Signal 01 · · CCN Intelligence

The IDScan.net Breach Exposes a Bigger Risk in Canada’s Digital Identity Infrastructure

Canada’s Privacy Commissioner has opened an investigation into IDScan.net after an unauthorized third party accessed company systems containing digital scans of driver’s licences and other government issued identification. The immediate issue is a cybersecurity and privacy breach. The larger issue is structural: as businesses increasingly rely on specialized identity verification providers, highly sensitive identity data can become concentrated within platforms that sit behind thousands of everyday transactions. Canada’s digital trust infrastructure therefore depends not only on how organizations protect their own systems, but also on how they select, govern and continuously assess the companies handling identity information on their behalf.

What happened

Privacy Commissioner Philippe Dufresne has formally opened an investigation into IDScan.net following reports that an unauthorized third party accessed the company’s database and stole personal information, including digital scans of driver’s licences and other identification documents. IDScan.net provides identity verification technology used by businesses including hospitality and nightlife establishments to verify government issued identification. The investigation will examine the security safeguards IDScan.net had in place at the time of the breach and whether affected individuals were adequately notified, with the Commissioner assessing compliance with Canada’s federal private sector privacy law, PIPEDA. The potential scale has attracted attention in both Canada and the United States. Media reporting, citing independent cybersecurity research, has suggested that a much larger collection of North American identity documents may have been exposed and that searches of the dataset appeared to include roughly 1.1 million Canadian driver’s licence records. Those figures have not been independently confirmed by Canadian authorities, so the eventual scope of Canadian exposure remains an important unresolved question.

Why it matters for Canada

The incident raises a broader Canadian question about where digital identity risk actually sits. Organizations increasingly outsource identity verification because specialized providers can authenticate government documents, automate age or identity checks and reduce fraud. But outsourcing the verification process does not eliminate the underlying responsibility for personal information. That point is particularly significant because the Office of the Privacy Commissioner issued new third party service provider guidance on September 10. The guidance states that organizations remain responsible for personal information under their control, including information collected or processed by a third party on their behalf. It encourages organizations to assess privacy and compliance risks before selecting providers and to address those risks through governance and contractual controls. Identity information is also different from many other forms of compromised data. Passwords can be reset and payment cards can be replaced. A driver’s licence contains durable identity attributes that can potentially be combined with other data for impersonation, social engineering and fraud. As Canada expands digital identity, age verification, financial services, travel, online government services and other forms of automated identity assurance, the security of the organizations sitting between individuals and the services asking them to prove who they are becomes increasingly important.

What CCN sees

Digital identity providers are becoming part of Canada’s critical digital trust infrastructure, whether we formally recognize them that way or not. The strategic issue is not simply whether one company was breached. It is whether Canada sufficiently understands the concentration of identity information being created by verification platforms and the dependencies that develop when large numbers of organizations rely on the same providers. This changes the security question from “How well do we protect the data we hold?” to “Who else holds our customers’ identity data, why are they holding it, for how long, and what happens if that provider is compromised?” It also raises a data minimization question. Identity verification does not always require long term retention of a complete digital copy of an identity document. Organizations and providers increasingly need to distinguish between verifying an attribute and retaining the underlying document used to prove it. Canada’s digital trust strategy will ultimately depend on getting this architecture right: strong verification, minimal unnecessary retention, clear accountability, resilient providers and security requirements proportionate to the sensitivity and concentration of the data involved.

What leaders should consider

Business leaders should treat identity verification providers as more than ordinary software vendors. Organizations using outside identity or age verification services should understand exactly what personal information is collected, where it is stored, how long it is retained, whether subcontractors have access to it, how it is protected and what notification obligations apply if a breach occurs. Procurement teams should also reconsider whether vendor assessments adequately reflect concentration risk. A provider serving thousands of organizations can represent an attractive target because one compromise may expose information originating from many otherwise unrelated businesses. Security, privacy, legal and procurement teams therefore need a common view of identity risk rather than evaluating these providers independently. Leaders should also examine whether they actually need copies of identity documents retained after verification or whether less data intensive approaches can accomplish the same business purpose.

What to watch next

Watch first for the Privacy Commissioner’s findings on IDScan.net’s security safeguards, notification practices and compliance with PIPEDA. The confirmed number of Canadians affected will also matter. Current public estimates should not be treated as established until authorities or the company provide further evidence. Beyond this incident, watch whether Canadian regulators begin applying greater scrutiny to identity verification providers, data retention practices and the responsibilities of organizations that outsource identity processing. Also watch for a broader policy discussion around whether high concentration identity verification services should face stronger security, assurance or transparency requirements as digital identity becomes more deeply embedded in the Canadian economy.

Source: https://www.priv.gc.ca/en/opc-news/news-and-announcements/2026/nr-c_260921/

Read the full edition · September 23, 2026

Get the Daily Signal