than before. Out of the nearly 90 hacks, there have been more than 40 instances where sensitive documents such as physical ID scans, verification selfies, fingerprints, or biometric templates have been scraped and sold online. In this case, the site Nexus has advertised that it has more than 150 million pieces of North American identification available for purchase on its website.

With privacy and security concerns continuing to mount, experts say we may see an increase in legislation to protect civilians. With companies like Meta and Snapchat currently facing lawsuits for illegally collecting, using, and selling the likeness of their users, internet citizens have never been more aware of their data leaks. PIPEDA is currently one of the strongest pieces of privacy legislation in the G7, but the OPC is unsure whether IDScans' behaviour will have violated it.

What can you do?

If you have used ID verification with any of the companies listed above, you may be included in this data breach. There are multiple ways of confirming whether or not you are a victim of this cyberattack. You can contact IDScan.net if you have used their services. You can also contact your bank, freeze your credit, and submit a fraud claim to your bank. If you have noticed any activity on your credit card, you should contact your bank immediately. You can also contact your local Member of Parliament (MP), requesting that they take action by enacting new legislation increasing Canada's privacy laws regarding ID verification sites.