Security News

Canadian Privacy Regulator Investigates ID Verification Firm After Massive Driver's Licence Breach

The Record · 23 Sept 2026
Key Takeaway Businesses that rely on third-party identity verification services should confirm those vendors have strong data security practices and clear breach notification processes before sharing customer ID data with them.

The Privacy Commissioner of Canada, Philippe Dufresne, has launched an investigation into IDScan.net after reports emerged that attackers breached the company's cloud platform and stole personal data, including scans of driver's licences. The regulator will examine IDScan's security practices and whether it properly notified affected individuals, as required under Canada's federal private-sector privacy law.

IDScan.net provides identity verification technology widely used across the retail and hospitality industries to check official IDs. The company confirmed on 4 September that hackers had accessed user data stored in its cloud platform, but did not disclose how many customers were affected. This statement followed reporting that suggested tens of millions of driver's licences may have been exposed. IDScan reportedly learned of the breach around 1 September, hours after a journalist revealed the stolen scans were being sold on the dark web.

IDScan has not responded to requests for comment, and the full scope of the breach remains unclear as the investigation proceeds.

data breach privacy regulation identity verification Canada third-party risk
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.