Secretus logo
newsidscanidentity-documentsdata-breach

Canada Opens an IDScan.net Investigation: The Breach Is Confirmed, the 153 Million Claim Is Not

Canada’s privacy regulator is investigating IDScan.net after identity data was stolen. The breach is confirmed; the 153 million figure is not.

·Updated ·10 min read·Secretus Editorial

Canada's Privacy Commissioner has opened an investigation into a data breach at IDScan.net, saying an unauthorized third party accessed the company database and stole personal information, including digital scans of driver's licences and other IDs. That resolves the central uncertainty that existed when this page was first published on September 3: this is no longer only a marketplace claim. It does not, however, validate the advertised total of more than 153 million driver's-license records or show that every record offered by the service came from IDScan.net.

IDScan.net's September 4 notification says an unauthorized party may have accessed or copied customer information stored within accounts on the IDScan.net cloud. It names full names and driver's-license or other government-issued identification numbers as information that may be involved. The notice does not publish an affected-person count, an intrusion method, a complete date range or a finding that every advertised image came from its systems.

What changed on September 21

The Office of the Privacy Commissioner of Canada says its investigation will examine the safeguards IDScan.net had in place and whether its notifications to affected people were adequate under Canada's federal private-sector privacy law, PIPEDA. Opening an investigation is not a finding that IDScan.net violated the law. The regulator says the matter is active and has not released further detail.

CBC independently reported the Canadian investigation. The primary evidence remains the regulator's own release and IDScan.net's filed notification; the news report is corroboration, not the basis for expanding the known scope.

What is confirmed, reported and alleged

The confirmed facts are narrower than the largest headlines. The Canadian regulator calls the event a data breach and says digital identity scans were stolen. IDScan.net says customer information in its cloud may have been accessed or copied and is notifying potentially affected people. Neither source confirms 153 million affected individuals.

KrebsOnSecurity reports that the illicit service, called Nexus, advertised more than 153 million driver's-license records, alongside other identification, travel-document and medical-card images. A blank search reportedly returned roughly the advertised scale, and the collection included infrared and ultraviolet versions of some IDs. The operator also claimed continuing access to a major identity-verification provider.

The authentic samples and matching timestamps are evidence that real documents were exposed through some pathway. The operator's figures, claimed source and claim of ongoing exfiltration remain allegations. A marketplace row count is not automatically a unique person count: a person may appear more than once, synthetic entries may exist and the service's own statistics have not been independently audited.

The original investigation did more than repeat a forum post. The reporter found his own licence in the service, obtained permission to check records for other people and matched several image timestamps with occasions when those people had presented their IDs. Those checks support the conclusion that at least part of the collection is authentic. They do not establish the provenance, completeness or uniqueness of every advertised record. Krebs also reported that the FBI's New Orleans field office opened an inquiry; no public FBI release or final forensic report confirms the marketplace's count.

What the new confirmation still does not prove

The regulator now names IDScan.net as the organization whose breach it is investigating, so the existence of an IDScan.net incident is no longer an inference. Public evidence still does not connect every item in the Nexus collection to that incident. A vendor's appearance on a customer page also does not prove that every person who used that business was processed by the vendor or appears in the reported collection.

The Nexus service went offline shortly after publication. That removes one point of public access; it does not demonstrate that copies were deleted, identify the initial access method or resolve whether collection occurred from stored archives, a live processing path, a customer deployment or another system.

An identity document is not a password

A compromised password can be revoked. A driver's-license image contains durable attributes—name, portrait, birth date, address, document number and physical descriptors—that may remain useful for impersonation long after the incident. A front and back image can also weaken services that treat possession of a document scan as strong proof of identity.

Organizations should therefore stop treating ID scans as ordinary attachments. Before collecting one, document why it is necessary, which fields are required, who may access it, whether a less sensitive proof would work and when every operational copy and backup becomes eligible for deletion. "We might need it later" is not a retention policy.

What organizations should do now

  1. Identify the real processor. Map the scanner, SDK, cloud portal, local workstation and any downstream verification provider used in each workflow.
  2. Ask for incident-specific facts. Request written confirmation of affected products, dates, tenants, data fields, retention behavior and required customer actions.
  3. Preserve evidence. Keep relevant contracts, processing records, configuration, consent screens, timestamps and vendor notices without copying additional ID images into the incident ticket.
  4. Pause unnecessary collection. If a workflow can validate age or eligibility without retaining a full document image, use the less invasive option.
  5. Separate verification from account recovery. Do not let a license scan by itself reset MFA, replace an administrator or recover a high-value account.
  6. Prepare accurate notices. Do not tell every customer they were affected until evidence supports that conclusion, but do not hide behind uncertainty when a notification duty is triggered.

Safer handling when an ID image must be transferred

When a legitimate recipient must receive an identity document, send it through a narrowly scoped, time-limited channel rather than attaching it to email or leaving it in a persistent chat. Verify the recipient independently, set the shortest practical expiry and avoid creating extra copies in downloads, ticket systems and shared drives.

Secretus can reduce the durable plaintext left in the transport channel by using a one-time encrypted link. It cannot force a recipient to delete a document after opening, secure a compromised scanning endpoint or replace the legal and operational controls a verification provider needs. Secure delivery is one part of minimization, not permission to collect indefinitely.

What individuals can reasonably do

There is no confirmed public lookup that identifies every affected person. A past rental, hotel stay or identity check is not proof of inclusion. People concerned about identity misuse can monitor financial accounts, review credit reports and consider a credit freeze using official government guidance. Be skeptical of unsolicited breach-notification, identity-protection or account-recovery messages; a high-profile incident creates a second opportunity for phishing.

What remains unknown

Public evidence does not yet establish the initial-access method, the full time window, whether access continued after containment, the number of unique people, every affected customer, the complete set of data fields or whether IDScan.net is the sole source of the illicit collection. The company's wording is conditional and the regulator's investigation is not complete. Those points should remain explicitly unresolved until a forensic report, final regulator finding or other primary evidence answers them.

Sources