HomeCanada NewsCanada’s Privacy Commissioner Launches Investigation Into Major Driver’s Licence Data Breach

Canada’s Privacy Commissioner Launches Investigation Into Major Driver’s Licence Data Breach

Canada’s Privacy Commissioner Launches Investigation Into Major Driver’s Licence Data Breach

Canada’s federal privacy commissioner has launched an investigation into a major cyberattack involving IDScan.net, after reports that an unauthorized third party gained access to a database containing digital scans of driver’s licences and other identification documents belonging to people in Canada and the United States. The Office of the Privacy Commissioner of Canada announced the investigation on September 21, saying Commissioner Philippe Dufresne will examine whether IDScan.net had appropriate security safeguards in place when the breach occurred and whether the company properly notified people who may have been affected.
The investigation will assess the company’s compliance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the federal privacy law governing the handling of personal information by many private-sector organizations. According to the privacy commissioner’s office, the investigation was launched following reports that an unauthorized party accessed the company’s database and stole personal information, including digital copies of driver’s licences and other forms of government-issued identification.
IDScan.net provides identity-verification technology used by businesses to verify government-issued identification. Its services are used in industries including hospitality and nightlife, where customers may be required to present identification.
The scale of the reported breach has raised significant concerns. Cybersecurity journalist Brian Krebs previously reported that a dark-web service known as Nexus was offering access to more than 153 million driver’s licence records from people in Canada and the United States. The figure has not been independently confirmed by Canadian authorities, and officials have not released a definitive number of Canadians affected.
Krebs reported that the database contained driver’s licence scans and other identification documents and that some records appeared to be newly added over time. He also said he was able to confirm the authenticity of licence information belonging to several individuals. The source of all the data has not been definitively established by authorities. However, IDScan.net said earlier this month that it had determined an unauthorized third party may have accessed or copied certain customer information stored within accounts on its cloud platform. The company said it became aware of the issue around September 1 and subsequently issued a public advisory. The investigation by Canadian authorities is expected to examine the circumstances surrounding the breach and the company’s response. The Office of the Privacy Commissioner said it has been communicating with IDScan.net since the incident became known and will continue working with the company to ensure appropriate steps are taken to address the breach and reduce potential risks to Canadians. Because the investigation is active, the commissioner’s office has not released further details.
The RCMP is also monitoring reports about the incident and said it remains engaged with Canadian and international law-enforcement and cybersecurity partners. Canadian authorities have not publicly confirmed the exact number of Canadians whose information may have been compromised. The U.S. Federal Bureau of Investigation has separately said it is looking into the incident. The FBI began examining reports after the alleged stolen licence data appeared for sale online. The potential exposure of driver’s licences is particularly concerning because the documents can contain information that may be used for identity verification, including names, photographs, dates of birth and licence details.
Cybersecurity experts have warned that stolen identification information can potentially be used in identity theft, financial fraud, account takeovers and other forms of impersonation. The Canadian privacy commissioner notes that PIPEDA considers financial loss, identity theft and negative effects on a person’s credit record among examples of significant harm.
IDScan.net has said people who may have been affected will be contacted directly and that eligible individuals are being offered access to credit monitoring and identity-protection services.
However, the exact number of Canadians affected remains unknown. Provincial and territorial governments are responsible for issuing driver’s licences, but the reported breach involves information held by a private identity-verification company rather than a confirmed compromise of provincial driver’s licence databases. The privacy investigation could ultimately determine whether IDScan.net had adequate safeguards for the sensitive information it stored and whether its response and notifications met Canadian privacy-law requirements.
For Canadians, authorities and cybersecurity specialists are urging continued vigilance. People should watch their financial accounts and credit reports for unusual activity and be cautious about unexpected messages requesting personal information or financial details.
The investigation is ongoing, and officials have not yet determined the full scope of the breach, how the information was obtained or exactly how many Canadians may have been affected.
If confirmed at the scale reported by cybersecurity researchers, the incident could represent one of the largest exposures of government-issued identity documents involving Canadians and Americans, underscoring growing concerns about how sensitive identification information is stored and protected by private companies.

error: Content is protected !!